Skip to content

Open nowPosted 93 days ago

Principal Product Cybersecurity Assurance Engineer

humanoid103 open roles

Where
UK, London
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPrincipal Product Cybersecurity Assurance Engineerhumanoid · UK, London
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on humanoid's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 93 days ago

The posting

Here at Humanoid, we believe in a future where robots amplify human potential. That’s why we’ve set out on a mission to build the world’s most capable, commercially-scalable, and safe humanoid robots. We’re bringing that mission to life with HMND‑01 - our rapidly developed humanoid platform being deployed in real industrial environments - and we’re growing the team to take it even further.

ABOUT THE ROLE

We are seeking a Principal Product Cybersecurity Assurance Engineer with deep expertise in product security, threat modelling, and risk assurance for highly regulated electromechanical systems. In this role, you will lead the delivery of product cybersecurity across Humanoid's HMND 01 platform family — the Alpha Wheeled industrial robot and the Alpha Bipedal home robot — both powered by our KinetIQ VLM/VLA-based AI framework. Working alongside product, firmware, autonomy, and hardware teams as part of the Systems Engineering and Architecture Team, you will define and maintain the cybersecurity assurance strategy for all product security activities from first concept through post-market deployment. Security at Humanoid is an engineering discipline inseparable from functional safety and central to our mission of creating the world's most reliable, commercially scalable, and safe humanoid robots. To excel in this position, you must demonstrate the authority to influence security architecture decisions across complex, cross-functional programmes, the rigour to build defensible security cases for novel cyber-physical systems, and the leadership to grow and guide a cross team of security engineers operating at the frontier of robotics.

WHAT YOU'LL DO

- Team Leadership & Product Security Delivery - Lead and develop a cross-functional team of security engineers, maintaining accountability for the delivery of product security services within product teams throughout the HMND 01 development lifecycle. - Define product security requirements and advise development teams on suitable implementation standards, techniques, and toolchains for embedded and AI-enabled robotic systems. - Partner with cross-functional teams to develop security protocols, tools, and processes that keep HMND 01 technologies ahead of emerging threats — including attack surfaces specific to the KinetIQ AI inference pipeline and cloud-to-robot communication architecture. - Own and maintain key security artefacts for audit-ready cybersecurity documentation including Security Management Plans, Threat Analysis and Risk Assessment (TARA) reports, Risk Assessments, and Remediation Action Plans across both platforms. Security Assurance & Certification - Drive security assurance through the full product lifecycle, ensuring every HMND 01 design is robust, compliant, and resilient. Contribute to the continual improvement of security engineering capability across the organisation. - Ensure compliance with cybersecurity obligations under the EU Machinery Regulation 2023/1230 where cyber controls intersect with safety-critical functions and compliance to IEC 62443 (for industrial/OT product security), and the EU Cyber Resilience Act. - Provide independent Information Assurance (IA) reviews and risk assessments on complex, high-impact projects — with particular focus on cyber-physical systems where a digital compromise could result in physical harm to operators or end users. - Review and provide guidance on security risk assessments, risk mitigation plans, mitigation gap analysis, and security management documentation in support of system cybersecurity certification. Incident Response & Lifecycle Security - Establish and maintain a Product Security Incident Response (PSIR) process, encompassing coordinated vulnerability disclosure, patch deployment pipelines, and post-field incident analysis. - Define and oversee security monitoring requirements for deployed fleets, ensuring field data feeds back into risk files and security artefacts in line with post-market surveillance obligations. Commercial & Bid Support - Support the production of work package descriptions and cost estimates for product bids, services, and proposals that include product security scope. - Represent Humanoid's security posture in customer and partner engagements, including regulatory consultations and certification body interactions.

WHAT WE'RE LOOKING FOR

- Proven, hands-on experience with ISO 27001/27004/27005 and the NIST Risk Management Framework (RMF), applied to regulated hardware or embedded product programmes.

- Experience owning a security risk management system for highly regulated, safety-critical products — with background drawn from automotive, commercial vehicle, or industrial automation environments.

- Working knowledge of IEC 62443, with the ability to adapt ISO/SAE 21434 lifecycle methodologies to robotic or electromechanical product context.

- Solid understanding of engineering development lifecycles and how the product cybersecurity specialism aligns with systems engineering, functional safety, and hardware/software co-development.

- Ability to interpret Penetration Test reports and author Remediation Action Plans that address identified vulnerabilities in a structured, risk-prioritised manner.

- Clear, structured communication skills — able to articulate complex security risk arguments to both technical engineers and executive stakeholders with equal confidence.

Preferred:

- Familiarity with Threat Analysis and Risk Assessment (TARA) or equivalent threat modelling methodologies (STRIDE, PASTA) applied to embedded or OT/IT convergent systems.

- Understanding of secure-by-design principles for AI/ML-enabled systems, including securing inference pipelines, model integrity, and cloud-to-edge communication paths.

- Exposure to CAN bus, Ethernet backbone, or wireless interface security in mobile, vehicular, or robotic systems.

- Experience contributing to or establishing a Product Security Incident Response (PSIRT) process or coordinated vulnerability disclosure programme.

- Knowledge of UL 4600, UL 3300, or ISO 13482 and an appreciation of how cybersecurity evidence integrates into safety case arguments.

- Prior engagement with certification bodies (TUV, UL, BSI) or standards development organisations (ISO TC 184, IEC TC 65, SAE, IEEE RAS).

WHAT WE OFFER

- Competitive equity: stock options with meaningful upside as we scale.

- 30+ paid days off, including 23 days of annual leave, all UK bank holidays, and additional company closure days (including Christmas–New Year shutdown).

- Private healthcare, including virtual and in-person care.

- Pension scheme with 8% total contribution (5% employee, 3% employer) on full earnings.

- Free daily breakfast, catered lunch, and snacks in-office.

- Work at the frontier - collaborate daily with world-class engineers, researchers, and product experts building the next generation of AI and humanoid robotics.

- Real ownership - direct access to founding leadership, meaningful input on product direction, and the ability to drive key initiatives from day one.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against humanoid's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on humanoid's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    humanoid's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.