We are seeking an experienced cybersecurity professional to support CRA, Product Security, and Cybersecurity Lab services. The role combines cybersecurity assessment, product security testing, regulatory compliance evaluation, and laboratory operations. The successful candidate will support customer projects, cybersecurity testing activities, ISO/IEC 17025 laboratory processes, and service expansion in CRA, IoT Security, and Medical Device Cybersecurity.
RESPONSIBILITIES
- Conduct cybersecurity assessments, gap analyses, and technical documentation reviews against CRA and related cybersecurity standards.
- Perform vulnerability assessments, penetration testing, threat modeling, and product security evaluations.
- Review cybersecurity risk assessments, SBOMs, secure development lifecycle (SDLC) evidence, and vulnerability management processes.
- Develop and execute cybersecurity test plans, test procedures, and technical reports.
- Lead cybersecurity laboratory operations, test method development, validation activities, and quality processes.
- Lead ISO/IEC 17025 accreditation activities, internal audits, and laboratory readiness initiatives.
- Participate in customer technical discussions, workshops, assessments, and project delivery activities.
- Provide technical leadership, mentoring, and cybersecurity competency development for engineering teams.
- Support proposal development, service scoping, and pre-sales activities.
- Contribute to service development in CRA, IoT device security, and medical device cybersecurity.
QUALIFICATIONS
Required
- Bachelor's degree in Cybersecurity, Computer Science, Information Security, Electrical/Electronic Engineering, or a related field.
- 7+ years of experience in cybersecurity, product security, security testing, assessment, or related disciplines.
- Strong understanding of:
- Network security and communication protocols
- Secure software development practices and principles
- Vulnerability management and risk assessment
- Authentication, authorization, and cryptography
- IoT and embedded systems security
- Experience in Linux and scripting languages (Python, Bash, or PowerShell)
- Familiarity with firmware analysis, reverse engineering, and hardware security testing
- Hands-on experience with:
- Vulnerability Assessment
- Penetration Testing
- Fuzz Testing
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- Threat Modeling / TARA
- Security Risk Assessment
- Secure Software Development Lifecycle (SSDLC)
- Product Security Evaluation
- Technical Documentation Review
- Experience with one or more of the following standards or regulations:
- CRA
- EN 18031
- ETSI EN 303 645
- IEC 62443
- ISO/SAE 21434
- Experience developing test plans, test procedures, and cybersecurity assessment reports.
- Experience supporting cybersecurity laboratory operations.
Preferred
- Experience with EN 18031 and ETSI EN 303 645 test method development, technical evaluation, or reporting for connected or radio-enabled products.
- Strong understanding of of OWASP Top 10, OWASP IoT Top 10, CWE, CVE, MITRE ATT&CK, secure coding principles, cryptography fundamentals, Authentication and authorization
- Experience with ISO/IEC 17025 accredited laboratories, including method validation and verification, internal audits, accreditation preparation, quality management systems, or laboratory operations.
- Knowledge of embedded Linux, RTOS, bootloaders, secure boot, firmware updates, hardware security, and Trusted Platform Module (TPM).
- Experience using security testing tools such as Burp Suite, Nessus, Nmap, Wireshark, tcpdump, Defensics, Checkmarx, Black Duck, Coverity, OWASP ZAP, or Metasploit.
- Relevant certifications such as OSCP, OSWE, CISSP, CompTIA Security+, CompTIA CySA+, or ISA/IEC 62443 Cybersecurity Expert.
Skills Required
- Bachelor's degree in Cybersecurity, Computer Science, Information Security, Electrical or Electronic Engineering, or a related field
- 7+ years of experience in cybersecurity, product security, security testing, assessment, or related disciplines
- Understanding of network security and communication protocols
- Understanding of secure software development practices and principles
- Understanding of vulnerability management and risk assessment
- Understanding of authentication, authorization, and cryptography
- Understanding of IoT and embedded systems security
- Experience with Linux and scripting languages such as Python, Bash, or PowerShell
- Familiarity with firmware analysis, reverse engineering, and hardware security testing
- Hands-on experience with vulnerability assessment, penetration testing, fuzz testing, SAST, DAST, SCA, threat modeling or TARA, security risk assessment, SSDLC, product security evaluation, and technical documentation review
- Experience with CRA, EN 18031, ETSI EN 303 645, IEC 62443, or ISO/SAE 21434
- Experience developing cybersecurity test plans, test procedures, and assessment reports
- Experience supporting cybersecurity laboratory operations
- Experience with EN 18031 and ETSI EN 303 645 test method development, technical evaluation, or reporting
- Understanding of OWASP Top 10, OWASP IoT Top 10, CWE, CVE, MITRE ATT&CK, secure coding, cryptography, authentication, and authorization
- Experience with ISO/IEC 17025 accredited laboratories, method validation, internal audits, accreditation preparation, quality systems, or laboratory operations
- Knowledge of embedded Linux, RTOS, bootloaders, secure boot, firmware updates, hardware security, and TPM
- Experience with security testing tools including Burp Suite, Nessus, Nmap, Wireshark, tcpdump, Defensics, Checkmarx, Black Duck, Coverity, OWASP ZAP, or Metasploit
- Relevant certifications such as OSCP, OSWE, CISSP, CompTIA Security+, CompTIA CySA+, or ISA/IEC 62443 Cybersecurity Expert
UL Solutions Compensation & Benefits Highlights
-
Strong & Reliable Incentives — All employees are eligible for a broad-based annual incentive bonus, and formal plan language references an All Employee Incentive Plan. This companywide structure is consistently presented as a core element of total rewards.
-
Retirement Support — U.S. materials describe a meaningful 401(k) match complemented by an additional company contribution after the first year of service. Employer-verified listings also point to protections like disability and life insurance that bolster long-term financial security.
-
Healthcare Strength — Health plans offer multiple options (PPO and HDHPs) with the employer covering a substantial share of premiums. Complementary features such as dental, vision, HSA/FSA options, and periodic company contributions to accounts are also noted.
UL Solutions Insights
What We Do
A global leader in applied safety science, UL Solutions transforms safety, security and sustainability challenges into opportunities for customers in more than 100 countries. UL Solutions delivers testing, inspection and certification services, together with software products and advisory offerings, that support our customers’ product innovation and business growth. The UL Certification Marks serve as a recognized symbol of trust in our customers’ products and reflect an unwavering commitment to advancing our safety mission. We help our customers innovate, launch new products and services, navigate global markets and complex supply chains, and grow sustainably and responsibly into the future. Our science is your advantage.
Why Work With Us
Science is in our DNA; we are endlessly curious and passionate about seeking and speaking the truth. We take delight in knowing that our work makes a meaningful contribution to society, and we are proud that our culture is centered on integrity, collaboration, inclusion and excellence.
Gallery
UL Solutions Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Depending on the role we offer hybrid or remote opportunities.


.jpeg)


.jpeg)



.jpeg)


.jpeg)
