Electronic Systems Technical Specialist - Software

Cummins Inc.Pune, MaharashtraOn-siteFull-timeStaff, 8–12 yearsListed 1 hour ago

Apply now

About this role

Job Summary:
This applied technology position creates software that is sold as an integral part of Cummins’ products. People in these positions have involvement in identification and understanding of stakeholder requirements and developing specifications, and responsibility for design, implementation, testing and/or release of software that controls the operation of Cummins’ products in a variety of customer applications.

Key Responsibilities:
Investigates product software problems, understands causal mechanisms, recommends appropriate action, owns problem resolution, and documents results. Applies and improves the improvement of product software development processes and tools. Processes include coding, compiling and test. Tools include code editors, integration tools, static analysis tools, compilers and hardware in the loop test tools. Details specific to this role may be found at the end of this document. Obtains input and negotiates with product and software development teams and delivers verified software features, components, builds to product teams. Uses systems knowledge and expertise to make decisions in the areas of software requirements, architecture, design, and test that impact the quality and performance of software builds, product lines (platforms) and management of cross-BU integration and coordination. Responsible for review of less-experienced developers/testers’ work to ensure robust, reusable, and efficient designs. Responsibile for interacting and collaborating with cross-functional teams. Provides independent leadership of smaller business impact projects or ownership of complex components, products, systems or services with greater elements of ambiguity over the senior or lead engineer level and with full accountability to the project team. Delivers independent execution of established and emerging work processes and systems, while still developing technology or product knowledge. Leads the development and improvement of work processes and systems across function(s) within a global business unit or managing improvement across business units. Coordinates and directs work amongst technicians and temporary student employees, assists in the transfer of knowledge to lesser experienced engineers through either indirect (scope of influence) or direct management of a small, local group of engineers. Provides support and guidance to influence technical direction within a project team and continues to develop proficiency in the competency areas critical to success in the role. Operates as a recognized specialist in a discipline or product area within the immediate team.

Job Specific Description

This role will serve as a technical specialist for cybersecurity, embedded software architecture, and Linux-based control/HMI platforms used in Cummins Power Generation products, including generator set controllers, power system controllers, connected devices, service interfaces, and next-generation embedded platforms.

The position is primarily responsible for defining and driving cybersecurity architecture, software architecture, and Embedded Linux system architecture , ensuring that products are secure, maintainable, scalable, and aligned with evolving regulatory, product, and technology requirements.

The role will lead architecture and design decisions spanning secure boot, software update, identity and access management, cryptographic services, secure communications, diagnostics, platform hardening, application isolation, logging, provisioning, and lifecycle security , while ensuring that these capabilities are integrated coherently within the overall embedded software platform.

A major focus of the position will be supporting both control platforms from traditional RTOS-based embedded systems as well Embedded Linux-based architectures , while establishing reusable software and cybersecurity foundations that can be adopted across multiple controller families and product programs.

The individual will work closely with PCRA, embedded software, controls, platform, systems engineering, validation, digital, service tools, manufacturing, and application engineering teams. Approximately 10–20% of the role will focus on system-level architecture and system integration , ensuring that cybersecurity and software platform decisions remain aligned with overall product architecture, power system behavior, external interfaces, and validation strategy.

The role is expected to provide technical leadership without direct authority , drive structured architecture decisions, establish reusable platform capabilities, identify architectural risks early, and ensure traceability from requirements through architecture, implementation, verification, and product deployment.

Key Responsibilities (Job-Specific)

- Lead definition and evolution of embedded cybersecurity architecture for Power Generation controllers/HMI/ATS/AUX and connected embedded platforms.
- Define cybersecurity concepts and architecture for capabilities including:
Secure boot and chain of trust
- Firmware authenticity and integrity verification
- Secure software update and rollback protection
- Device identity and certificate management
- Cryptographic key management and provisioning
- Hardware-backed security and secure key storage
- Identity, authentication, authorization, and access control
- Secure diagnostics and service access
- Secure communications and protocol security
- Security logging, audit, and event management
- Secure manufacturing and device provisioning
- Vulnerability management and product security lifecycle
- Secure decommissioning and credential lifecycle management

