Product Cybersecurity Engineer (TARA)

Contract Product Cybersecurity Engineer (TARA)

Location: Hybrid on-site in Surrey for workshops/design sessions
Duration: Initial 3 Months with potential to extend to 6 Months
Rate: TBC based on experience, Outside IR35 status determined by the engaging consultancy)
Right to work: UK right to work without sponsorship required. No security clearance needed.

The Role

A specialist product cybersecurity consultancy is looking for additional delivery capacity on an in-flight EU Cyber Resilience Act conformity programme for a UK manufacturer of specialist commercial vehicles. Five ISO/SAE 21434 threat analysis and risk assessments (TARAs) are in scope across three product lines, including CAN-based vehicle controllers with 4G telematics and a connected fleet-management product on an embedded Linux platform.

The method, templates, governance framework and client relationship are already established and owned by the consultancy's Product Security Architect. This role is delivery capacity within that method not a review, re-baseline or redesign of the approach.

Deliverables

- TARAs to ISO/SAE 21434 for assigned product lines, from item definition and asset identification through damage scenarios, threat scenarios, attack path analysis, attack feasibility rating and risk determination, to a documented risk treatment decision
- Derived, testable and traceable cybersecurity requirements
- Cybersecurity assumptions/interface requirements for third-party platform components
- Contribution to the cybersecurity case for assigned product lines
- Facilitation of technical workshops with client engineering, with written outputs

All work is subject to independent QA before it reaches the client.

Essential Criteria (must be evidenced, not just listed)

- Personally authored at least two completed TARAs to ISO/SAE 21434, item definition through to risk treatment decision and residual risk acceptance, on a product that reached production or formal assessment
- Fluent in the assessment structure: damage scenarios, impact rating, threat scenarios, attack paths, attack feasibility, risk determination, treatment
- Applied a named attack feasibility approach and can justify it over alternatives
- Authored or materially contributed to a cybersecurity case
- Embedded/vehicle systems literacy: ECUs, CAN networks, telematics units, software update paths, embedded Linux
- Derived cybersecurity requirements and passed them to a supplier/integrator, including handling unverifiable third-party platform assumptions
- Facilitated technical workshops with engineers who were not the requesting party
- Assurance-grade written English (documentation that has withstood audit/assessment/regulator scrutiny)

Desirable

- UNECE R155 CSMtGuard, Ansys medini analyze, itemis SECURE, ThreatGet or comparable
- IEC 62443 alongside 21434
- Off-highway, agricultural, construction, municipal or other specialist vehicle sector experience
- Working knowledge of Yocto/emS development, submission or audit exposure
- TARA tooling: Threabedded Linux build systems
- Functional safety experience alongside cybersecurity
- EU Cyber Resilience Act awareness

What this role is NOT

- Not security architecture, Zero Trust or design authority
- Not enterprise, cloud, identity or infrastructure security
- Not CISO, virtual CISO or governance/management-system work
- Not embedded OS implementation (Yocto, kernel config, secure boot, hardening sit with the client's integrator) this role specifies and assures, it does not build

If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.

Job Details

Company
Experis
Location
South East, United Kingdom
Hybrid / Remote Options
Employment Type
Contract
Posted