Job Description
Role Profile: Senior Hardware, IoT & OT Security Specialist
n
Location: Pune, India
n
Reports to: Head – Cybersecurity / Engineering Security (To be finalized)
n
n
About Spiro
n
SPIRO is a Time 100 Influential Company 2024. Our mission is to accelerate access to affordable, clean energy technology in the mobility sector through excellent customer service and continued agility.
n
Currently building manufacturing and assembling facilities, SPIRO will be the first company to manufacture e-bikes and batteries in Africa, helping to solve import-export imbalances, unlocking economic growth and sustainable development. SPIRO is the largest EV company in Africa and is uniquely focused on Africa's clean industrialization through e-mobility technologies. Designed around swappable batteries and connected to SPIRO's extensive charging infrastructure, our different motorcycle models deliver clean transport built-for-purpose to address local market challenges.
n
n
Role Purpose
n
The Senior Hardware, IoT & OT Security Specialist will be responsible for securing Spiro's connected products, embedded systems, manufacturing environments, and cloud-connected ecosystems. This role will lead security architecture reviews, vulnerability assessments, penetration testing, threat modeling, and security assurance activities across hardware, firmware, IoT, Operational Technology (OT), and industrial systems.
n
The role plays a critical part in ensuring secure-by-design product development, protecting connected vehicle technologies, manufacturing infrastructure, and industrial control systems while maintaining compliance with global cybersecurity standards and industry best practices.
n
n
Key Accountabilities
n
Security Architecture & Product Security
n
n
- Conduct security architecture reviews for hardware, firmware, IoT devices, embedded systems, OT environments, and cloud-connected platforms.
n
- Define and implement secure-by-design principles across products, connected devices, and industrial environments.
n
- Lead product security assessments and security sign-offs for new technologies and product releases.
n
- Collaborate with engineering teams to embed cybersecurity throughout the product development lifecycle.
n
n
Vulnerability Assessment & Penetration Testing
n
n
- Perform vulnerability assessments, penetration testing, and ethical hacking across hardware, firmware, embedded systems,
IoT devices, and industrial control systems.
n
- Identify, prioritize, and manage security vulnerabilities while tracking remediation activities.
n
- Conduct threat modeling exercises to proactively identify security risks and mitigation strategies.
n
- Validate the effectiveness of implemented security controls.
n
n
Embedded & IoT Security
n
n
- Assess and strengthen embedded security mechanisms including Secure Boot, TPM, HSM, TrustZone, OP-TEE, and cryptographic implementations.
n
- Evaluate certificate management, device identity, secure communication protocols, and OTA (Over-the-Air) update mechanisms.
n
- Secure connected devices against emerging threats throughout the product lifecycle.
n
- Support firmware security reviews and embedded software hardening initiatives.
n
n
Operational Technology (OT) Security
n
n
- Support OT cybersecurity initiatives across manufacturing and industrial environments.
n
- Assess industrial network security, segmentation strategies, remote access security, and secure communication architectures.
n
- Strengthen Industrial Control Systems (ICS) security in line with ISA/IEC 62443 requirements.
n
- Collaborate with operations teams to improve the cybersecurity posture of manufacturing environments.
n
n
Compliance & Governance
n
n
- Ensure compliance with ISO 21434, ISA/IEC 62443, NIST Cybersecurity Framework, ISO 27001, GDPR, and internal security standards.
n
- Develop security recommendations aligned with regulatory and industry requirements.
n
- Support security audits, compliance reviews, and risk assessments.
n
n
Cross-functional Collaboration
n
n
- Partner with engineering, infrastructure, manufacturing, cloud, and operations teams to improve overall security posture.
n
- Provide technical guidance on secure product development and industrial cybersecurity.
n
- Promote cybersecurity awareness and secure engineering best practices across teams.
n
n
Experience
n
n
- 4–8 years of experience in Hardware Security, Embedded Systems Security, IoT Security,
OT/ICS Security, or Product Security.
n
- Proven experience conducting Vulnerability Assessments (VA), Penetration Testing (PT), ethical hacking, and security architecture reviews.
n
- Experience working with embedded systems, industrial control systems, and connected products.
n
- Exposure to cloud-connected IoT ecosystems and enterprise security practices is highly desirable.
n
- Experience within automotive, electric mobility, manufacturing, or industrial environments is preferred.
n
n
Capabilities
n
n
- Solid understanding of hardware, firmware, embedded systems, and IoT security principles.
n
- Expertise in threat modeling, vulnerability management, and security risk assessment.
n
- Knowledge of industrial protocols such as Modbus, OPC-UA, and Profinet.
n
- Familiarity with automotive and EV cybersecurity including telematics, Battery Management Systems (BMS), charging infrastructure, and vehicle connectivity.
n
- Strong analytical and problem-solving skills with the ability to identify and mitigate complex security risks.
n
- Excellent stakeholder management and cross-functional collaboration abilities.
n
- Effective communication skills with the ability to influence technical and non-technical stakeholders.
n
- Continuous learning mindset with awareness of evolving cybersecurity threats and technologies.
n
n
Education
n
n
- Bachelor's Degree in Cybersecurity, Computer Science, Engineering, or a related technical field.
n
- Relevant professional certifications such as OSCP, CEH, GICSP, ISA/IEC 62443, ISO 21434 , or equivalent are preferred.
n
- Additional certifications in cloud security, embedded systems, or ethical hacking are advantageous.
n
n
Technical Knowledge
n
n
- Hardware Security
n
- Embedded Systems Security
n
- Secure Boot, TPM, HSM, TrustZone, OP-TEE
n
- IoT Device Security
n
- OTA Security & Certificate Management
n
- Vulnerability Assessment & Penetration Testing (VA/PT)
n
- Threat Modeling
n
- Industrial Control Systems (ICS)
n
- OT Security
n
- CAN Bus Security
n
- Industrial Protocols (Modbus, OPC-UA, Profinet)
n
- Automotive & EV Cybersecurity
n
- Telematics & Battery Management Systems (BMS)
n
- Cloud Security
n
- ISO 21434
n
- ISA/IEC 62443
n
- ISO 27001
n
- NIST Cybersecurity Framework
n
- GDPR
n
- AI-assisted Security Testing & Automation Tools
n
n
📌 Senior Hardware, IoT & OT Security Specialist (Pune)
🏢 SPIRO
📍 Pune