Position title
Description
Responsibilities
Organization Information
A well known Truck OEM's Embedded Engineering is a rapidly expanding organization that is transforming the way control systems and software are developed for commercial vehicle applications. This includes developing the latest vehicle controls, display technology, and autonomous truck solutions that exceed customer expectations. You will collaborate with an international, cross-functional team focused on driving superior technical solutions that maximize customer uptime and operating efficiency. Successful applicants will demonstrate individual creativity in addressing challenges and opportunities while working within a supportive team to develop industry-leading solutions for the medium- and heavy-duty truck industry
Position Summary
A well known Truck OEM's Embedded Engineering department, has an opening for an Embedded Cybersecurity Engineer focusing on ADAS functions. The Embedded Cybersecurity Engineer will be responsible for performing threat modeling and risk assessments with a major focus on next-generation autonomous vehicle battery electric vehicle systems. The ideal candidate will have the ability to define security controls for system-level design and coordinate with the distributed global team for managing security scope during development activities. The candidate will collaborate with non-security professionals to provide feedback on vehicle architecture ensuring secure design practices are followed as well as breaking down the security implementation with the internal enterprise IT security team to ensure security goals are achieved. The Embedded Cybersecurity Engineer will have industry-level responsibility to participate in global knowledge-sharing events, such as AutoISAC to ensure the industry continues to move forward with emerging technology.
Job Functions / Responsibilities
- Perform risk and threat assessments of current and forward-model vehicle systems
- Participate in the prioritization of response
- Lead updates to software development process standards to incorporate current best practices in secure development techniques and tools
- Consult with EE system architects to achieve continuous improvement in vehicle security with each future update
- Disseminate awareness of risks, opportunities, and best practices to key personnel across company locations
- Collaborate with corporate purchasing and supplier quality to establish standard contract terms and assessments that enhance cyber-security in the supply chain
- Liaise with IT Security align goals and strategy
- Maintain ISAC (industry-wide information sharing and analysis center) communications to support risk and threat knowledge sharing
- Assess technology proposals from external suppliers for their potential to provide effective information security, intrusion detection, and/or protection of vehicle operation
- Coordinate internal and external assessments, penetration tests, and related security evaluation activity
- Develop and deliver training to enhance embedded cyber-security knowledge and skill throughout the company
Qualifications
Skills & Qualifications
- Bachelor’s degree in Engineering, Computer Science, or equivalent
- Proficiency with at least one compiled and one interpreted programming language
- Familiarity with a security management framework such as ISO 21434, ISO 27001, NIST CSF, etc.
- Ability to work in a highly-distributed, lean, collaborative team environment
- Excellent communication and interpersonal skills, good planning/tracking skills
- Competency with standard office software (word processing, spreadsheets, presentation tools, etc)
- Able to design new processes and resourcefully solve complex technical issues
- Determined commitment to reliability, value, quality, and safety in all aspects of work
- Willingness to grow continuously, both personally and professionally, and a strong results orientation
- 3 or more years of experience in two or more roles: real-time software development, vehicle electronics, and controls, embedded systems design, application security, penetration testing, incident response, or compliance
- Ability to travel for scheduled meetings less than 20% to domestic and international locations
- Ability to maintain/obtain within 6 months a security certification: CompTIA CAP or CASP, ISC2 CISM or CISSP, GIAC GSLC, EC-Council CCISO
Additional Valued Attributes
- Knowledge of applied cryptography for provisioning secure hardware
- Knowledge of secure development techniques using static and dynamic analysis
- Practical experience with security controls for POSIX-type operating systems
- Experience managing vulnerability disclosure programs
- Familiarity with AGILE software development processes
- Familiarity with requirements tracking and software test/validation tools
- Proficiency using Requirements Capture, Simulation, Software Configuration, and Defect Tracking/Reporting tools.
- Awareness of heavy-duty commercial truck regulations, especially affecting instrumentation, emissions, safety, On Board Diagnostics, and other areas that impact electrical and electronic design, architecture, and functionality
- Experience with structured product development processes
- Automotive electronic systems engineering skills including multiplex communication systems (especially CAN/J1939), architecture, and control system design and analysis.
Job Benefits
- 401k with up to a 5% company match
- Fully funded pension plan that provides monthly benefits after retirement
- Comprehensive paid time off – minimum of 10 paid vacation days (additional days are provided with additional seniority/years of service), 12 paid holidays, and sick time
- Tuition reimbursement for continued education
- Medical, dental, and vision plans for you and your family
- Flexible spending accounts (FSA) and health savings account (HSA)
- Paid short-and long-term disability programs
- Life and accidental death and dismemberment insurance
- EAP services including wellness plans, estate planning, financial counseling and more