Automotive Embedded Security Tester
Sunrise Systems, Inc
Plymouth, MI, United States
2 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.thejobnetwork.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Testing (Software)
4G (Telecommunication)
LTE (Telecommunication)
Artificial Intelligence
Software System Penetration Testing
ARM Architecture
AUTomotive Open System Architecture (AUTOSAR)
Bash Shell
Bluetooth
Burp Suite
C++ (Programming Language)
Cellular Networks
+41 more
Static Program Analysis
Cyber Security
Computer Programming
Computer Engineering
Linux
Firmware
Flash Memory
FlexRay
Fuzz Testing
Hardware Security Module
Joint Test Action (IEEE Standards)
Python (Programming Language)
Machine Learning
NumPy
QNX (Software)
Posix
Real-Time Operating Systems
Tensorflow
Reverse Engineering
Sensor Fusion
System Programming
System Testing
Test Case
Wireshark
Universal Asynchronous Receiver/Transmitter
VxWorks
Wi-Fi Technology
Scripting
Pytorch
Advanced Reports
Pandas
Scikit Learn
Information Technology
IDA Pro
GNU Operating System
Real Time Data
Machine Learning Operations
IoT Security
Canoe Software
Hardware Debugging
Vulnerability Analysis
Job description
- Design & Execute Campaigns: Build and execute comprehensive penetration testing campaigns against a wide variety of automotive embedded targets.
- Advanced Fuzzing: Configure and deploy targeted fuzzing frameworks (e.g., AFL++, libFuzzer, Peach, Defensics) against vehicle computers, ECUs, and clusters.
- Vulnerability Discovery: Uncover memory corruption vulnerabilities (buffer overflows, use-after-free), resource exhaustion, and complex logic flaws that automated static analyzers often miss.
Comprehensive Wireless & Wired Protocol Analysis
- Wired Vehicle Networks: Intercept, manipulate, and inject traffic across internal wired topologies, including CAN, CAN-FD, Automotive Ethernet (SOME/IP, DoIP), LIN, and FlexRay. You will utilize industry-standard tools like Vector CANoe/CANalyzer and Vehicle Spy.
- Wireless Ecosystems: Aggressively analyze and exploit vulnerabilities across every wireless communication interface. This includes deep-dive assessments of Bluetooth/BLE, Wi-Fi (802.11), Cellular networks (4G/LTE, 5G, and C-V2X), UWB, NFC, and traditional RF/Keyless Entry Systems (RKE/PEPS) using Software Defined Radios (SDRs like HackRF, USRP).
Hardware & Firmware Reverse Engineering
- Physical Attack Vectors: Conduct hands-on, hardware-level security testing to identify physical attack vectors.
- Hardware Debugging & Exploitation: Utilize tools like Logic Analyzers, Bus Pirate, J-Link, and UART/JTAG/SPI debuggers, side-channel analysis (SCA), and voltage/clock fault injection techniques.
- Firmware Analysis: Extract firmware from flash memory for subsequent reverse engineering and static analysis using disassemblers like IDA Pro.
AI-Enhanced Fuzzing and Vulnerability Discovery
- Develop and apply AI-driven fuzzing techniques, using machine learning to intelligently guide test case generation and uncover complex vulnerabilities in vehicle software.
- Utilize ML models to perform automated analysis of source code and binaries, identifying potential zero-day vulnerabilities that evade traditional static and dynamic analysis tools.
Automated Anomaly Detection in Vehicle Networks
- Implement and manage machine learning systems to analyze real-time data from CAN, Automotive Ethernet, and wireless channels, automatically detecting anomalous patterns indicative of a cyberattack.
Adversarial AI/ML System Testing
- Conduct security assessments of on-board AI/ML systems (e.g., those used for perception, sensor fusion, or decision-making in autonomous driving).
- Design and execute adversarial attacks (e.g., data poisoning, evasion attacks) to test the resilience and integrity of automotive AI models.
Strategic Remediation
- Actionable Reporting: Document findings in meticulous, highly technical reports that include mitigation strategies.
- Engineering Collaboration: Partner directly with other security tester/consultants to craft actionable, robust remediation strategies that fix the root cause of vulnerabilities.
Requirements
- Automotive industry background required
- Experience with Electronic Control Units (ECUs)
- Strong understanding of CAN (Controller Area Network) protocols
Technical Skills
- Penetration testing experience
- Must have experience beyond fuzz testing
- Looking for candidates with security testing experience in one or more of the following areas:
- USB
- Wireless communications
- Bluetooth
- Similar embedded/connected device technologies, * Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Computer Engineering, or a heavily related technical discipline.
- Proven experience in applying AI/ML techniques to cybersecurity challenges, such as intelligent fuzzing, anomaly detection, or securing machine learning systems.
- 3+ years of hands-on experience in penetration testing, vulnerability research, or reverse engineering, specifically focused on automotive embedded systems, IoT devices, or specialized custom hardware.
Deep Technical Expertise & Certifications
- Deep understanding of automotive E/E architectures, RTOS (e.g., QNX, VxWorks, AUTOSAR OS), and POSIX-based systems (Automotive Linux).
- Familiarity with automotive microcontrollers (e.g., Infineon AURIX TriCore, Renesas RH850, ARM Cortex-R/M) and hardware security modules (HSM/SHE).
- Strong grasp of industry-standard cybersecurity regulations and frameworks, specifically ISO/SAE 21434, UNECE WP.29 R155, and MITRE Telecommunication&CK.
- Knowledge of common machine learning frameworks (e.g., TensorFlow, PyTorch, scikit-learn) and their application in a security context.
Understanding of adversarial ML concepts and defenses.
- Preferred Certifications: OSCP, OSCE, OSWE, eCPTX, GXPN, or specialized automotive/IoT security certifications.
Programming & Tooling Proficiency
- Proficiency in scripting and low-level programming languages such as Python, C/C++, Bash, or Assembly (ARM/x86/TriCore).
- Experience with data science and machine learning libraries within Python (e.g., Pandas, NumPy).
- Extensive hands-on experience with hardware/software testing tools (e.g., Oscilloscopes, Wireshark, Burp Suite, GNU Radio, Binwalk).
About the company
Founded in 1990, Sunrise Systems is an award winning IT/Professional Staffing firm to Fortune 500 and State/Local Government Agencies.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.thejobnetwork.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
over 1 year ago
LM
Luis Minvielle
The 8 Best Code Testing Tools
over 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
CH
Chris Heilmann
Dev Digest 138 - Are you secure about this?
almost 2 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
LM
Luis Minvielle
Is Software Engineering Over-Saturated?
over 2 years ago