Principal Product Cybersecurity Assurance Engineer

UK-based AI and robotics company building commercially scalable humanoid robots for industrial deployment.

London, United Kingdom

Funding history

About Humanoid

Humanoid develops industrial humanoid robots and its proprietary KinetIQ AI framework for real-world tasks across manufacturing, logistics, and related environments.

View jobs by Humanoid

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will lead product cybersecurity assurance across the full lifecycle of robotic products. You will define security requirements and assurance strategies, manage security documentation and risk assessments, guide engineers, support certifications, establish incident-response processes, oversee fleet monitoring, and represent the security posture in customer and regulatory engagements.

Requirements

  • Apply ISO 27001, ISO 27004, ISO 27005, and the NIST Risk Management Framework to regulated hardware or embedded product programmes.
  • Own security risk management for highly regulated, safety-critical products.
  • Apply IEC 62443 and adapt ISO/SAE 21434 lifecycle methodologies.
  • Understand engineering development lifecycles, systems engineering, functional safety, and hardware/software co-development.
  • Interpret penetration-test reports and author risk-prioritised Remediation Action Plans.
  • Communicate complex security risk arguments to technical and executive stakeholders.

Responsibilities

  • Lead and develop a cross-functional team of security engineers.
  • Define product security requirements and advise on implementation standards, techniques, and toolchains.
  • Develop security protocols, tools, and processes for robotic systems.
  • Maintain cybersecurity documentation, including Security Management Plans, TARA reports, risk assessments, and Remediation Action Plans.
  • Drive security assurance throughout the product lifecycle.
  • Ensure compliance with the EU Machinery Regulation, IEC 62443, and the EU Cyber Resilience Act.
  • Provide independent information-assurance reviews and risk assessments.
  • Review security risk assessments, mitigation plans, gap analyses, and security management documentation.
  • Establish and maintain a Product Security Incident Response process.
  • Define and oversee security monitoring requirements for deployed fleets.
  • Support work package descriptions and cost estimates for bids, services, and proposals.
  • Represent the security posture in customer, partner, regulatory, and certification engagements.

Benefits

  • Comprehensive medical, dental, and vision insurance, virtual care, and employee assistance resources.
  • 23 days of accrued PTO, separate sick leave, and paid company holidays.
  • 401(k) retirement plan with a 4% employer match.
  • Stock options.
  • Free daily catered lunch, snacks, and drinks in-office.