About the RoleWe are expanding our established security team-currently composed of 4 security professionals-by adding a hands-on
Cybersecurity Compliance Specialist to help govern and scale cyber resilience across a large portfolio of 150+ products. In this role, you will partner closely with embedded software engineers, security leads, and product managers to follow established processes, evaluate vulnerabilities, manage security backlogs, and ensure seamless alignment with secure software development life cycle (SDLC) practices. This is an exciting opportunity for someone deeply interested in cybersecurity to support regulatory compliance without impeding delivery velocity.
Key Responsibilities- Security Program & Backlog Management: Create, manage, and track the security backlog for embedded software products, ensuring traceability, on-time delivery of security artifacts, and alignment with cyber resilience project plans.
- Vulnerability & Threat Assessment: Help teams understand where vulnerabilities fit within the architecture, utilizing tools like SD Elements to support threat modeling, SBOM tracking, and risk remediation.
- Process & Compliance Facilitation: Help engineering teams meet strict regulatory and internal compliance standards (such as IEC 62443 industrial control security standards) while maintaining high delivery speed and following established processes.
- Cross-Functional Coordination: Provide administrative and technical support to senior security leads and engineering managers, facilitate planning sessions, track remediation items, and manage project metrics/dashboards.
Requirements- Education: Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or a related technical field.
- Experience: 2+ years of professional cybersecurity experience with a strong focus on the software side, including knowledge of secure SDLC practices, vulnerability analysis, and threat modeling.
- Technical Tools & Standards: Hands-on experience with threat modeling and secure design tools (such as SDElements). Familiarity with IEC 62443 / EN 62443 standards for industrial automation and control systems (IACS) is considered a strong plus.
- Certifications: Any professional security certifications are highly preferred.
- Core Competencies: A genuine passion for cybersecurity, exceptional organizational skills, and clear communication capabilities to collaborate effectively across a global team.
Equal Opportunity Employer / Disabled / Protected Veterans
The Know Your Rights poster is available here:
_EEOC_KnowYourRights6.12.pdf
The pay transparency policy is available here:
_%20English_formattedESQA508c.pdf
For temporary assignments lasting 13 weeks or longer, AllSTEM Connections is pleased to offer major medical, dental, vision, 401k and any statutory sick pay where required.
We are committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation for any part of the employment process, please contact your staffing representative who will reach out to our HR team.
AllSTEM Connections participates in the E-Verify program in certain locations as required by law. Learn more about the E-Verify program.
_Participation_Poster_ES.pdf
We also consider for employment qualified applicants regardless of criminal histories, consistent with legal requirements, including, if applicable, the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance. Pursuant to applicable state and municipal Fair Chance Laws and Ordinances, we will consider for employment-qualified applicants with arrest and conviction records, including, if applicable, the San Francisco Fair Chance Ordinance. For Los Angeles, CA applicants: Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
Additional Skills(none specified)
AllSTEM Representative Contact InfoAccount Executive: Nichols
Branch Phone: Location: Ontario, CA