- Develop and maintain reusable cybersecurity platform services and abstractions that can be leveraged by applications, communication stacks, service interfaces, manufacturing tools, and operating-system components.
- Drive architecture for the use of hardware security capabilities , including secure elements, HSMs, TPMs, TrustZone-class mechanisms, MCU security peripherals, hardware crypto accelerators, protected key storage, lifecycle controls, and debug-access protection where applicable.
- Ensure software and cybersecurity architectures support applicable security standards, regulations, and industry practices, including relevant requirements from IEC 62443, ISO/SAE 21434 where applicable, NIST guidance, EU Cyber Resilience Act, EU Machinery Regulation, UL requirements, IEC standards, and applicable IETF security standards .
- Lead cybersecurity architecture reviews, threat modeling activities, trust-boundary definition, attack-surface analysis, and mitigation planning for embedded control platforms and associated communication interfaces.
- Define and evolve the embedded software architecture for controller platforms, including software layering, platform services, application frameworks, middleware, hardware abstraction, runtime services, communication services, persistence, diagnostics, security services, and system management.
- Establish clear software architecture principles for modularity, portability, testability, maintainability, scalability, fault containment, interface stability, and controlled dependency management .
- Define reusable software architecture patterns that support deployment across multiple controller families, hardware variants, product configurations, and operating-system environments.
- Lead architecture and migration strategies for moving selected control platforms from RTOS-based software architectures to Embedded Linux-based systems while preserving appropriate real-time, reliability, safety, and cybersecurity characteristics.
- Define Embedded Linux platform architecture covering:
Boot architecture and boot-time sequencing
- Bootloader integration
- Secure boot
- Kernel configuration and hardening
- Device tree and hardware abstraction
- System services
- Process and service decomposition
- Inter-process communication
- Application isolation
- File-system architecture
- Persistent storage
- Read-only and immutable system partitions where appropriate
- Logging and diagnostics
- Resource management
- Network configuration
- Security policies
- Software update mechanisms
- Recovery and rollback
- Containerization or application sandboxing where appropriate

- Establish Linux platform engineering practices for system service architecture, Yocto-based build systems, package management, software composition, configuration management, reproducible builds, SBOM generation, secure update, and platform lifecycle management .
- Define separation between platform software, reusable middleware, cybersecurity services, product-specific applications, control applications, and external interfaces .
- Partner with software development teams to ensure architecture decisions are implementable and provide sufficient detail through architecture specifications, reference implementations, interface definitions, design patterns, and reusable platform components.
- Facilitate structured technical design discussions covering cybersecurity, software architecture, Linux platform architecture, and embedded communications.
- Drive clear architectural decisions by documenting alternatives, trade-offs, constraints, rationale, risks, assumptions, and follow-up actions.
- Establish and maintain Architecture Decision Records (ADRs) and other design-governance mechanisms to improve consistency and institutionalize important technical decisions.
- Identify architectural gaps, technical debt, security weaknesses, dependency risks, scalability limitations, and integration risks across existing and next-generation embedded platforms.
- Define migration strategies for legacy architectures where immediate replacement is not feasible, balancing product lifecycle, business constraints, cybersecurity requirements, and engineering cost.
- Ensure architecture supports field-serviceability, diagnostics, manufacturing, provisioning, software update, calibration, validation, and product support requirements throughout the full product lifecycle.
- Define architecture for secure embedded communication across interfaces such as Ethernet, CAN/J1939, RS-485, USB, OPC UA, Modbus, MQTT, HTTPS/TLS, and other product-specific protocols .
- Ensure protocol implementations use appropriate authentication, encryption, authorization, certificate handling, key management, session security, and attack-resilience mechanisms.
- Partner with enterprise, digital, cloud, and service-tool organizations where embedded controllers interface with external services, ensuring clear security boundaries and ownership across device, edge, service tool, cloud, and enterprise systems.
- Support architecture for secure integration with service tools, manufacturing tools, engineering tools, calibration tools, diagnostics applications, and firmware delivery systems .
- Define software interfaces and security controls for device provisioning, firmware signing, software packaging, manufacturing personalization, key injection, certificate issuance, and field-update workflows.
- Ensure software architectures support observability and diagnosability , including structured event logging, fault reporting, health monitoring, audit records, security events, and platform diagnostics.
- Work with validation and cybersecurity verification teams to define architecture-driven verification strategies, including:
Security functional testing
- Penetration testing
- Fuzz testing
- Protocol robustness testing
- Negative and misuse-case testing
- Software update failure testing
- Credential and provisioning validation
- Linux platform hardening verification
- Network security validation
- Recovery and fault-injection testing

