JOB DETAILS

Principal Product Cybersecurity Compliance Engineer

CompanyEnovation Controls LLC
LocationTulsa
Work ModeOn Site
PostedJune 2, 2026
About The Company
Enovation Controls is an innovative manufacturer of electronic controls and displays for diverse markets. We are an international leader in fully customized solutions for engines, engine-driven equipment, and specialty vehicles with a broad range of displays, controls, and instrumentation products. Long known as an industry leader for cutting-edge electronic control technology, Enovation Controls conquers complex system challenges by rapidly leveraging our product platforms and engineering expertise to deliver remarkable, integrated solutions. We thrive in markets that our competitors do not – by solving challenges like it's never been done before. We are driven to clear a path to our customers'​ success. We've built a company and culture by living out our core values. They are the cornerstone of our success. We earn our customers' trust by challenging convention and questioning everything to deliver the most technologically advanced, production-ready system solutions industry-wide. Across our entire organization, you will find exceptional people who we empower to unleash their potential and enrich lives. We strive to laugh often and find meaning in our individual and collective efforts and have fun while doing it. We believe that putting our full assets at the command of our employees can generate sizable success, and we take pride in fostering the success of our customers by doing the right thing -- every day. With our Murphy, High Country Tek, and Zero Off brands, we serve a variety of markets, including off-highway, recreational and commercial marine, power sports and specialty vehicles, agriculture and water pumping, power generation and industrial equipment. The company, a subsidiary of Helios Technologies (formerly Sun Hydraulics Corp.), employs an internationally diverse team to serve customers worldwide with global sales, manufacturing, and engineering operations. To learn more about our product offerings and solutions, please visit our website.
About the Role

Description

About Us  

Enovation Controls specializes in complex projects, offering unparalleled expertise and innovative solutions. As a turnkey provider, we are dedicated to delivering game-changing technology and exceeding expectations. Our commitment to excellence is embedded in our core values, and we seek individuals who resonate with our values and thrive in our dynamic environment. 

  

Culture

Enovation Controls has built a company and culture by living out our core values. We are looking for hungry, humble, and smart people who will embrace our core values and thrive in a fun and rewarding culture. Enovation Controls is a learning organization that conquers complexity with high expectations and performance. The company's teams are multi-disciplined and offer a wide variety of experiences. With diverse teams and a focus on high-performance standards, Great Place to Work has honored Enovation Controls as one of the Best Workplaces in Manufacturing & Production for six consecutive years.

  

Position Summary

Enovation Controls is seeking a Principal Product Cybersecurity Compliance Engineer that will be responsible for owning and driving the implementation, integration, and sustainment of product cybersecurity practices aligned with industry standards including ISA/IEC 62443, ISO/SAE 21434, UN R155, and the Cyber Resilience Act (CRA). This role is focused on product-level security and ensures that both hardware and software products are designed, developed, and maintained in compliance with applicable cybersecurity requirements.
 

This position operates with a high degree of autonomy and accountability, acting as the primary driver of cybersecurity process integration across the organization. While executive leadership maintains overall responsibility, this role is expected to independently execute, coordinate, and advance cybersecurity initiatives across engineering and product teams.
 

The role integrates cybersecurity processes into the organization’s Quality Implementation Procedures (QIP), updating governing documents and engineering practices to reflect risk-based security thinking. The position requires strong organizational discipline, the ability to extract and synthesize technical information from engineering teams, and excellent communication skills to align stakeholders and ensure consistent adoption of cybersecurity practices.
 

This role also supports customer-facing commercial activities by clearly communicating the company’s cybersecurity posture, maturity, and product-level security capabilities to build customer confidence and enable business growth. Product Management retains ownership of defining the minimum acceptable security posture for products; however, this role provides strong, influential technical input to shape those decisions. 


Safety Sensitive Designation

This position is designated as Safety Sensitive and is subject to applicable safety policies, which may include drug and alcohol testing in accordance with company policy and applicable law.


