Hitachi Energy
R&D Product Security Engineer - Digital Service Solutions
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About Hitachi Energy
Hitachi Energy Ltd. is a global leader in electrification and power grid technologies, based in Zurich, Switzerland. As a subsidiary of Hitachi Ltd., the company employs over 50,000 people across 60 countries and generates approximately $16 billion in revenue. Established in 2020 through the acquisition of ABB's Power Grids division, Hitachi Energy focuses on sustainable energy solutions, including high-voltage equipment, transformers, automation, and digital technologies. The company provides essential products and services across the power value chain, emphasizing digital integration for utilities, industries, and infrastructure. Their offerings include ultra-high-voltage direct current systems, automation solutions for grid modernization, and digital tools for smart grids and asset monitoring. Hitachi Energy serves a diverse range of customers, including utilities and grid operators, and has been involved in notable projects such as the world's first 1,100 kV UHVDC line in China and renewable microgrids in Canada.
Security at Hitachi Energy
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
“Hitachi Energy frames cybersecurity as an ecosystem requirement, stating that 'the world needs a cybersecurity ecosystem for a resilient electric future.' Their product/software security services include 'Security assessment of your enterprise software applications and their supporting infrastructure.' Hitachi Energy also publishes a 'Digital Products Vulnerability Handling Policy'.”
Security Team
Job postings indicate product/security roles with SDLC and vulnerability handling responsibilities, such as ensuring 'a timely and consistent process for handling of security vulnerabilities in Enterprise Software Solutions products' and being 'Responsible for tracking, auditing and reporting as per internal Security Development Lifecycle.' A leadership role describes a 'fully remote, strategic leadership role with global visibility and six indirect reports.' Job postings also list familiarity with tools like 'OneTrust, Tenable, Lansweeper, Axonius, Azure DevOps, and Power BI.' Public leaders with security responsibilities include Joe Doetzl, who has 'Global responsibility for IT, OT and product security,' and Ranu Parmar, who 'led a panel on isolated recovery environments for cyber resilience.' However, an explicit AppSec team model (centralized vs. embedded) with authoritative org-chart statements is 'Information not publicly available'.
Key Initiatives
Product vulnerability handling processes are documented via a published policy, the 'Digital Products Vulnerability Handling Policy.' Job responsibilities include integrating security into development, specifically to 'Work collaboratively with the R&D team to ensure cybersecurity is integrated into the development process.' Security assessment service responsibilities also involve improving 'security assessment processes and ServiceNow workflows' and overseeing 'application onboarding, RFP responses, and tool integrations.' However, 'Evidence of a named Security Champions program' is 'Information not publicly available'.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.