Why This Role Stands Out
Advance your career in automotive embedded security by performing cutting-edge penetration and fuzz testing on critical ECUs, a role perfect for experienced testers with a strong understanding of CAN protocols and connected technologies. This hybrid position offers a fantastic opportunity to develop your skills within a reputable company and contribute to the safety of future vehicles.
Quick Overview
Job Description
Job Title: Automotive Embedded Security Tester (BH ID) Location: Plymouth, MI Duration:2+ year contract
Key Requirements
- Automotive industry background required
- Experience with Electronic Control Units (ECUs)
- Strong understanding of CAN (Controller Area Network) protocols
Technical Skills
- Penetration testing experience
- Must have experience beyond fuzz testing
- Looking for candidates with security testing experience in one or more of the following areas:
- USB
- Wireless communications
- Bluetooth
- Similar embedded/connected device technologies
Position Notes: Embedded Security / Pen Testing Engineer
Automotive Embedded Security Tester (BH ID)
Embedded Systems Penetration & Fuzz Testing
- Design & Execute Campaigns: Build and execute comprehensive penetration testing campaigns against a wide variety of automotive embedded targets.
- Advanced Fuzzing: Configure and deploy targeted fuzzing frameworks (e.g., AFL++, libFuzzer, Peach, Defensics) against vehicle computers, ECUs, and clusters.
- Vulnerability Discovery: Uncover memory corruption vulnerabilities (buffer overflows, use-after-free), resource exhaustion, and complex logic flaws that automated static analyzers often miss.
Comprehensive Wireless & Wired Protocol Analysis
- Wired Vehicle Networks: Intercept, manipulate, and inject traffic across internal wired topologies, including CAN, CAN-FD, Automotive Ethernet (SOME/IP, DoIP), LIN, and FlexRay. You will utilize industry-standard tools like Vector CANoe/CANalyzer and Vehicle Spy.
- Wireless Ecosystems: Aggressively analyze and exploit vulnerabilities across every wireless communication interface. This includes deep-dive assessments of Bluetooth/BLE, Wi-Fi (802.11), Cellular networks (4G/LTE, 5G, and C-V2X), UWB, NFC, and traditional RF/Keyless Entry Systems (RKE/PEPS) using Software Defined Radios (SDRs like HackRF, USRP).
Hardware & Firmware Reverse Engineering
- Physical Attack Vectors: Conduct hands-on, hardware-level security testing to identify physical attack vectors.
- Hardware Debugging & Exploitation: Utilize tools like Logic Analyzers, Bus Pirate, J-Link, and UART/JTAG/SPI debuggers, side-channel analysis (SCA), and voltage/clock fault injection techniques.
- Firmware Analysis: Extract firmware from flash memory for subsequent reverse engineering and static analysis using disassemblers like IDA Pro.
AI-Enhanced Fuzzing and Vulnerability Discovery
- Develop and apply AI-driven fuzzing techniques, using machine learning to intelligently guide test case generation and uncover complex vulnerabilities in vehicle software.
- Utilize ML models to perform automated analysis of source code and binaries, identifying potential zero-day vulnerabilities that evade traditional static and dynamic analysis tools.
Automated Anomaly Detection in Vehicle Networks
- Implement and manage machine learning systems to analyze real-time data from CAN, Automotive Ethernet, and wireless channels, automatically detecting anomalous patterns indicative of a cyberattack.
Adversarial AI/ML System Testing
- Conduct security assessments of on-board AI/ML systems (e.g., those used for perception, sensor fusion, or decision-making in autonomous driving).
- Design and execute adversarial attacks (e.g., data poisoning, evasion attacks) to test the resilience and integrity of automotive AI models.
Strategic Remediation
- Actionable Reporting: Document findings in meticulous, highly technical reports that include mitigation strategies.
- Engineering Collaboration: Partner directly with other security tester/consultants to craft actionable, robust remediation strategies that fix the root cause of vulnerabilities.
