岗位描述
Responsibilities:
• Apply a strong understanding of automotive communication protocols (e.g. CAN, CAN-FD, Automotive Ethernet) to analyze and secure the in-vehicle networks.
• Conduct hands-on security assessments, including penetration testing and fuzz testing, to identify vulnerabilities in automotive hardware, firmware, software, and communication systems. Document findings and support remediation efforts.
• Actively participate in the technical implementation of cybersecurity measures for projects, ensuring adherence to security requirements and contributing to the successful integration of security features.
• Contribute to design reviews and architectural discussions by providing security input and ensuring that cybersecurity considerations are integrated early in the development lifecycle.
• Support the development, optimization, and lifecycle maintenance of in-vehicle security products, including in-vehicle IDPS and PKI systems.
• Develop cybersecurity requirements for emerging technologies, translating threat analysis and risk assessment (TARA) outcomes into actionable requirements, and collaborate with product teams to ensure requirements are correctly implemented.
• Research and monitor existing and upcoming automotive cybersecurity regulations and standards, and support gap analysis and validation testing to ensure vehicle features and products meet applicable regulatory and certification requirements.
Qualifications:
• Bachelor’s Degree in Cyberspace Security, Computer Science, Software Engineering or Electronics/Electrical Engineering.
• Over 4 years of experience in automotive product cybersecurity, including a minimum of 2 years specializing in in-vehicle and mobility cybersecurity.
• Ability to proactively identify potential security issues and areas for improvement, beyond simply completing assigned tasks.
• Taking full responsibility for the assigned cybersecurity tasks, ensuring quality, meeting deadlines, and following through on commitments.
• Demonstrating a strong drive to proactively learn new technologies, stay updated on emerging cybersecurity threats and best practices, and take on new challenges with minimal supervision.
• Clearly articulate technical cybersecurity concepts, findings (e.g. from penetration tests), and recommendations to peers and senior engineers in a concise and understandable manner.
• Actively participating in team discussions, contributing to shared goals, and supporting colleagues to achieve collective cybersecurity objectives.
• Proficient in Vehicle Type Approval technical assessment, testing, and validation processes for cybersecurity, ensuring compliance with China regulations (GB44495/44464).
• Ability to interpret complex regulatory texts, translate them into actionable engineering requirements, and lead teams through the compliance and homologation process
• Lead and conduct advanced threat modeling methodologies (e.g. ISO21434, STRIDE, Attack Trees, HEAVENS) specifically for both connected and non-connected vehicle components, systems, and end-to-end architectures.
• Hands-on experience in leading and performing sophisticated penetration tests against in-vehicle networks, diagnostic systems, and connected vehicle components (e.g. telematics units, infotainment, ADAS sensors).
• Lead the secure architectural design and review of complex automotive systems, ensuring security is "built-in" from concept phase for in-vehicle networks, ECUs, and connected services.
• Expert in in-vehicle communication protocols such as CAN, CAN-FD, Automotive Ethernet, and LIN, with an in-depth understanding of their specifications, security vulnerabilities (e.g. message injection, spoofing, DoS, replay attacks), and advanced countermeasures.
• Strong understanding of cryptographic primitives, key management, hardware security modules, and trusted platform modules.
• Hands-on experience in network analysis/fuzzing, reverse engineering, Static/Dynamic analysis and penetration test.
• Knowledge of various embedded operating systems (e.g. AUTOSAR, QNX, Android, Embedded Linux) and their security hardening.
• High proficiency in multiple programming languages (C, Java) for low-level embedded development, security tool creation, scripting, and automation of security tasks.