Architect Cybersecurity
Job Summary
Introduction: A Career at HARMAN Automotive
Were a global multi-disciplinary team thats putting the innovative power of technology to work and transforming tomorrow. At HARMAN Automotive we give you the keys to fast-track your career.
- Engineer audio systems and integrated technology platforms that augment the driving experience
- Combine ingenuity in-depth research and a spirit of collaboration with design and engineering excellence
- Advance in-vehicle infotainment safety efficiency and enjoyment
About the Role
As an Automotive Cybersecurity Architect you will define and guide cybersecurity concepts and architectures for connected vehicle systems including Android Automotive and Linux-based infotainment platforms telematics connectivity and supporting backend services. You will translate cybersecurity risks regulatory obligations and product requirements into implementable controls engineering work products and compliance evidence. You will collaborate with systems software hardware validation quality and program teams to ensure cybersecurity is addressed throughout the product lifecycle. This is an individual contributor role and the reporting relationship is to be confirmed.
What You Will Do
- Develop and maintain cybersecurity concepts cybersecurity requirements security architectures interface specifications and verification criteria for automotive products.
- Plan facilitate document and maintain Threat Analysis and Risk Assessment activities including asset identification attack-path analysis impact assessment risk determination cybersecurity goals and risk-treatment decisions.
- Create review and maintain applicable ISO/SAE 21434 work products ensuring bidirectional traceability between identified risks cybersecurity goals requirements architecture decisions implemented controls verification evidence and residual-risk decisions.
- Perform cybersecurity architecture reviews and provide actionable guidance to system software hardware cloud and validation teams.
- Define security controls for Android Automotive and Linux-based IVI systems including secure boot chain of trust SELinux policy application sandboxing Trusted Execution Environment integration Trusted Applications key protection and secure storage.
- Define and review cryptographic designs involving PKI certificate and key lifecycle management authentication authorization encryption TLS/SSL OpenSSL JSSE and secure communications.
- Define security controls for telematics and connected systems including connectivity diagnostics vehicle-to-backend communication OTA software updates software authenticity integrity validation rollback protection and secure update authorization.
- Support implementation of Cybersecurity Management System processes and product evidence needed for UNECE R155 compliance cybersecurity audits assessments and Vehicle Type Approval activities.
- Support Software Update Management System processes and product evidence needed for UNECE R156 compliance including software update governance update traceability integrity and authenticity controls compatibility assessment and update verification evidence.
- Contribute to cybersecurity case development by consolidating requirements analyses architecture decisions test results vulnerability information open risks assumptions deviations and residual-risk acceptance evidence.
- Support cybersecurity planning cybersecurity interface agreements supplier cybersecurity reviews distributed-development coordination and review of supplier-provided cybersecurity evidence.
- Define cybersecurity verification and validation strategies including security requirements testing robustness testing vulnerability scanning fuzz testing penetration-testing support and remediation verification.
- Assess vulnerabilities and coordinate their treatment through triage applicability analysis risk evaluation remediation planning security patch integration verification disclosure coordination and post-production monitoring.
- Support incident-response readiness and product cybersecurity monitoring by defining logging detection escalation investigation containment and evidence-retention expectations.
- Review backend and API security controls including identity and access management authentication authorization encryption secrets management secure API design logging monitoring and cloud security fundamentals.
- Support alignment between automotive product cybersecurity activities and relevant ISO/IEC 27001 controls where product development operational or backend environments intersect with the organizational information security management system.
- Prepare and present cybersecurity status risks assumptions compliance gaps remediation plans and technical decisions to engineering and program stakeholders.
- Support internal and external cybersecurity assessments by providing objective evidence responding to findings and tracking corrective actions to closure.
- Promote security-by-design practices reusable security patterns secure engineering guidance and lessons learned across automotive development teams.
What You Need to Be Successful
- Bachelors degree in computer science cybersecurity electrical engineering software engineering telecommunications or a related technical discipline.
- Professional experience in automotive cybersecurity embedded security product security or security architecture. The required number of years is to be confirmed.
- Hands-on experience applying ISO/SAE 21434 within an automotive product lifecycle and producing or reviewing cybersecurity engineering work products.
