Product Cybersecurity Engineer at May Mobility
$100,000–$155,000
Jul 12, 2026
—
Jul 21, 2026
What this job asks for AI summary
A product security engineering role focused on embedding cybersecurity across the full development lifecycle of vehicle and autonomous systems. Day-to-day work spans threat modeling, TARA/HARA analyses, security architecture reviews, SBOM/HBOM management, and vulnerability tracking, with close collaboration across hardware, software, and safety teams. Suits early-career engineers with grounding in automotive protocols, cybersecurity standards such as ISO 21434, and hands-on experience with SBOMs and attack surface analysis.
Mid level · 1+ years · Remote · Bachelor's required · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Rare in this occupation — lead with these, and say what you built with them.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The experience range in the JD is written as '[1-3] years' — the bracket notation suggests a placeholder that was never finalized; the overall years minimum is set to 1 (the stated minimum).
The role sits at the intersection of product/embedded security and information security analysis; 15-1212 (Information Security Analysts) was chosen as the primary code because the dominant work is security analysis, compliance, and vulnerability management rather than software development. 15-1299 (Computer Occupations, All Other) is the runner-up given the strong automotive/embedded-systems specialization that doesn't map cleanly to any single SOC.
CAN, LIN, and Ethernet are listed together as vehicle communication protocols under a single familiarity requirement; CAN is used as the primary skill name with LIN and Ethernet as alternatives.
SPDX and CycloneDX are listed as interchangeable SBOM format options; SPDX is the primary with CycloneDX as the alternative.
R155/R156 and UL 4600 appear in the required qualifications section alongside ISO 21434 and UNECE WP.29, but are framed as 'maintain working knowledge of' rather than demonstrated experience — treated as required given their placement in the Required block.
AUTOSAR, CANalyzer/Wireshark, JTAG, and penetration testing all appear under the 'Desirable' heading and are marked preferred accordingly.
No compensation figures are provided in the posting.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.