- Ensure cybersecurity and software requirements are traceable through architecture, detailed design, implementation, verification, and validation .
- Support development of automated cybersecurity and software-platform validation environments, including HIL, SIL, network simulation, virtualized test environments, fault injection, and integration laboratories .
- Promote early testability by ensuring software interfaces, platform services, security controls, diagnostic hooks, and simulation capabilities are designed into the architecture rather than added late in development.
- Support integration of model-based engineering and simulation where appropriate, ensuring consistency between system behavior, control models, software architecture, and validation environments.
- Provide technical guidance for secure coding practices, dependency management, third-party software integration, open-source software governance, library selection, and software component lifecycle management.
- Support vulnerability assessment and remediation for embedded platforms, including evaluation of vulnerabilities affecting Linux kernels, bootloaders, cryptographic libraries, network stacks, open-source components, middleware, and application software .
- Work with product cybersecurity teams to determine technical applicability and mitigation strategies for CVEs, security advisories, and emerging vulnerabilities.
- Contribute to establishment of secure software development lifecycle practices , including architecture review, threat modeling, secure design review, code analysis, dependency scanning, security verification, and release readiness.
- Define reusable platform reference architectures for secure embedded control systems that can serve as baselines for future product programs.
- Contribute to long-term technology roadmaps covering embedded Linux, RTOS platforms, cybersecurity capabilities, secure connectivity, processor security features, virtualization, application isolation, and software update technologies.
- Act as a system-level architecture integration point to ensure cybersecurity and software architecture decisions align with overall controller and product architecture.
- Participate in system architecture discussions involving generator set controls, power system controls, distributed control systems, grid interaction, data center applications, service interfaces, and external communication networks .
- Ensure subsystem boundaries, software interfaces, network interfaces, and cybersecurity boundaries are clearly defined and consistent with system-level behavior.
- Identify cross-domain dependencies between controls, hardware, software, cybersecurity, communications, diagnostics, validation, and external systems.
- Support resolution of system integration issues where ownership spans multiple engineering disciplines or organizational boundaries.
- Ensure software and cybersecurity architecture decisions consider system-level requirements for:
Availability
- Reliability
- Determinism
- Performance
- Safety
- Maintainability
- Serviceability
- Diagnostics
- Cybersecurity
- Field updateability
- Product lifecycle support

- Partner with systems and validation teams to ensure system-level requirements and failure scenarios are reflected in software architecture and verification strategies.
- Support system-level design and integration reviews for new control platforms, major software features, communication architectures, and cybersecurity capabilities.

System and System Integration Responsibilities — Approximately 10–20%

Architecture and Technical Deliverables

The role is expected to create and maintain high-quality architecture and engineering artifacts including:

- Cybersecurity Architecture Documents
- Software Architecture Documents
- Embedded Linux Platform Architecture
- Platform Reference Architectures
- System Context and Trust-Boundary Diagrams
- Software Component and Deployment Diagrams
- Data Flow Diagrams
- Network and Communication Architecture
- Interface Control Documents
- Software API and Service Definitions
- Threat Models
- Attack-Surface Assessments
- Security Concept and Security Architecture
- Secure Boot and Software Update Architecture
- Key Management and Provisioning Architecture
- Identity and Access Management Architecture
- Logging and Audit Architecture
- Platform Hardening Specifications
- Architecture Decision Records
- Requirements-to-Architecture Traceability
- Architecture-to-Test Traceability
- Failure and Recovery Strategies
- Platform Migration Roadmaps
- Cybersecurity Verification Strategies
- Reference Implementations and Architecture Patterns
- Strong understanding of embedded software architecture , including software decomposition, abstraction layers, interfaces, middleware, operating systems, communication stacks, and application frameworks.
- Strong experience or demonstrated expertise in embedded cybersecurity architecture and secure product design .
- Working knowledge of embedded security concepts including:
Root of trust
- Secure boot
- Cryptographic authentication
- Firmware signing
- Secure update
- Key management
- Certificate management
- Secure storage
- Authentication and authorization
- Device identity
- Platform hardening
- Security logging
- Vulnerability management

