Security Architect
Leads design and implementation of cybersecurity architectures for automotive systems, ensuring compliance with ISO/SAE 21434 and UN R155/156 standards. Requires 7+ years in embedded automotive security, systems programming in C/C++/Rust, and threat analysis expertise.
About the job
Responsibilities
- Develop cybersecurity architectures compliant with ISO/SAE 21434 engineering requirements and UN R155 Cybersecurity Management System (CSMS) mandates across all vehicle lifecycle phases (concept, development, production, operation, decommissioning)
- Implement UN R156-compliant Software Update Management Systems (SUMS) with secure OTA update mechanisms, cryptographic verification, and version control for automotive ECUs
- Conduct threat analysis and risk assessments (TARA) per ISO 21434 Annex C requirements, addressing 69 attack vectors identified in UN R155 Annex 5
- Design hardware-rooted security controls for automotive SoCs including secure boot, hardware security modules (HSM), and TEE implementations
- Collaborate with suppliers to ensure Tier 1/Tier 2 component security meets ISO 21434 supply chain requirements and UN R155 post-production obligations
- Develop automotive-specific security requirements for AI/ML systems in autonomous driving platforms, addressing model integrity and adversarial attack prevention
Requirements
- 7+ years of hands-on experience designing and deploying security solutions for embedded automotive systems, with proven expertise in:
- Automotive communication protocol security (CAN bus hardening, Ethernet intrusion detection)
- Cryptographic engineering for resource-constrained environments (ECC optimization, post-quantum crypto prototyping)
- Proficiency in automotive security toolchains:
- Embedded debug tools (JTAG, UART, Trace32)
- Vehicle network analysis (Vector CANoe, Wireshark dissectors for SOME/IP)
- ECU flashing and diagnostic tools (ODX/PDX scripting, UDS exploit development)
- Strong systems programming skills in C/C++/Rust for bare-metal and RTOS environments, with experience in:
- Secure over-the-air update implementations
- Real-time intrusion detection systems for vehicle networks
- Demonstrated ability to lead technical security initiatives, including:
- Threat modeling for complex automotive architectures
- Security code reviews for safety-critical embedded software
- Mentoring junior engineers in secure coding practices
- Familiarity with automotive development workflows: AUTOSAR Classic/Adaptive security components
Nice to have
- Contributions to open-source automotive security projects (e.g., OpenXC, SavvyCAN)
- Experience with autonomous vehicle sensor security (LiDAR/Camera spoofing countermeasures)
- Background in hardware security evaluation (glitching, fault injection, TEMPEST)
- Development of vehicle-specific penetration testing rigs (CAN bus injectors, ECU emulators)
- Public research on automotive vulnerabilities (CVEs, conference presentations, whitepapers)
- Secure boot implementation and hardware-rooted trust chains (HSM provisioning, TEE architectures)
- Reverse engineering and vulnerability research on automotive firmware (ARM Cortex-M/R, QNX, AUTOSAR)
- Experience with hardware security module integration
- Familiarity with CI/CD pipelines for ECU software with SBOM generation
- Familiarity with Hardware-in-the-loop (HIL) security testing
Compensation
Base salary range: $197,400 - $292,393 USD annually (full-time position)
Skills
Iso/Sae 21434, Un R155, Un R156, Can Bus, Ethernet, Cryptography, Ecc, Jtag, Uart, Trace32, Vector Canoe, Wireshark, C++, Rust, Autosar Classic/Adaptive
Similar jobs
Security Engineering jobsSenior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.
Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.
Own and advance the security of Anyscale’s production and multi-cloud infrastructure, including hardening, segmentation, Kubernetes runtime protection, and access controls. Requires 8+ years of security engineering experience and hands-on expertise with AWS, Azure, Kubernetes, and cloud security tooling.