Compliance and Risk Management Specialist

Dearborn, MI, US • Posted 6 hours ago • Updated 6 hours ago
Contract W2
12 Months
No Travel Required
On-site
Depends on Experience
Fitment

Dice Job Match Score™

👾 Reticulating splines...

Job Details

Skills

  • Cyber Security
  • Automotive Engineering
  • ISO 9000
  • ISO/IEC 27001:2005
  • NIST 800-53
  • Embedded Systems

Summary

Compliance and Risk Management Specialist
Dearborn, MI
12 Months

Description:We are seeking a Cybersecurity Key Provisioning Process Engineer to join our Vehicle Cybersecurity organization. This role sits at the intersection of automotive engineering, cryptographic security architecture, and manufacturing operations owning the end-to-end process by which cryptographic key material is defined, provisioned, and secured across every Electronic Control Unit (ECU) and vehicle program. The ideal candidate is a systems thinker who can translate cryptographic and security requirements into concrete engineering specifications, drive supplier accountability through audit and integration, and operate our backend Public Key Infrastructure (PKI) and Key Management System (KMS) to deliver secure keys at scale. This is a highly cross-functional role requiring fluency in cybersecurity engineering, supplier quality/manufacturing processes, and product key management systems. This role involves the development and governance of security policies and procedures, review of security controls and their efficiency, and monitoring processes for compliance risk and vulnerabilities. They also specialize in managing third party security risk programs

Skills Required:
Embedded Systems, Auditing, Cyber Security, Compliance Professional

Skills Preferred:
ISO 27001, Supply Chain Operations

Experience Required:

  • Own and facilitate the process for defining, documenting, and approving cryptographic key requirements (algorithms, key lengths, key hierarchies, usage policies, rotation/expiry rules) for each ECU type and vehicle program.
  • Serve as the central point of coordination between vehicle program teams, ECU feature owners, and cybersecurity architecture to ensure requirements are complete, consistent, and traceable across program timelines.
  • Conduct technical audits of Tier-1 supplier manufacturing sites and processes to validate conformance to our cybersecurity requirements.
  • Assess supplier readiness against Client cryptographic and secure manufacturing requirements; identify gaps and drive corrective action plans.
  • Establish and monitor supplier compliance metrics, escalating non-conformances through appropriate governance channels.
  • Partner with cybersecurity architects, ECU/software engineering teams, vehicle program management, procurement, and manufacturing to define cryptographic key requirements tailored to each ECU's function, threat model, and program constraints.
  • Orchestrate the technical implementation of approved key requirements within Client backend PKI and KMS infrastructure, coordinating with platform/IT teams responsible for these systems.
  • Define and manage key lifecycle workflows within the KMS in alignment with program and supplier timelines.
  • Troubleshoot and resolve issues in the key delivery pipeline between backend systems and supplier manufacturing lines.
  • Author clear, precise technical documentation, specifications, and work instructions covering cryptographic key requirements, provisioning processes, and PKI/KMS interfaces.
  • Cascade approved requirements to relevant internal teams and external suppliers, ensuring proper acknowledgment and implementation.
  • Enforce compliance with documented requirements through audits, design reviews, and program gate reviews; maintain version control and change management for all specifications.

Experience Preferred:

  • Familiarity with automotive cybersecurity standards (ISO/SAE 21434, UNECE R155/R156).
  • Hands-on experience with commercial or in-house PKI/KMS platforms (e.g., Thales, Entrust, HashiCorp Vault, AWS KMS, or automotive-specific secure provisioning platforms).
  • Experience with ECU/embedded systems development lifecycle and vehicle program timing
  • Knowledge of secure manufacturing/provisioning protocols (e.g., SHE, HSM-based key injection, secure flashing).
  • Project or process management experience (e.g., Agile, Six Sigma, or similar).
  • Experience with relevant control frameworks (e.g., NIST 800-53/800-57, ISO 27001, PCI-HSM, or automotive-specific key management security standards) is a plus.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: mirmi001
  • Position Id: 9052648
  • Posted 6 hours ago
Contact the job poster
SP

Sai Peri

Recruiter @ Miracle Software Systems, Inc.
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Dearborn, Michigan

Today

Full-time

Dearborn, Michigan

Today

Easy Apply

Full-time

$60 - $70 per hour

Ann Arbor, Michigan

Today

Full-time

USD 98,800.00 - 118,600.00 per year

Allen Park, Michigan

Today

Full-time

Search all similar jobs