- Strong understanding of Embedded Linux architecture , including kernel, drivers, device tree, system services, process management, file systems, networking, security mechanisms, and boot architecture.
- Experience with or strong familiarity with Yocto/OpenEmbedded-based Linux systems and embedded Linux build and deployment workflows.
- Working knowledge of RTOS-based embedded systems and the architectural differences and migration considerations between RTOS and Embedded Linux environments.
- Understanding of embedded networking and security protocols, including Ethernet and IP-based communications.
- Familiarity with protocols and technologies such as TCP/IP, TLS, OPC UA, MQTT, HTTP/HTTPS, CAN/J1939, Modbus, RS-485, USB, and related embedded communication technologies .
- Understanding of cryptographic principles and practical use of modern cryptographic libraries and hardware acceleration mechanisms.
- Experience defining software platform services, middleware, reusable components, or shared infrastructure used across multiple embedded applications.
- Demonstrated ability to apply systems and architectural thinking , including analysis of component interactions, dependencies, constraints, failure modes, trade-offs, and lifecycle implications.
- Ability to lead complex technical discussions and influence decisions across multiple engineering organizations without direct authority.
- Experience creating high-quality architecture and engineering documentation.
- Strong understanding of requirements traceability and the relationship between requirements, architecture, detailed design, implementation, verification, and validation .
- Understanding of software validation approaches, including unit, integration, system, security, robustness, and fault-injection testing.
- Experience working with multiple concurrent programs and resolving cross-team technical dependencies.
- Strong written and verbal communication skills, including the ability to communicate complex architecture decisions to both technical specialists and engineering leadership.
- Demonstrated initiative and ability to rapidly understand new processor architectures, operating systems, cybersecurity technologies, communication protocols, and product domains.
- Experience in power generation, energy systems, data center power systems, industrial controls, or other mission-critical embedded systems .
- Experience architecting cybersecurity for industrial control systems or operational technology environments .
- Familiarity with cybersecurity standards and regulatory frameworks such as IEC 62443, NIST Cybersecurity Framework, NIST SP 800-series guidance, EU Cyber Resilience Act, ISO/SAE 21434, UL cybersecurity requirements, and applicable IEC/IETF standards .
- Experience with secure bootloaders and software update frameworks such as U-Boot, RAUC, SWUpdate, Mender, wolfBoot, or equivalent technologies .
- Familiarity with embedded cryptographic libraries and security frameworks such as OpenSSL, wolfSSL, mbed TLS, PKCS#11, TPM2, HSM interfaces, or hardware-specific crypto/security engines .
- Experience with Linux security mechanisms including capabilities, namespaces, seccomp, SELinux/AppArmor, secure file-system configuration, privilege separation, and application sandboxing.
- Experience defining or supporting Yocto BSPs, Linux platform layers, kernel configurations, device drivers, systemd services, and embedded Linux application platforms .
- Familiarity with software supply-chain security including SBOM, dependency management, vulnerability scanning, software provenance, secure build infrastructure, and signed software artifacts .
- Experience integrating embedded controllers with cloud, enterprise, service-tool, or manufacturing systems.
- Familiarity with hardware-in-the-loop, software-in-the-loop, network simulation, cybersecurity test labs, penetration-testing environments, and automated integration testing .
- Experience with model-based development or simulation tools and their integration with embedded software and validation workflows.
- Experience participating in or leading cybersecurity reviews, architecture reviews, threat-modeling sessions, and multi-team technical design reviews .
- Familiarity with architecture methods and notation such as UML, SysML, C4, data-flow diagrams, threat-model diagrams, sequence diagrams, and Architecture Decision Records .
- Familiarity with requirements, architecture, and collaboration tools such as Jira, Confluence, DOORS, Polarion, Git-based development environments, CI/CD systems, and architecture repositories .

Required Skills and Experience

The expected technical focus of the role is approximately:

- 35–40% — Cybersecurity Architecture and Product Security
- 25–30% — Embedded Software Architecture and Platform Services
- 20–25% — Embedded Linux Systems and Platform Evolution
- 10–20% — System Architecture, System Integration, and Cross-Functional Technical Leadership

The exact balance may vary by program and platform maturity, but the primary accountability remains the development of secure, reusable, scalable, and well-governed software and Linux platform architectures , with system integration providing the broader context in which those architectures must operate.

Expected Role Outcome

The successful individual will enable Power Generation engineering teams to move from program-specific and component-focused software solutions toward reusable, secure, platform-oriented architectures .

The role should result in:

- Stronger cybersecurity-by-design across embedded products
- Clear and reusable software architecture patterns
- A well-defined transition path from RTOS-based platforms to Embedded Linux
- Consistent security and platform services across controller families
- Reduced architectural duplication and technical debt
- Better-defined interfaces between controls, software, cybersecurity, systems, and external tools
- Earlier identification of architecture and integration risks
- Improved requirements and design traceability
- Increased testability and automation
- More consistent technical decision-making across engineering programs
- Improved readiness for emerging cybersecurity regulations and long-term product lifecycle requirements