Haystack
← Back to Jobs
Other

Compliance and Risk Management Specialist

Miracle Software Systems, Inc.Dearborn, MI🇺🇸United StatesPosted 11 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Compliance and Risk Management Specialist
Dearborn, MI
12 Months

Description:We are seeking a Cybersecurity Key Provisioning Process Engineer to join our Vehicle Cybersecurity organization. This role sits at the intersection of automotive engineering, cryptographic security architecture, and manufacturing operations owning the end-to-end process by which cryptographic key material is defined, provisioned, and secured across every Electronic Control Unit (ECU) and vehicle program. The ideal candidate is a systems thinker who can translate cryptographic and security requirements into concrete engineering specifications, drive supplier accountability through audit and integration, and operate our backend Public Key Infrastructure (PKI) and Key Management System (KMS) to deliver secure keys at scale. This is a highly cross-functional role requiring fluency in cybersecurity engineering, supplier quality/manufacturing processes, and product key management systems. This role involves the development and governance of security policies and procedures, review of security controls and their efficiency, and monitoring processes for compliance risk and vulnerabilities. They also specialize in managing third party security risk programs

Skills Required:
Embedded Systems, Auditing, Cyber Security, Compliance Professional

Skills Preferred:
ISO 27001, Supply Chain Operations

Experience Required:

  • Own and facilitate the process for defining, documenting, and approving cryptographic key requirements (algorithms, key lengths, key hierarchies, usage policies, rotation/expiry rules) for each ECU type and vehicle program.
  • Serve as the central point of coordination between vehicle program teams, ECU feature owners, and cybersecurity architecture to ensure requirements are complete, consistent, and traceable across program timelines.
  • Conduct technical audits of Tier-1 supplier manufacturing sites and processes to validate conformance to our cybersecurity requirements.
  • Assess supplier readiness against Client cryptographic and secure manufacturing requirements; identify gaps and drive corrective action plans.
  • Establish and monitor supplier compliance metrics, escalating non-conformances through appropriate governance channels.
  • Partner with cybersecurity architects, ECU/software engineering teams, vehicle program management, procurement, and manufacturing to define cryptographic key requirements tailored to each ECU's function, threat model, and program constraints.
  • Orchestrate the technical implementation of approved key requirements within Client backend PKI and KMS infrastructure, coordinating with platform/IT teams responsible for these systems.
  • Define and manage key lifecycle workflows within the KMS in alignment with program and supplier timelines.
  • Troubleshoot and resolve issues in the key delivery pipeline between backend systems and supplier manufacturing lines.
  • Author clear, precise technical documentation, specifications, and work instructions covering cryptographic key requirements, provisioning processes, and PKI/KMS interfaces.
  • Cascade approved requirements to relevant internal teams and external suppliers, ensuring proper acknowledgment and implementation.
  • Enforce compliance with documented requirements through audits, design reviews, and program gate reviews; maintain version control and change management for all specifications.

Experience Preferred:

  • Familiarity with automotive cybersecurity standards (ISO/SAE 21434, UNECE R155/R156).
  • Hands-on experience with commercial or in-house PKI/KMS platforms (e.g., Thales, Entrust, HashiCorp Vault, AWS KMS, or automotive-specific secure provisioning platforms).
  • Experience with ECU/embedded systems development lifecycle and vehicle program timing
  • Knowledge of secure manufacturing/provisioning protocols (e.g., SHE, HSM-based key injection, secure flashing).
  • Project or process management experience (e.g., Agile, Six Sigma, or similar).
  • Experience with relevant control frameworks (e.g., NIST 800-53/800-57, ISO 27001, PCI-HSM, or automotive-specific key management security standards) is a plus.

Skills

AWS
Embedded Systems
Agile
Auditing
Compliance
Concrete
PKI
Procurement
Risk Management
Six Sigma
Vault

Similar jobs