Sr. Product Security Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

Trane Technologies · 22 hours ago

Sr. Product Security Engineer

Trane Technologies is a leader in creating innovative climate solutions for sustainable environments. They are seeking a Senior Product Security Engineer to lead efforts in assessing threats and vulnerabilities while developing secure embedded software for refrigeration and HVAC applications.

IndustrialMachinery ManufacturingManufacturing
check
H1B Sponsor Likelynote

Responsibilities

Assess product security risks, develop comprehensive mitigation strategies, and evaluate technical and business trade-offs
Apply the Secure Development Lifecycle and lead product security processes including architectural analysis, threat modeling, security DFMEA, penetration testing, attack modeling and simulation, and data privacy impact assessments
Identify, evaluate, and verify security issues discovered through automated testing, penetration testing, and customer feedback. Maintain and track closure of vulnerability backlogs
Interpret and enforce product security requirements, conduct vulnerability reviews, and ensure compliance with industry regulations and standards (IEC 62443, ISO 21434, NIST, etc.)
Monitor outputs and effectiveness from all security tools integrated within the software development lifecycle
Advise, guide, and mentor cross-disciplinary engineering teams during the design, review, and implementation of security features
Validate that software meets all functional, security, regulatory (cybersecurity compliance), and quality benchmarks—particularly within industrial and transportation environments

Qualification

Embedded SystemsSecurity AnalysisVulnerability ManagementCompliance & StandardsDevOps & AutomationConnectivity ProtocolsProgramming LanguagesTechnical GuidanceCommunication & CollaborationContinuous Improvement

Required

Demonstrated expertise in securing embedded controls platforms, with hands-on knowledge of Embedded Linux (e.g., Yocto) and RTOS environments (e.g., FreeRTOS, Zephyr Project, MicroC/OS-II)
Strong grasp of static analysis (SAST) and software composition analysis techniques for vulnerability detection and remediation
Familiarity with modern DevOps pipelines and tools (e.g., GitHub Actions, Azure DevOps, GitLab CI), with practical knowledge of automated testing frameworks (e.g., CppUTest)
Effective communicator with strong organizational skills, adept at working with cross-functional teams and presenting technical risks to varied audiences
Commitment to ongoing learning and driving continuous maturity in product security processes and technical strategies
Assess product security risks, develop comprehensive mitigation strategies, and evaluate technical and business trade-offs
Apply the Secure Development Lifecycle and lead product security processes including architectural analysis, threat modeling, security DFMEA, penetration testing, attack modeling and simulation, and data privacy impact assessments
Identify, evaluate, and verify security issues discovered through automated testing, penetration testing, and customer feedback. Maintain and track closure of vulnerability backlogs
Interpret and enforce product security requirements, conduct vulnerability reviews, and ensure compliance with industry regulations and standards (IEC 62443, ISO 21434, NIST, etc.)
Monitor outputs and effectiveness from all security tools integrated within the software development lifecycle
Advise, guide, and mentor cross-disciplinary engineering teams during the design, review, and implementation of security features
Validate that software meets all functional, security, regulatory (cybersecurity compliance), and quality benchmarks—particularly within industrial and transportation environments

Preferred

Bachelor's or Master's degree in computer engineering, computer science, electrical engineering or related technical field with 5+ years of experience
Preferred that the candidate have experience as an embedded product security engineer
Experience with embedded software development and proficiency in relevant programming languages (e.g., C, C++, C#, Rust, Python)
Multi-region travel up to 5% may be required

Benefits

Health insurance
Holistic wellness programs
Family building benefits include fertility coverage and adoption/surrogacy assistance.
401K match up to 6%, plus an additional 2% core contribution = up to 8% company contribution.
Paid time off, including in support of volunteer and parental leave needs.
Educational and training opportunities through company programs along with tuition assistance and student debt support.

Company

Trane Technologies

company-logo
Trane Technologies develops energy efficient indoor environments for commercial and residential applications.

H1B Sponsorship

Trane Technologies has a track record of offering H1B sponsorships. Please note that this does not guarantee sponsorship for this specific role. Below presents additional info for your reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (46)
2024 (48)
2023 (28)
2022 (41)
2021 (33)
2020 (13)

Funding

Current Stage
Public Company
Total Funding
unknown
2020-03-17IPO

Leadership Team

leader-logo
David Regnery
Chief Executive Officer
linkedin
leader-logo
Victoria Lazar
SVP, General Counsel and Corporate Secretary
linkedin
Company data provided by crunchbase