- Practical experience conducting and documenting TARA activities and deriving cybersecurity goals claims requirements and risk-treatment measures.
- Working knowledge of UNECE R155 CSMS expectations audit evidence and cybersecurity contributions to Vehicle Type Approval.
- Working knowledge of UNECE R156 SUMS expectations and security considerations for automotive software update and OTA processes.
- Experience developing or reviewing cybersecurity concepts system security architectures cybersecurity requirements design decisions interface controls and verification strategies.
- Strong understanding of embedded and connected-system security including secure boot roots of trust hardware-backed key storage Trusted Execution Environments cryptography PKI authentication authorization secure communications and secure diagnostics.
- Knowledge of Android Automotive or Android platform security including SELinux application permissions sandboxing keystore concepts Trusted Applications JSSE and platform update security.
- Knowledge of Linux security concepts including access control privilege separation hardening service isolation secure configuration logging and OpenSSL-based communications.
- Understanding of telematics connected-vehicle interfaces OTA systems vehicle-to-cloud communication and backend or API security fundamentals.
- Experience with cybersecurity verification methods such as security testing vulnerability analysis fuzz testing penetration-testing coordination and remediation verification.
- Ability to establish and maintain requirements-to-test and risk-to-control traceability using structured engineering lifecycle processes.
- Ability to assess technical findings communicate risk accurately and recommend proportionate mitigations without losing sight of product safety usability performance and delivery constraints.
- Strong written and verbal communication skills with the ability to explain cybersecurity topics to engineering management quality compliance and non-security stakeholders.
- Working proficiency in English.
Bonus Points if You Have
- Masters degree in cybersecurity computer science electrical engineering software engineering or a related discipline.
- Recognized cybersecurity certifications such as CISSP CSSLP CCSP OSCP or an automotive cybersecurity certification.
- Experience supporting Certification Authorities technical services OEM compliance teams or approval authorities during CSMS SUMS UNECE R155 UNECE R156 or Vehicle Type Approval activities.
- Experience with ISO 24089 software update engineering ISO 26262 functional safety Automotive SPICE TISAX or ISO/IEC 27001.
- Experience creating cybersecurity cases assurance arguments compliance matrices audit packages or release-readiness evidence.
- Experience with hardware security modules secure elements TPMs TrustZone hypervisors domain isolation secure provisioning code signing or manufacturing security.
- Experience securing automotive communication technologies and protocols such as CAN LIN Automotive Ethernet SOME/IP DoIP UDS Bluetooth Wi-Fi cellular or GNSS-related services.
- Experience with software composition analysis Software Bill of Materials open-source compliance vulnerability management security scanning or DevSecOps integration.
- Experience with cloud security connected-vehicle backends API gateways IAM OAuth 2.0 OpenID Connect certificate management or security monitoring.
- Experience collaborating with globally distributed engineering teams suppliers third-party laboratories or independent cybersecurity assessors.
What Makes You Eligible
- You are eligible to work in the country of employment. Country and any applicable work-authorization requirements are to be confirmed.
- You are able to work from the designated HARMAN or customer location when required. Location and hybrid-working expectations are to be confirmed.
- You are willing to travel as required. Expected travel frequency is to be confirmed.
- You can collaborate effectively across global time zones when program activities require it.
What We Offer
- A hybrid work environment that balances flexibility with in-person collaboration with most office-based roles onsite three days a week.
- Access to employee discounts on world-class Harman and Samsung products (JBL HARMAN Kardon AKG etc.)
- Extensive training opportunities through our own HARMAN University
- Competitive wellness benefits
- Tuition reimbursement
- Be Brilliant employee recognition and rewards program
- An inclusive and diverse work environment that fosters and encourages professional and personal development
HARMAN is proud to be an Equal Opportunity / Affirmative Action employer. All qualified applicants will receive consideration for employment without regard torace religion color national origin gender (including pregnancy childbirth or related medical conditions) sexual orientation gender identity gender expression age status as a protected veteran status as an individual with a disability or other applicable legally protected characteristics.
Required Experience:
Staff IC
About Company
Symphony Teleca Corporation is the world’s first services company dedicated exclusively to helping clients manage the global convergence of software, the cloud and connected devices. We deliver solutions for product and services innovation, with contemporary product development, syste ... View more