Security Engineer (Purple Team)
Applied Intuitionabout 2 years ago
Sunnyvale, CA, USAMid Level
H1B Sponsor
Base Salary
$140k - $260k/yr
Responsibilities
- Review, assess, and audit vehicle software platform code using automated tests and security tooling to identify vulnerabilities.
- Lead security verification and validation initiatives and serve as the point of contact for security V&V activities.
- Set up automotive test benches for penetration testing and risk assessments.
- Implement vulnerability fixes where appropriate and coordinate long-term remediation with core software teams.
- Help design secure vehicle software, connected vehicle, and connected autonomous vehicle architectures.
- Conduct hands-on security testing, perform risk assessments, and prioritize security bugs, threats, and mitigation strategies.
- Develop secure automotive products in alignment with ISO 21434 processes and UN R155 technical specifications.
- Collaborate with software, security, systems, and safety engineering teams to advance product security.
- Work with customers and internal business units to deliver secure automotive products.
Requirements
- At least 2 years of industry experience in software engineering or product security engineering.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Engineering, Software Engineering, or equivalent experience.
- Strong understanding of embedded systems and software interaction with hardware.
- Strong penetration-testing or hands-on security-assessment experience for embedded systems.
- Technical knowledge of Linux or QNX internals.
- Security expertise in one or more of C, C++, x86, ARM, cryptography, or exploit development.
- Experience with firewall configurations and SSH authentication.
- Proficiency in C/C++ or Python programming.
- Understanding of secure boot, key management, and cryptographic accelerators.
- Experience with vulnerability databases, automated fuzzing frameworks such as AFL or libFuzzer, or specialized automotive tools.
- Proficiency in manual and automated code auditing and vulnerability research.
- Experience conducting formal risk assessments and prioritizing mitigations by risk level.
- Ability to act as a technical lead and coordinate security projects with internal teams and external customers.
- Preferred: automotive security experience and familiarity with CAN, Automotive Ethernet, and UDS.
- Preferred: knowledge of automotive SoCs/MCUs, ISO 21434, UN R155, Android Security, embedded operating systems, HSMs, and TEEs.
Benefits
- Primarily in-office work five days per week, with occasional remote-work flexibility.
- Comprehensive health, dental, vision, life, and disability insurance.
- 401(k) retirement benefits with employer match.
- Learning and wellness stipends.
- Paid time off.