Jobs and Careers
OS

Principal Cybersecurity Engineer

Oshkosh Corporation
Hagerstown, United Statesfull_timeVerifiedPosted 1 Apr 2025
💰 $231,400/yr($132,200/yr$231,400/yr)

About the role

At Oshkosh, we build, serve and protect people and communities around the world by designing and manufacturing some of the toughest specialty trucks and access equipment. We employ over 18,000 team members all united by a common purpose. Our engineering and product innovation help keep soldiers and firefighters safe, is critical in building and keeping communities clean and helps people do their jobs every day.

Oshkosh Corporation owns significant assets in the form of information. Some of these assets may lose substantial value if improperly disclosed, and such disclosure could result in significant harm to the organization. This role supports the Cybersecurity mission by partnering with the business as a trusted advisor to reduce cybersecurity risk to acceptable levels. Specifically, the role serves as a key mechanism to identify, maintain, and improve cybersecurity controls through a risk-based approach, while driving education and awareness to preserve the confidentiality, integrity, and availability of company information.

YOUR IMPACT

These duties are not meant to be all-inclusive; additional responsibilities may be assigned.

  • Serve as a cybersecurity expert or coach in areas including network and application design, operating systems, endpoint protection, mobile device security, and foundational cybersecurity controls across on-premises and cloud environments (IaaS, PaaS, SaaS). Conduct security assessments and recommend appropriate controls to ensure solutions meet regulatory, contractual, and corporate security policies.
  • Act as a trusted advisor to business functional areas (e.g., Finance, HR, Engineering) and internal Digital Technology (DT) teams (e.g., infrastructure, applications, services). Ensure alignment between business and technical requirements and compliance with regulatory and contractual obligations. Advocate for cybersecurity risk mitigation during planning and implementation of new services.
  • Provide cybersecurity consulting to a wide range of stakeholders, including business units with limited technical knowledge, technical teams with deep domain expertise, and cybersecurity professionals.
  • Collaborate with technology architects and analysts to ensure security is embedded in systems design and implementation, effectively mitigating identified risks while supporting business goals.
  • Maintain expert-level awareness of cybersecurity regulations and best practices, including CMMC, PCI, SOC, HIPAA, and NIST (800-53, 800-171).
  • Contribute to the development and continuous improvement of cybersecurity strategies and roadmaps. Develop and update metrics to measure the effectiveness of cybersecurity programs.
  • Support the Cybersecurity Education & Awareness (SEA) program by creating strategies and content to promote positive security behaviors and raise global awareness.
  • Use programming and scripting skills to automate tasks such as data parsing, reporting, and other repeatable workflows.
  • Support the Security Incident Response Team (SIRT) in detecting, responding to, and recovering from security incidents, employing risk-based strategies to limit impact and recurrence.
  • Collaborate with SIRT to enhance processes, procedures, and training materials—such as investigation playbooks—and participate in threat hunts and purple team exercises to deepen knowledge of the environment.

MINIMUM QUALIFICATIONS

  • Bachelor’s degree in Cybersecurity, Information Systems, or a related field, or equivalent experience.
  • Eight (8) or more years of cybersecurity experience.

STANDOUT QUALIFICATIONS

  • Graduate degree in Cybersecurity, Information Systems, Management, or related discipline.
  • Strong conceptual, analytical, and innovative problem-solving skills.
  • Demonstrated knowledge of security controls for networks, applications, and operating systems.
  • Excellent communication skills—both verbal (e.g., phone, one-on-one, group presentations) and written (e.g., email, reports, documentation)—across technical and non-technical audiences.
  • Experience leading or contributing to complex projects involving multiple technologies and lines of business.
  • Industry-recognized certifications (e.g., CISSP, CEH, GIAC, Security+, SSAP).
  • Experience identifying attacker techniques, including emerging vulnerabilities, attack vectors, and exploits.
  • In-depth knowledge of cybersecurity tools and systems, including SIEM, SOAR, IDS/IPS, honeypots, open-source intelligence (OSINT), and sandbox analysis tools.
  • Ability to obtain or maintain a U.S. Government Secret-level (or higher) security clearance.
  • Hands-on experience with: SIEM/SOAR platforms (e.g., Splunk, IBM QRadar, Palo Alto XSOAR)
  • Hands-on experience with: Iden

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Oshkosh Corporation

View company profile →