Sr. Product Security Engineer

Trane TechnologiesMinneapolis, MinnesotaOn-siteFull-timeSenior, 5–8 yearsListed 14 hours ago

Apply now

About this role

Be a part of our mission! As a world leader in creating comfortable, sustainable, and efficient climate solutions for buildings, homes and transportation, it's our responsibility to put the planet first. For us at Trane Technologies , and through our businesses including Trane®  and  Thermo King ,  sustainability is not just how we do business—it is our business.  Do you dare to look at the world's challenges and see impactful possibilities?  Do you want to contribute to making a better future?  If the answer is yes, we invite you to consider joining us in boldly challenging what's possible for a sustainable world.

Learn about our benefits designed for you to Thrive at work and at home.

We boldly go.

Where is the work:
Monday to Thursday, work onsite with your colleagues. Fridays, choose your work location, balancing what your work requires.

What’s in it for you:

Thermo King is hiring an experienced  Senior Product Security Engineer to work on the creation and implementation of secure embedded software by demonstrating a comprehensive understanding of secure by design principles to support the next-generation transport refrigeration and mobile HVAC controls platform while meeting vehicle cybersecurity and software-update regulatory type-approval requirements.

In this role, you will lead the cross-product efforts to regularly assess threats and vulnerabilities, perform Security DFMEA, and review penetration tests & threat modeling reports on products throughout its lifecycle. You will use the findings from new threats to improve processes and productivity by providing guidance and implementing priority updates based on findings. Your tasks include developing and capturing requirements, coordinating implementation, and helping the team to deliver product security goals. You will work closely with Systems, Hardware, Software, and teams to understand customer needs, align product security with overall practices, and define effective product security solutions and oversee their development.

What you will do:

- Risk Management:  Assess product security risks in a maintained register, develop comprehensive mitigation strategies, and evaluate technical and business trade-offs.
- Lead Security Activities:  Apply the Secure Development Lifecycle and lead product security processes including architectural analysis, threat modeling, security DFMEA, penetration testing, attack modeling and simulation, cybersecurity type-approval activities including TARA per ISO/SAE 21434, and data privacy impact assessments.
- Vulnerability Management:  Identify, evaluate, and verify security issues discovered through automated testing, penetration testing, and customer feedback. Maintain and track closure of vulnerability backlogs.
- Compliance & Standards:  Interpret and enforce product security requirements, conduct vulnerability reviews, and ensure compliance with automotive and industrial cybersecurity regulations and standards (UNECE R155, UNECE R156, ISO/SAE 21434, ISO 24089, GB 44495-2024, IEC 62443, NIST, and applicable regional data-privacy laws).
- Regulatory Type Approval & Management Systems:  Support vehicle cybersecurity and software-update type approval by maintaining Cyber Security Management System (CSMS) and Software Update Management System (SUMS) processes and evidence aligned to regulations and standards.
- Secure Updates & Cryptographic Assurance:  Define and validate secure over-the-air and service-tool update paths, covering secure boot, hardware root of trust, PKI and certificate management, code signing, and anti-rollback protection across the zonal architecture and independent modules.
- Data Privacy Compliance:  Apply privacy-by-design and support data-protection impact assessments to meet regional obligations such as GDPR, CCPA, LGPD, the EU Data Act, and California SB-327.
- Security Tools Oversight:  Monitor outputs and effectiveness from all security tools integrated within the software development lifecycle.
- Technical Guidance:  Advise, guide, and mentor cross-disciplinary engineering teams during the design, review, and implementation of security features.
- Assurance:  Validate that software meets all functional, security, regulatory (cybersecurity compliance), and quality benchmarks particularly within industrial and transportation environments.
- Multi-region travel up to 5% may be required.

What you will bring:

- Bachelor's or Master's degree in computer engineering, computer science, electrical engineering or related technical field with 5+ years of experience.
- Preferred that the candidate have experience as an embedded product security engineer.
- Experience with automotive or vehicle cybersecurity and regulatory type approval (ISO/SAE 21434, UNECE R155/R156) and secure over-the-air software updates is strongly preferred.
- Experience with embedded software development and proficiency in relevant programming languages (e.g., C, C++, C#, Rust, Python).
- Embedded Systems Experience:  Demonstrated expertise in securing embedded controls platforms, with hands-on knowledge of Embedded Linux (e.g., Yocto) and RTOS environments (e.g., FreeRTOS, Zephyr Project, MicroC/OS-II).
- Connectivity Protocols:  Preferred background securing in-vehicle and telematics networks—CAN J1939/CAN FD with SecOC, Automotive Ethernet/SPE (100Base-T1, 10Base-T1S) with MACsec and TLS 1.3, and MQTT with mutual TLS.
- Cryptography & Secure Boot:  Working knowledge of secure boot, hardware root of trust and secure elements, PKI, code signing, and key management for embedded systems.
- Automotive Cybersecurity Standards:  Familiarity with ISO/SAE 21434 TARA, UNECE R155 and R156, ISO 24089, and/or GB 44495-2024 type-approval expectations.
- Security Analysis:  Strong grasp of static analysis (SAST) and software composition analysis techniques for vulnerability detection and remediation.
- DevOps & Automation:  Familiarity with modern DevOps pipelines and tools (e.g., GitHub Actions, Azure DevOps, GIT), with practical knowledge of automated testing frameworks (e.g., CppUTest, Pluma).
- Communication & Collaboration:  Effective communicator with strong organizational skills, adept at working with cross-functional teams and presenting technical risks to varied audiences.
- Continuous Improvement:  Commitment to ongoing learning and driving continuous maturity in product security processes and technical strategies.

Annual Base Salary Range or Hourly Base Pay Range:
$105,228.33 - $168,700.00
Compensation Type:
Salary
Incentive Eligible:
No
Sales Commission Eligible:
No

Disclaimer : We strive to provide competitive compensation for this position, tailored to a variety of factors. The actual compensation will depend on elements such as seniority, merit, geographic location, education, experience,  travel requirements, and union designation.   Our compensation range is generally based on the national average for the country.  Additionally, benefits may vary depending on the region, business alignment, union involvement, and employee status.

Thrive at work and at home:

- Benefits kick in on DAY ONE for you and your family, including health insurance and holistic wellness programs that include generous incentives – WE DARE TO CARE!
- Family building benefits include fertility coverage and adoption/surrogacy assistance.
- Paid time off includes  up to 15 vacation days, paid holidays, sick leave, and additional options to support volunteer and parental leave.
- 401K match up, educational and training opportunities through company programs along with tuition assistance and student debt support.

Disclaimer:  Benefit offerings may vary by site as well as Collective Bargaining Agreements and local/state regulations

Safety Sensitive Role:
No
The company designates certain roles as Safety Sensitive. Safety Sensitive roles may require that you pass additional drug screening.

We offer competitive compensation and comprehensive benefits and programs. We are an equal opportunity employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, pregnancy, age, marital status, disability, status as a protected veteran, or any legally protected status.