Automotive/IoT Security Engineer
The job description
Tech stack. CAN bus and automotive Ethernet, ISO/SAE 21434, UNECE R155 and R156, OTA update security, embedded Linux, threat analysis and risk assessment (TARA), Python, vehicle penetration testing tools
About the role
You will secure connected vehicles and IoT devices for an automotive technology company, where a exploited vulnerability can affect physical safety rather than merely compromising data. The team owns cybersecurity across electronic control units, telematics systems, companion mobile applications, and cloud backends. You will perform threat analyses, guide secure design, coordinate penetration testing, and build the evidence regulators demand. This role matters because governments now require cybersecurity engineering evidence for every vehicle sold, and your work is what stands between capable attackers and two tons of moving steel traveling on public roads. You will also coordinate continuously with safety engineering to align cybersecurity and functional safety evidence for every vehicle program.
What you will achieve
- Complete TARA assessments for every new vehicle platform, with identified risks tracked to verified mitigation before production approval.
- Implement secure OTA update pipelines featuring cryptographic signing, verification, and rollback protection across the entire vehicle fleet.
- Pass UNECE R155 cybersecurity audits with zero major nonconformities, maintaining certification continuously across model years.
- Discover and remediate ECU and telematics vulnerabilities through structured penetration testing conducted each model year.
- Build the vulnerability monitoring program tracking supplier hardware and software components across the vehicle's 15-year service life.
What you will bring
Must-haves
- 2 to 5 years in automotive cybersecurity, embedded security, or IoT security roles with shipped products.
- Working knowledge of ISO/SAE 21434 engineering processes and UNECE R155/R156 regulatory requirements.
- Understanding of in-vehicle network architectures: CAN, CAN FD, automotive Ethernet, and central gateway designs.
- Experience with secure OTA update design covering signing infrastructure, on-device verification, and rollback protection.
- Ability to perform or technically coordinate penetration testing of embedded and telematics systems.
- Familiarity with threat analysis and risk assessment methodologies built for cyber-physical systems.
- Documentation discipline producing evidence that satisfies both internal quality gates and external auditors.
Nice-to-haves
- Experience with AUTOSAR security modules or EVITA hardware security module concepts.
- Knowledge of functional safety standard ISO 26262 and its interfaces with cybersecurity engineering.
- Supplier security assessment experience across a multi-tier automotive supply chain.
- Familiarity with electric vehicle charging infrastructure security considerations.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta