We are seeking a Hands-On Automotive Cybersecurity Engineer to drive low-level security implementation and testing on physical Electronic Control Units (ECUs). This is an active execution role—not a process, governance, or compliance management position. You will write robust Embedded C/C++ code, configure microcontroller security peripherals, integrate Hardware Security Modules (HSM), and validate firmware security directly on hardware target benches.
Core Responsibilities
- Embedded Development: Write, maintain, and optimize production-grade Embedded C/C++ code for automotive ECUs running bare-metal or RTOS environments.
- HSM & Hardware Security: Integrate and configure Hardware Security Module (HSM) firmware stacks (e.g., Vector vHSM, ESCRYPT CycurHSM) and configure underlying silicon security hardware (SHE, HSM cores).
- Secure Boot & Firmware: Implement Root of Trust, Secure Boot mechanisms, and Secure Firmware Update (OTA/FOTA) pipelines.
- Diagnostics & Cryptography: Code UDS Security Access routines (Services $27 / $29) and implement cryptographic primitives (AES, RSA, ECC, CMAC) and key storage management.
- Bench Validation & Fuzzing: Perform active security testing, interface fuzzing, penetration testing, and vulnerability assessments using hardware trace tools and bus analyzers on real ECU targets.
Required Qualifications & Technical Skills
- Programming Languages: Advanced proficiency in Embedded C and Embedded C++.
- Microcontrollers: Hands-on development experience with 32-bit automotive microcontrollers such as Infineon AURIX (TC2x/TC3x/TC4x), NXP S32, Renesas RH850, STMicroelectronics (STM32), or TI AM26x.
- Security Stacks: Proven experience in one of the following domains:
- AUTOSAR Ecosystem: AUTOSAR Crypto Stack (vCSM, vCRY, vHSM, Vector Security Stacks).
- Non-AUTOSAR / Bare-Metal: Custom security implementations on RTOS/Bare-Metal architectures.
- Protocols & Diagnostics: Deep knowledge of UDS (ISO 14229) Security Access, CAN/CAN-FD, and cryptographic algorithms (AES-128/256, RSA, ECC, PKI).
- Validation & Debugging: Proficiency with Vector tools (CANoe, CANalyzer, vFlash), hardware debuggers (Lauterbach Trace32, JTAG), and fuzzing/vulnerability testing tools.