Automotive Penetration Tester (Red Team)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+8 more
Job description
Born in Detroit with automotive expertise at our core, Block Harbor is on a mission to secure the future of mobility. Vehicles are no longer just mechanical transport - they are highly connected computers on wheels. We combine deep vehicle engineering knowledge with world-class offensive security to find and fix vulnerabilities before they ever hit the pavement. Powered by our proprietary Vehicle Security Engineering Cloud (VSEC), our award-winning Red Team rigorously tests vehicle components, systems, and cloud infrastructure for the worldâs most innovative automakers and tier-1 suppliers.
The Automotive Penetration Tester owns the full engagement lifecycle: scoping customer requirements, authoring proposals, executing hands-on technical assessments, and translating findings into clear, actionable guidance. If you thrive at the intersection of deep vehicle knowledge and adversarial thinking, this role was built for you.
We believe AI and automation are reshaping how security work gets done. Candidates who actively leverage LLMs and AI tooling to sharpen efficiency and accelerate research will have a distinct advantage here., We are looking for a relentless Automotive Penetration Tester to join our Red Team. In this role, you wonât just scan for vulnerabilities - you will actively reverse engineer, fuzz, and exploit embedded ECUs, telematics units, and vehicle network architectures. You will pair manual âcar hackingâ grit with our automated VSEC Test platform to deliver deep, compliant vulnerability analysis to North American OEMs and suppliers. If you are a security researcher who loves pulling apart hardware, dissecting binary structures, and finding the zero-days others miss, you belong at Block Harbor.
- Customer Engagement & Scoping: Partner with customers to understand their security objectives, vehicle architectures, and compliance requirements - translating technical needs into well-defined test scopes and accurate, compelling proposals.
- Proposal Development: Author clear and thorough penetration test proposals that articulate methodology, scope, timelines, and expected deliverables. Communicate the value of Block Harborâs approach in terms that resonate with both technical and non-technical stakeholders.
- Offensive Security Testing: Execute deep-dive, activity-based penetration tests across physical and wireless vehicle interfaces - including CAN, LIN, Automotive Ethernet, UDS, DoIP, Bluetooth, Wi-Fi, and Web APIs.
- Firmware & Software Reversing: Reverse engineer and perform binary composition analysis on embedded vehicle controllers to surface configuration flaws, logic bugs, and memory corruption vulnerabilities.
- Automated & Manual Fuzzing: Apply advanced fuzzing techniques to expose zero-day vulnerabilities and stability weaknesses in vehicle communication stacks and diagnostic services.
- VSEC Platform Utilization: Leverage Block Harborâs VSEC platform to accelerate test execution and centralize vulnerability management - and actively contribute feedback that shapes its development.
- Reporting & Remediation Support: Produce comprehensive, client-ready penetration test reports mapped to relevant regulatory frameworks (ISO/SAE 21434, UN R155, NIST). Present findings directly to customer engineering teams, clearly communicating technical risk and prioritized mitigation strategies.
- Community & Research: Represent Block Harbor in the broader automotive security ecosystem - including ASRG, DEF CON Car Hacking Village, and SAE international committees - through ongoing threat research and thought leadership.
Requirements
Do you have experience in Wi-Fi analyzers?, * Experience: 3+ years of professional experience in offensive security, penetration testing, or hardware security assessment within the automotive, embedded systems, or IoT domains.
- Protocols & Architecture: Hands-on expertise with vehicle electrical architectures (E/E) and protocols, particularly CAN/CAN-FD, UDS, and Automotive Ethernet.
- Tools of the Trade: Proficiency with hardware and network exploitation tools including Wireshark, Vector CANalyzer/CANoe, Ghidra, IDA Pro, JTAG/SWD debuggers, and software fuzzers.
- AI and LLM: Hands-on experience with AI and LLMs in a security or research context.
- Standards Knowledge: Working knowledge of automotive cybersecurity compliance frameworks, specifically ISO/SAE 21434 and UN R155.
- Mindset: A âSecurity-Alwaysâ ethic, sharp problem-solving instincts, and a collaborative approach that embodies our âfull throttle collaborationâ culture.
- Travel: Willingness to travel internationally.
Preferred / Nice-to-Have
- Experience with cloud platforms and API security
- Comfortable engaging directly with customers and presenting technical findings
Benefits & conditions
Pulled from the full job description
- Parental leave
- Health insurance
- Retirement plan
- 401(k) matching
- Paid time off
- Vision insurance
- Health savings account, * 401(k) matching
- Dental insurance
- Flexible spending account
- Health insurance
- Health savings account
- Paid time off
- Parental leave
- Retirement plan
- Vision insurance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
The 8 Best Code Testing Tools
Dev Digest 121 - AI goes offline
Dev Digest 138 - Are you secure about this?