JCB
Principal Engineer – Product Cybersecurity Compliance

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Salary: Competitive Salary
Contract Type: Full Time
Working Pattern: Permanent
The Opportunity – Principal Engineer – Product Cybersecurity Compliance
Click here for our Careers & Life at JCB pages
About the role:
We’re looking for a Principal Engineer – Product Cybersecurity Compliance, who’ll play a critical role in defining, governing and continuously improving JCB's product cybersecurity compliance and assurance framework.
As the Product Cybersecurity Compliance Owner, you’ll provide technical leadership and independent assurance across product programmes and suppliers, ensuring compliance with internal requirements, industry standards and emerging regulations. You'll be accountable for delivering evidence-based cybersecurity assessments, driving a culture of "no place for second best", and ensuring cybersecurity is embedded throughout the entire product lifecycle, including post-production activities.
This is a principal-level position that combines deep technical expertise with strategic leadership, influencing stakeholders across the business and providing direction to cybersecurity testing and vulnerability management activities. The role is instrumental in ensuring JCB's readiness for evolving regulatory requirements, including the Cyber Resilience Act (CRA) and associated reporting obligations.
What does this role involve day to day?
Lead Product Cybersecurity Governance & Compliance
- Own and maintain JCB's product cybersecurity governance and assurance framework, ensuring alignment with wider engineering compliance processes.
- Develop and maintain standards, templates, checklists and guidance to support consistent cybersecurity compliance across product programmes.
- Create and deliver training, coaching and enablement activities that help engineering teams achieve compliance requirements efficiently and effectively.
- Provide mentorship and expert guidance on cybersecurity assurance, governance and regulatory interpretation.
Deliver Independent Compliance Assessment & Assurance
- Plan and conduct cybersecurity compliance assessments for product programmes and suppliers, identifying risks, gaps and improvement opportunities.
- Assess compliance against internal cybersecurity requirements and external standards and regulations, including ISO/SAE 21434, ISO 24882, IEC 62443 and the Cyber Resilience Act.
- Review key cybersecurity work products, including Threat Analysis and Risk Assessments (TARA), cybersecurity requirements, architecture evidence, verification strategies and residual risk documentation.
- Work collaboratively with engineering, software, systems, verification, manufacturing, service and supplier teams to drive closure of findings.
- Act as the escalation point for complex cybersecurity compliance, assurance and regulatory challenges.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Provide Technical Leadership for Cybersecurity Testing & Assurance
- Define cybersecurity testing expectations, ensuring appropriate coverage, methodologies, reporting and remediation tracking.
- Coordinate cybersecurity testing and Red Team assurance activities to support compliance objectives and evidence generation.
- Identify and address gaps in testing capability and assurance coverage.
Strengthen Vulnerability Management & Post-Production Assurance
- Establish and oversee governance for post-production vulnerability management activities.
- Ensure vulnerabilities from suppliers, security researchers, testing activities and PSIRT processes are appropriately monitored, assessed and routed.
- Support Cyber Resilience Act readiness, including Article 14 reporting workflows and response processes for critical vulnerabilities.
- Capture lessons learned and embed improvements into standards, guidance, checklists and training materials.
This will be suited to you if…
- You have extensive experience within an OEM, Tier 1 supplier, or similar embedded systems environment, working in cybersecurity, systems engineering, compliance or assurance.
- You have proven experience in product cybersecurity governance, assurance, compliance assessment or cybersecurity auditing for embedded or cyber-physical products.
- You possess strong working knowledge of ISO/SAE 21434 and ISO 24882 and can translate regulatory and standards requirements into practical engineering processes.
- You have experience reviewing and assessing cybersecurity evidence, identifying risks and driving corrective actions with stakeholders.
- You are an excellent communicator with the ability to influence, challenge and support teams at all levels.
- You are recognised as a technical specialist who can lead and drive improvements without direct authority.
- You are analytical, pragmatic and comfortable making risk-based decisions.
- You enjoy mentoring others and helping teams build cybersecurity capability.
- You are self-motivated, resilient and committed to continuous improvement.
Even better if…
- You have experience with Threat Analysis and Risk Assessment (TARA) methodologies and threat modelling techniques.
- You have knowledge of vulnerability management processes and post-production cybersecurity governance.
- You have experience of cybersecurity requirements engineering and cybersecurity testing activities, including evidence generation and assessment.
- You understand the relationship between Functional Safety and Cybersecurity.
- You have experience of embedded product technologies, including ECUs, CAN, J1939 and diagnostic protocols such as UDS.
- You have knowledge of IEC 62443 and supplier cybersecurity assurance practices.
- You are familiar with Cyber Resilience Act requirements and product security reporting obligations.
- You have experience working with Software Bill of Materials (SBOMs) and vulnerability monitoring processes.
- You have strong technical writing skills and are comfortable producing governance, assurance and compliance documentation.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
This role offers an excellent opportunity to shape the future of product cybersecurity compliance at JCB, influencing engineering excellence across the organisation while helping ensure our products remain secure, compliant and trusted by customers worldwide.
What happens next?
Ordinarily, our Resourcing Team reviews and shortlists CVs. If shortlisted, you’ll speak to one of our Recruiters to discuss the role further. Our interview process usually consists of an initial team’s interview followed by an in-person interview. We’ll keep in touch throughout the process but if you have any questions, please get in touch at recruitment@jcb.com
What’s in it for you?
This is your chance to join a company that values expertise not only in rewards but also in real employee care. At JCB you don’t just get a competitive salary, 33 days’ holiday and access to our company pension—you can also use our onsite gym, in-house doctor and dentist. We have an ULEV car scheme available for our employees too. Then there’s the JCB Rewards Hub, which gives you discounts with high street retailers. Feel like biking to work? There’s our Cycle to Work Scheme.
We value diversity and welcome applications from candidates from all backgrounds.
We’re committed to ensuring our recruitment process is fair and inclusive. If you face any accessibility challenges with your online application and require additional support, you have the option of speaking to a member of our Recruitment Team who can support you to complete an application in an alternative format. If you would benefit from this support, please email recruitment@jcb.com, and a member of the team will be in touch.
Recruitment Agencies: JCB does not accept any speculative approaches to present candidates for advertised vacancies.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills