Quick Overview
Job Description
Job Title: Automotive Embedded Security Tester (BH ID) Location: Plymouth, MI Duration:2+ year contract
Key Requirements
- Automotive industry background required
- Experience with Electronic Control Units (ECUs)
- Strong understanding of CAN (Controller Area Network) protocols
Technical Skills
- Penetration testing experience
- Must have experience beyond fuzz testing
- Looking for candidates with security testing experience in one or more of the following areas:
- USB
- Wireless communications
- Bluetooth
- Similar embedded/connected device technologies
Position Notes: Embedded Security / Pen Testing Engineer
Automotive Embedded Security Tester (BH ID)
Embedded Systems Penetration & Fuzz Testing
- Design & Execute Campaigns: Build and execute comprehensive penetration testing campaigns against a wide variety of automotive embedded targets.
- Advanced Fuzzing: Configure and deploy targeted fuzzing frameworks (e.g., AFL++, libFuzzer, Peach, Defensics) against vehicle computers, ECUs, and clusters.
- Vulnerability Discovery: Uncover memory corruption vulnerabilities (buffer overflows, use-after-free), resource exhaustion, and complex logic flaws that automated static analyzers often miss.
Comprehensive Wireless & Wired Protocol Analysis
- Wired Vehicle Networks: Intercept, manipulate, and inject traffic across internal wired topologies, including CAN, CAN-FD, Automotive Ethernet (SOME/IP, DoIP), LIN, and FlexRay. You will utilize industry-standard tools like Vector CANoe/CANalyzer and Vehicle Spy.
- Wireless Ecosystems: Aggressively analyze and exploit vulnerabilities across every wireless communication interface. This includes deep-dive assessments of Bluetooth/BLE, Wi-Fi (802.11), Cellular networks (4G/LTE, 5G, and C-V2X), UWB, NFC, and traditional RF/Keyless Entry Systems (RKE/PEPS) using Software Defined Radios (SDRs like HackRF, USRP).
Hardware & Firmware Reverse Engineering
- Physical Attack Vectors: Conduct hands-on, hardware-level security testing to identify physical attack vectors.
- Hardware Debugging & Exploitation: Utilize tools like Logic Analyzers, Bus Pirate, J-Link, and UART/JTAG/SPI debuggers, side-channel analysis (SCA), and voltage/clock fault injection techniques.
- Firmware Analysis: Extract firmware from flash memory for subsequent reverse engineering and static analysis using disassemblers like IDA Pro.
AI-Enhanced Fuzzing and Vulnerability Discovery
- Develop and apply AI-driven fuzzing techniques, using machine learning to intelligently guide test case generation and uncover complex vulnerabilities in vehicle software.
- Utilize ML models to perform automated analysis of source code and binaries, identifying potential zero-day vulnerabilities that evade traditional static and dynamic analysis tools.
Automated Anomaly Detection in Vehicle Networks
- Implement and manage machine learning systems to analyze real-time data from CAN, Automotive Ethernet, and wireless channels, automatically detecting anomalous patterns indicative of a cyberattack.
Adversarial AI/ML System Testing
- Conduct security assessments of on-board AI/ML systems (e.g., those used for perception, sensor fusion, or decision-making in autonomous driving).
- Design and execute adversarial attacks (e.g., data poisoning, evasion attacks) to test the resilience and integrity of automotive AI models.
Strategic Remediation
- Actionable Reporting: Document findings in meticulous, highly technical reports that include mitigation strategies.
- Engineering Collaboration: Partner directly with other security tester/consultants to craft actionable, robust remediation strategies that fix the root cause of vulnerabilities.
What We Are Looking For
Experience & Education
- Bachelor's or Master's degree in Computer Science, Cybersecurity, Computer Engineering, or a heavily related technical discipline.
- Proven experience in applying AI/ML techniques to cybersecurity challenges, such as intelligent fuzzing, anomaly detection, or securing machine learning systems.
- 3+ years of hands-on experience in penetration testing, vulnerability research, or reverse engineering, specifically focused on automotive embedded systems, IoT devices, or specialized custom hardware.
Deep Technical Expertise & Certifications
- Deep understanding of automotive E/E architectures, RTOS (e.g., QNX, VxWorks, AUTOSAR OS), and POSIX-based systems (Automotive Linux).
- Familiarity with automotive microcontrollers (e.g., Infineon AURIX TriCore, Renesas RH850, ARM Cortex-R/M) and hardware security modules (HSM/SHE).
- Strong grasp of industry-standard cybersecurity regulations and frameworks, specifically ISO/SAE 21434, UNECE WP.29 R155, and MITRE Telecommunication&CK.
- Knowledge of common machine learning frameworks (e.g., TensorFlow, PyTorch, scikit-learn) and their application in a security context.
Understanding of adversarial ML concepts and defenses.
- Preferred Certifications: OSCP, OSCE, OSWE, eCPTX, GXPN, or specialized automotive/IoT security certifications.
Programming & Tooling Proficiency
- Proficiency in scripting and low-level programming languages such as Python, C/C++, Bash, or Assembly (ARM/x86/TriCore).
- Experience with data science and machine learning libraries within Python (e.g., Pandas, NumPy).
- Extensive hands-on experience with hardware/software testing tools (e.g., Oscilloscopes, Wireshark, Burp Suite, GNU Radio, Binwalk).
Similar jobs
- LS
Corporate Security Subject Matter Expert (SME)
NewLumen Solutions Group Inc.
United States🇺🇸Hybrid23 hours agoAdministrative - AS
Professional - Procurement Specialist
NewApex Systems
Miami, FL🇺🇸$20 - $25/hrOn-site23 hours agoAdministrative - MA
Intrusions Management Chief with Security Clearance
NewMANTECH
Linthicum Heights, MD🇺🇸Hybrid23 hours agoAdministrative - MA
Quality Analysts with Security Clearance
NewMANTECH
halawa, HI🇺🇸Hybrid23 hours agoAdministrative - NG
Azure Engineer with Security Clearance
NewNasTech Global, Inc.
Washington, DC🇺🇸On-site23 hours agoScrumAgileAdministrative - TS
Research Assistant
NewTalent Software Services, Inc
Cambridge, MA🇺🇸On-site23 hours agoAdministrative