Product Cybersecurity Manager, Ford Energy

Ford Ford · Auto · Dearborn, MI +1 · Enterprise Technology

This role focuses on Product Cybersecurity for Ford's Battery Energy Storage Systems (BESS) portfolio. The manager will be responsible for implementing, validating, and optimizing security controls throughout the product lifecycle, from hardware development to deployment. Key responsibilities include end-to-end security architecture, hardware/firmware hardening, threat modeling, penetration testing, and ensuring compliance with industry standards. The role requires deep technical expertise in embedded systems, firmware, and hardware security, with a strong emphasis on offensive security validation and cross-functional leadership.

What you'd actually do

  1. Lead and integrate cybersecurity engineering across the entire battery storage system lifecycle, including design, manufacturing, deployment, operations, and decommissioning.
  2. Define, implement, and audit security controls at the silicon, microcontroller, and firmware levels, including secure boot, cryptographic key management, secure storage, and Hardware Security Modules (HSMs).
  3. Lead threat modeling (e.g., STRIDE) and risk assessments to resolve highly ambiguous, large-scale technical challenges across battery management systems (BMS), power conversion systems (PCS), and overall BESS architectures.
  4. Plan, coordinate, and execute hands-on penetration testing and vulnerability assessments on embedded hardware, firmware, and communication protocols (e.g., Modbus, CAN, DNP3, and TCP/IP).
  5. Align product engineering processes and security controls with relevant industry standards and frameworks (e.g., IEC 62443, ISO 21434, UL 2900, and NIST SP 800-82).

Skills

Required

  • Embedded Systems Security
  • Product Cybersecurity
  • Security Engineering
  • Firmware security
  • Hardware security
  • Penetration testing
  • Threat modeling
  • Risk assessment
  • Secure coding practices (C/C++ or Rust)
  • Hardware architectures
  • Secure boot
  • JTAG debugging protection
  • Cryptographic implementations
  • Physical hardware interfaces (UART, JTAG, SPI, I2C)
  • Industrial/automotive network protocols (CAN, Modbus, DNP3)
  • Cybersecurity frameworks and standards (IEC 62443, ISO 21434, UL 2900)
  • Leadership

Nice to have

  • Renewable Energy industry experience
  • Automotive (EV/BMS) industry experience
  • Semiconductor industry experience
  • Export control regulations familiarity
  • International intellectual property protection familiarity
  • CISSP certification
  • CSSLP certification
  • CEH certification
  • GPEN certification
  • GICSP certification
  • OSCP certification

What the JD emphasized

  • deep technical expertise
  • firmware
  • hardware
  • penetration testing
  • implement, validate, and optimize security controls
  • entire lifecycle
  • robust defense-in-depth
  • early-stage hardware development
  • senior technical lead
  • End-to-End Security Architecture & Engineering
  • Lifecycle Integration
  • Hardware & Firmware Hardening
  • Technical Innovation
  • unusually complex cyber-physical security problems
  • high degree of ingenuity and creativity
  • engineering precedents
  • design patterns
  • Threat Modeling & Offensive Security Validation
  • Cyber-Physical Threat Modeling
  • resolve highly ambiguous, large-scale technical challenges
  • novel, high-performance, and resilient security frameworks
  • extreme hardware and operational constraints
  • Active Penetration Testing
  • hands-on penetration testing
  • embedded hardware, firmware, and communication protocols
  • Governance, Compliance & Incident Management
  • Standards & Framework Alignment
  • Project Risk Governance
  • Incident Response Operations
  • Cross-Functional Collaboration & Technical Leadership
  • Consensus Building
  • technical security direction and best practices
  • multiple engineering teams
  • Talent Mentorship
  • elevate the collective technical cybersecurity capabilities
  • Embedded Systems Security
  • Product Cybersecurity
  • Security Engineering
  • product lead or senior technical capacity
  • secure coding practices
  • hardware architectures
  • secure boot
  • JTAG debugging protection
  • cryptographic implementations
  • physical hardware interfaces
  • industrial/automotive network protocols
  • complex cyber-physical or industrial control systems (ICS)
  • embedded systems and critical infrastructure