What We Are Looking For
Experience & Education
- Bachelor's or Master's degree in Computer Science, Cybersecurity, Computer Engineering, or a heavily related technical discipline.
- Proven experience in applying AI/ML techniques to cybersecurity challenges, such as intelligent fuzzing, anomaly detection, or securing machine learning systems.
- 3+ years of hands-on experience in penetration testing, vulnerability research, or reverse engineering, specifically focused on automotive embedded systems, IoT devices, or specialized custom hardware.
Deep Technical Expertise & Certifications
- Deep understanding of automotive E/E architectures, RTOS (e.g., QNX, VxWorks, AUTOSAR OS), and POSIX-based systems (Automotive Linux).
- Familiarity with automotive microcontrollers (e.g., Infineon AURIX TriCore, Renesas RH850, ARM Cortex-R/M) and hardware security modules (HSM/SHE).
- Strong grasp of industry-standard cybersecurity regulations and frameworks, specifically ISO/SAE 21434, UNECE WP.29 R155, and MITRE Telecommunication&CK.
- Knowledge of common machine learning frameworks (e.g., TensorFlow, PyTorch, scikit-learn) and their application in a security context.
Understanding of adversarial ML concepts and defenses.
- Preferred Certifications: OSCP, OSCE, OSWE, eCPTX, GXPN, or specialized automotive/IoT security certifications.
Programming & Tooling Proficiency
- Proficiency in scripting and low-level programming languages such as Python, C/C++, Bash, or Assembly (ARM/x86/TriCore).
- Experience with data science and machine learning libraries within Python (e.g., Pandas, NumPy).
- Extensive hands-on experience with hardware/software testing tools (e.g., Oscilloscopes, Wireshark, Burp Suite, GNU Radio, Binwalk).
Similar jobs
- TE
Information Systems Security Manager (ISSM)
NewTekSynap
Fort Belvoir, Virginia🇺🇸$130k - $150k/yrHybrid1 hour agoData EntryTechnology - FO
Cyber Security Analyst
NewFedEx Office
Memphis, TN🇺🇸$7.1k/moHybrid16 hours agoExpressMFAMachine Learning+11Technology - FO
Sr Cyber Security Analyst
FedEx Office
Memphis, TN🇺🇸$9.2k - $16.6k/yrOn-site1 week agoSAFeDockerExpress+15Technology - RA
Senior Principal Software Security Engineer
NewRaytheon
Austin, TX🇺🇸$132.4k - $251.6k/yrHybrid16 hours agoScrumAgileC+++3Technology - RA
Embedded Security Software Engineer II (Onsite)
NewRaytheon
Miami, FL🇺🇸$68.9k - $131.1k/yrHybrid16 hours agoScrumAgileC+++3Technology - SE
Security Watch Center Analyst
NewSecuritas
Los Angeles, CA🇺🇸Hybrid2 days agoSchedulingAdministrative - SE
Global Security Operations Center Threat Monitoring Specialist
NewSecuritas
San Jose, CA🇺🇸Hybrid2 days agoMicrosoft OfficeTechnology - ST
Security Technician
Securitas Technology
West Palm Beach, FL🇺🇸On-site2 months agoMicrosoft OfficeAdministrative - ST
Security Technician
Securitas Technology
Orlando, FL🇺🇸On-site2 months agoMicrosoft OfficeAdministrative - AU
Security Solutions Engineer II
NewAllied Universal
Fort Myers, FL🇺🇸Hybrid16 hours agoLoad BalancingVMwareTechnology - SA
Information Systems Security Officer
NewSAIC
Chantilly, VA🇺🇸$120k - $160k/yrRemote16 hours agoSAFeAWSEncryption+3Technology - RA
Software Security Lead - Principal Software Engineer - S3E
NewRaytheon
Los Angeles, CA🇺🇸$107.5k - $204.5k/yrHybrid16 hours agoScrumAgileC+++3Technology