> Markdown version of [/jobs/ext/541199-automotive-penetration-tester-red-team](https://www.wearedevelopers.com/jobs/ext/541199-automotive-penetration-tester-red-team). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Automotive Penetration Tester (Red Team) - **Company:** Block, Inc. - **Location:** Detroit, MI, United States - **Experience:** Experienced - **Salary:** $80,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Bluetooth, Cloud Computing, Firmware, Fuzz Testing, Hardware Security Module, Joint Test Action (IEEE Standards), Network Architecture, Red Team (Cyber Security), Reverse Engineering, Test Execution Engine, Wireshark, Software Vulnerability Management, Wi-Fi Technology, Large Language Models, Software Security, IDA Pro, Vulnerability Analysis, Web Api - **Published:** June 5, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=7c5fc0483df0ad23 ## About the Role Do you have experience in Wi-Fi analyzers?, * Experience: 3+ years of professional experience in offensive security, penetration testing, or hardware security assessment within the automotive, embedded systems, or IoT domains. * Protocols & Architecture: Hands-on expertise with vehicle electrical architectures (E/E) and protocols, particularly CAN/CAN-FD, UDS, and Automotive Ethernet. * Tools of the Trade: Proficiency with hardware and network exploitation tools including Wireshark, Vector CANalyzer/CANoe, Ghidra, IDA Pro, JTAG/SWD debuggers, and software fuzzers. * AI and LLM: Hands-on experience with AI and LLMs in a security or research context. * Standards Knowledge: Working knowledge of automotive cybersecurity compliance frameworks, specifically ISO/SAE 21434 and UN R155. * Mindset: A "Security-Always" ethic, sharp problem-solving instincts, and a collaborative approach that embodies our "full throttle collaboration" culture. * Travel: Willingness to travel internationally. Preferred / Nice-to-Have * Experience with cloud platforms and API security * Comfortable engaging directly with customers and presenting technical findings ## Description Born in Detroit with automotive expertise at our core, Block Harbor is on a mission to secure the future of mobility. Vehicles are no longer just mechanical transport - they are highly connected computers on wheels. We combine deep vehicle engineering knowledge with world-class offensive security to find and fix vulnerabilities before they ever hit the pavement. Powered by our proprietary Vehicle Security Engineering Cloud (VSEC), our award-winning Red Team rigorously tests vehicle components, systems, and cloud infrastructure for the world's most innovative automakers and tier-1 suppliers. The Automotive Penetration Tester owns the full engagement lifecycle: scoping customer requirements, authoring proposals, executing hands-on technical assessments, and translating findings into clear, actionable guidance. If you thrive at the intersection of deep vehicle knowledge and adversarial thinking, this role was built for you. We believe AI and automation are reshaping how security work gets done. Candidates who actively leverage LLMs and AI tooling to sharpen efficiency and accelerate research will have a distinct advantage here., We are looking for a relentless Automotive Penetration Tester to join our Red Team. In this role, you won't just scan for vulnerabilities - you will actively reverse engineer, fuzz, and exploit embedded ECUs, telematics units, and vehicle network architectures. You will pair manual "car hacking" grit with our automated VSEC Test platform to deliver deep, compliant vulnerability analysis to North American OEMs and suppliers. If you are a security researcher who loves pulling apart hardware, dissecting binary structures, and finding the zero-days others miss, you belong at Block Harbor. * Customer Engagement & Scoping: Partner with customers to understand their security objectives, vehicle architectures, and compliance requirements - translating technical needs into well-defined test scopes and accurate, compelling proposals. * Proposal Development: Author clear and thorough penetration test proposals that articulate methodology, scope, timelines, and expected deliverables. Communicate the value of Block Harbor's approach in terms that resonate with both technical and non-technical stakeholders. * Offensive Security Testing: Execute deep-dive, activity-based penetration tests across physical and wireless vehicle interfaces - including CAN, LIN, Automotive Ethernet, UDS, DoIP, Bluetooth, Wi-Fi, and Web APIs. * Firmware & Software Reversing: Reverse engineer and perform binary composition analysis on embedded vehicle controllers to surface configuration flaws, logic bugs, and memory corruption vulnerabilities. * Automated & Manual Fuzzing: Apply advanced fuzzing techniques to expose zero-day vulnerabilities and stability weaknesses in vehicle communication stacks and diagnostic services. * VSEC Platform Utilization: Leverage Block Harbor's VSEC platform to accelerate test execution and centralize vulnerability management - and actively contribute feedback that shapes its development. * Reporting & Remediation Support: Produce comprehensive, client-ready penetration test reports mapped to relevant regulatory frameworks (ISO/SAE 21434, UN R155, NIST). Present findings directly to customer engineering teams, clearly communicating technical risk and prioritized mitigation strategies. * Community & Research: Represent Block Harbor in the broader automotive security ecosystem - including ASRG, DEF CON Car Hacking Village, and SAE international committees - through ongoing threat research and thought leadership. ## Related Videos - [Web APIs you might not know about](https://www.wearedevelopers.com/videos/281-web-apis-you-might-not-know-about) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Project Fugu: Extending the web](https://www.wearedevelopers.com/videos/832-project-fugu-extending-the-web) - [Cybersecurity for Software Defined Vehicles](https://www.wearedevelopers.com/videos/725-cybersecurity-for-software-defined-vehicles) ## Related Articles - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)