Job Title: Product Cybersecurity Engineer
Location: Harwell, Oxfordshire (Hybrid)
Overview
We are seeking an experienced Product Cybersecurity Engineer to lead and support cybersecurity activities across our spectroscopy and vacuum product portfolio. This role is critical to ensuring our products meet evolving global cybersecurity regulations, customer requirements, and industry best practices-particularly in regulated markets such as aviation security, customs & borders, pharmaceuticals, and defence. You will work cross functionally with R&D, Product Security, Agilent IT, Sales, and Marketing teams, ensuring cybersecurity is embedded throughout the product lifecycle-from design and development through to deployment and ongoing support. You will report to the R&D Software Manager and work on the software/firmware that powers our instruments.
Key Responsibilities
- Cybersecurity Compliance & Regulation
- Interpret and apply global cybersecurity and privacy regulations (e.g., GDPR, EU Cyber Resilience Act).
- Act as product line lead for EU CRA readiness.
- Own and track remediation plans to ensure continued product compliance.
- Sales & Customer Cybersecurity Support
- Support Sales and Marketing with cybersecurity content for tenders and bids.
- Contribute to cybersecurity whitepapers and documentation.
- Participate in customer facing discussions and translate requirements into product development inputs.
- Secure Product Development
- Ensure products meet internal security policies, external regulatory and customer requirements.
- Conduct or support testing and assessments, providing vulnerability reports.
- Provide guidance on encryption, key management, patch management, identity, and infrastructure security.
- DevSecOps & Security Engineering
- Drive adoption of DevSecOps practices within CI/CD pipelines.
- Implement automated vulnerability scanning, SAST, DAST, and SCA.
- Lead Software Bill of Materials (SBOM) creation for spectroscopy and vacuum lines.
- Embedded Systems Security
- Secure Windows 10/11 IoT based embedded systems (policy hardening, patch management, endpoint protection).
- Support development of embedded OS images; knowledge of Embedded Linux is desirable.
- Continuous Improvement & Future Proofing
- Monitor emerging threats and regulatory changes.
- Promote continuous improvement in cybersecurity practices across the lifecycle.
- Operational Security Activities
- Manage OS patching and release cycles for product platforms.
- Support CI/CD environment hardening and security patching.
Qualifications
- Essential: Bachelor's or master's degree or equivalent.
- Proven experience ( 4years) in product cybersecurity or application security.
- Strong understanding of SSDLC, vulnerability management and regulatory compliance (GDPR, EU CRA).
- Hands on experience with SAST, DAST, SCA, penetration testing or vulnerability analysis.
- Knowledge of Windows OS security (embedded/IoT variants) and exposure to regulated industries (defence, aviation, pharma, border security).
- Experience working with cross functional engineering teams.
Desirable Qualifications
- Relevant certifications (e.g., CISSP, CompTIA PenTest, ISC2 CSSLP).
- Familiarity with DevSecOps tools and CI/CD pipelines.
- Experience with Nessus or similar scanning tools, SBOM, Embedded Linux security.
- Experience leveraging AI assisted tools (e.g., Copilot, LLMs) for secure development and analysis.
Personal Attributes
- Strong analytical and problem solving skills.
- Ability to translate regulations into actionable engineering requirements.
- Excellent customer facing communication abilities.
- Proactive, self driven, and detail oriented.
- Comfortable working across multiple stakeholders and geographies.
What We Offer
- Exciting projects within an agile collaborative team.
- Career development opportunities in an international company.
- Competitive compensation and benefits package.
- Work life balance programs.
- Permanent contract with company pension scheme and private health care.
Travel Required: Occasional
Shift: Day
Equal Opportunity Employer
Agilent Technologies Inc. is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability or any other protected categories under all applicable laws.