Cyber Security Architect/engineer II

Honeywell Honeywell · Industrial · Phoenix, AZ +1

Cyber Security Architect/Engineer II at Honeywell, reporting to the Product Security Manager. This hybrid role focuses on leading efforts with development teams to manage product risk, implement security controls, drive security requirements into offerings, and provide guidance on secure product architecture. Responsibilities include threat modeling, security reviews, risk management, mentoring engineers on shift-left security, and leading initiatives to enhance the Secure Development Lifecycle. Requires a Bachelor's degree in a technical discipline or 3 years of Cyber Security experience, with 2+ years in mechanical design/development or equivalent Cyber Security/IT experience. Understanding of Agile, cryptography, PKI, and secure boot is necessary. Preferred qualifications include security accreditations and experience with various security tools and DevSecOps.

What you'd actually do

  1. Lead efforts with development teams to manage product risk and implement appropriate security controls.
  2. Drive best-in-class security requirements into product and service offerings.
  3. Provide architecture and best practices guidance for building secure Honeywell products.
  4. Support product security process activities, including threat modeling, security requirements, security reviews, threat vulnerability assessments, and risk management for PA applications.
  5. Mentor and train the engineering development community, facilitating the adoption of shift-left security practices.

Skills

Required

  • Bachelor's degree from an accredited institution in a technical discipline such as science, technology, engineering, mathematics, computer science, or 3 years of experience in Cyber Security.
  • 2 or more years of experience in mechanical design and development or equivalent work experience in Cyber Security or Information Technology.
  • Strong interpersonal skills with the ability to facilitate diverse groups, negotiate priorities, and resolve conflicts among stakeholders.
  • Understanding of Agile software development practices.
  • Understanding of cryptography, encryption algorithms, Public Key Infrastructure (PKI), secure boot, and open-source risk management.

Nice to have

  • Information Security accreditation (CISSP/CSSLP or other security-related certifications).
  • Experience with widely used security tools such as SD Elements, BlackDuck Hub, Microsoft Threat Modeling Tool, SAST (Coverity, SonarQube), DAST (Burp, ZAP, AppSpider), fuzzing, vulnerability management, and continuous monitoring tools.
  • 1 or more years of experience with DevSecOps and a solid working knowledge of tooling specific to CI/CD pipelines and security tooling.

What the JD emphasized

  • 3 years of experience in Cyber Security
  • 2 or more years of experience in mechanical design and development or equivalent work experience in Cyber Security or Information Technology
  • Understanding of cryptography, encryption algorithms, Public Key Infrastructure (PKI), secure boot, and open-source risk management.