Description
In this position, you will lead the cybersecurity architecture, risk analysis, and validation for Ford Energy's battery monitoring and BMS-related systems. You will be responsible for securing the BESS environment across embedded firmware, communication pathways, and control logic. This is a critical role ensuring the protection of battery data and control signals against sophisticated threats in a safety-critical infrastructure environment.
Responsibilities:
- Cybersecurity Architecture & Risk Management: Lead cybersecurity architecture and TARA (Threat Analysis and Risk Assessment) for battery monitoring electronics. Focus on mitigating risks related to sensor spoofing, unauthorized SOC manipulation, malicious commands, and firmware compromise. Define and maintain testable cybersecurity requirements for BMS and monitoring functions, ensuring traceability from concept to release. Develop and implement Hardware Root of Trust, secure boot, code signing, and key lifecycle management strategies.
- Communication & Update Security: Secure internal and external communication pathways, including CAN, CAN-FD, SPI, Ethernet, and Modbus TCP. Define and validate secure OTA (Over-the-Air) and field update strategies, focusing on authentication, anti-rollback protection, and recovery behavior. Identify and implement embedded intrusion/anomaly detection approaches for real-time attack awareness.
- Validation, Testing & Response: Support vulnerability analysis, penetration testing, and fuzz testing for battery monitoring and connected interfaces. Lead issue remediation planning and establish response processes for product vulnerabilities and field issues. Develop technical security case materials and evidence for design gates, audits, and compliance reviews.
- Cross-Functional Co-Engineering: Collaborate with software, controls, and safety teams to ensure security controls are compatible with functional safety and safe-state behavior. Align with Ford Auto Engineering and global suppliers on shared architecture and implementation standards. Communicate technical security risks, tradeoffs, and recommendations to executive-level stakeholders.
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://efds.fa.em5.oraclecloud.com/hcmUI/CandidateExperience/en/sites/CX_1/job/64520