Key Job Responsibilities   

  • Own and drive the implementation of product cybersecurity standards (ISA/IEC 62443, ISO/SAE 21434, UN R155, CRA) across the organization. 
  • Lead the integration of cybersecurity requirements into QIP (Quality Implementation Procedure) documents and governing processes. 
  • Operate autonomously to plan, execute, and track cybersecurity compliance initiatives across engineering teams. 
  • Extract, organize, and synthesize technical information from engineering teams to support compliance documentation and decision-making. 
  • Establish structured processes for collecting, managing, and validating cybersecurity compliance evidence and artifacts. 
  • Own and maintain the centralized cybersecurity compliance database, ensuring all required artifacts are complete, current, and auditable. 
  • Define standards for what constitutes sufficient compliance evidence and ensure consistency across product lines. 
  • Evaluate whether design methods, controls, and mitigation strategies are sufficient to address identified threats and meet applicable cybersecurity standards. 
  • Assess the adequacy of compliance artifacts and evidence in demonstrating effective risk mitigation and standards alignment. 
  • Train and guide engineering, product, and cross-functional teams on cybersecurity requirements, expectations, and best practices. 
  • Collaborate with engineering teams to identify security risks and define appropriate mitigation strategies. 
  • Ensure risk-based thinking is incorporated into design procedures, discipline checklists, and engineering workflows. 
  • Provide strong technical input to Product Management on security levels and requirements during product definition. 
  • Lead product-focused threat modeling and risk assessments. 
  • Provide insight into penetration testing activities and ensure findings are properly understood and addressed. 
  • Support cybersecurity considerations throughout the full product lifecycle, including design, validation, release, and sustainment. 
  • Act as a central point of coordination across engineering, product, and compliance-related roles. 
  • Participate in customer-facing discussions to communicate cybersecurity posture, maturity, and compliance status. 
  • Support Sales and Business Development in commercial engagements by demonstrating cybersecurity capabilities and building customer confidence. 
  • Coordinate with external auditors and certification bodies to achieve cybersecurity certifications for the organization and its products. 
  • Prepare and deliver required documentation and evidence to support certification audits. 
  • Maintain cybersecurity certifications by managing periodic audits, updates, and continuous compliance activities. 
  • Own and maintain the Product Security File (PSF) for each product line, ensuring complete, traceable, and audit-ready documentation aligned with 62443, CRA, and customer expectations. 
  • Lead the definition and justification of Security Level Targets (SL-T) in partnership with Product Management and system engineering, ensuring decisions are risk-based and defensible. 
  • Establish and manage supplier cybersecurity requirements, including SBOM expectations, vulnerability disclosure timelines, and secure development attestations. 
  • Define and oversee the product vulnerability management process, including intake, triage, remediation planning, and coordinated disclosure. 
  • Ensure each product has a documented, feasible, and secure update and patching strategy that meets CRA and 62443 requirements. 
  • Monitoring relevant Common Vulnerabilities and Exposures (CVEs) affecting products, software components, and supplier technologies.
  • Assessing CVE applicability, risk, and remediation planning. 
  • Coordinating customer communication regarding vulnerabilities, mitigations, and remediation status 
  • Supporting contractual / regulatory vulnerability disclosure expectations. 

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Engineering, Electrical Engineering, Computer Science, or related field required. Advanced degree preferred. 
  • 8–12+ years of experience in product cybersecurity, embedded systems, or secure product development. 
  • Demonstrated ability to independently drive organizational change and execute complex cross-functional initiatives. 
  • Strong ability to extract, interpret, and document technical information from engineering teams. 
  • Excellent organizational skills with ability to manage large volumes of information and maintain structured compliance databases. 
  • Exceptional written and verbal communication skills, including customer-facing communication. 
  • Strong understanding of cybersecurity standards such as ISA/IEC 62443, ISO/SAE 21434, UN R155, and CRA. 
  • Experience evaluating the effectiveness of security controls, mitigations, and compliance evidence against defined standards. 
  • Experience integrating cybersecurity into product development processes and quality systems. 
  • Knowledge of embedded systems, firmware, software, and hardware security principles. 
  • Experience with threat modeling, risk assessment, and vulnerability analysis. 
  • Experience coordinating audits and working with external certification bodies. 
  • Experience working within structured engineering processes (e.g., V-model, gated development). 
  • Ability to operate effectively without direct authority and influence cross-functional teams. 
  • Demonstrated technical leadership and ability to represent cybersecurity capabilities externally. 
  • Experience with CVE monitoring, vulnerability disclosure practices, coordinated remediation, and customer cybersecurity communications. 

  

We are an equal opportunity employer and value diversity. All employment is decided on the basis of qualifications, merit and business need.

Key Skills
Product CybersecurityISA/IEC 62443ISO/SAE 21434UN R155Cyber Resilience ActThreat ModelingRisk AssessmentVulnerability ManagementEmbedded Systems SecurityCompliance AuditingSBOMCVE MonitoringTechnical DocumentationCross-functional LeadershipStakeholder ManagementProduct Lifecycle Security
Categories
EngineeringSecurity & SafetyTechnologyManufacturingSoftware
Job Information
📋Core Responsibilities
Drive the implementation and sustainment of product cybersecurity practices aligned with industry standards like ISA/IEC 62443 and the Cyber Resilience Act. Integrate security requirements into quality procedures and manage compliance evidence and vulnerability disclosure processes.
📋Job Type
full time
📊Experience Level
10+
💼Company Size
261
📊Visa Sponsorship
No
💼Language
English
🏢Working Hours
40 hours
Apply Now →

You'll be redirected to
the company's application page