1) Understanding and experience in working across multiple phases of Secure Product Development Lifecycle, performing Penetration Testing of various technologies and Threat Modeling of products, systems and solutions. Focus on Cloud / Industrial IoT products is desirable.
2) Coding experience in one or more general purpose languages
3) Knowledge of attacks and mitigation in : Cloud-based applications, Network protocols and secure network design; Operating system internals and hardening (e.g. Windows, Linux, OS X, Android); Web application securtiy, Mobile App security.
4) Have Experience with assessments of cloud products hosted in azure, aws or other cloud providers.
4) Having a knowledge of CI/CD pipelines, DevSecOps and tools for SAST, SCA and other CI/CD tools.
5) Able to understand cybersecurity concepts in depth and be able to apply those concepts to Eaton products for cybersecurity testing.
6) Able to perform Threat Modeling and Risk Assessment for Eaton products
7) Having hands-on experience in various Cybersecurity activities including but not limited to - Cybersecurity assessments and penetration testing; Authentication and access control; Applied cryptography and security protocols; secure coding; preferably on embedded, ICS and IoT products.
8) Having hands on expertise with cybersecurity tools like Nessus, Black Duck, Defensics, Nessus, Burpsuite, Coverity, Kali Linux, Threat Modeler, Azure Security Toolkit, Crowdstrike, Invicti etc.
9) Having Good understanding of security protocols (HTTPS, HSTS, TLS, SSH, 802.11 security, Bluetooth, Zigbee) and ICS protocols (IEC 61850, DNP3, Modbus, WirelessHART, CAN)
10) Having knowledge of attacks and mitigation in : Network protocols and secure network design; Operating system internals and hardening (e.g. Windows, Linux, OS X, Android); Web application and browser security.
11) Having certifications like CEH, OSCP is a plus.