Role:
The successful candidate will join as Security Architect Harman's software engineering team working on in-vehicle Java SE-based communication middle-ware. The in-vehicle communication middle-ware is responsible for secure routing of messages between automotive back-end and services running inside a connected car.
Work is executed in collaboration with:
- engineers from other centers of excellence at Harman
- engineers from our customer which is a well-known German car manufacturer
- as well as engineers from the car manufacturer and external 3rd party automotive suppliers.
Responsibilities:
- Design of security related components
- Regular security threat & risk analysis
- Consult System-and SW architecture on Security relevant Change Requests (CRs)
- Conduct CR triage from Security point of view
- Security assessment for 3rd party and OSS deliveries
- Security Testing (penetration tests etc.) This might include collaboration with external company doing security tests
- Incident response handling process, e.g. monitor known CVEs (Common Vulnerabilities and Exposures) for a possible impact on the telematics unit
- Promote secure coding practices
- Provide Security related trainings
- Conduct Security Design and Code Reviews & Audits
- Maintain Linux SMACK, Firewall / Packet Filter configurations
- Certificate Handling
Demonstrated experience:
- Bachelor in Computer Science, or equivalent experience
- More than 5 years of experience in a Software Security role
- Very deep knowledge of diverse security domains in Linux and Automotive areas
- Expertise in cryptographic methodologies, key management, intrusion detection, Trusted Execution Environment etc.
- Knowledge and understanding of vehicle communication protocols (CAN, Automotive Ethernet, MQTT, HTTP, TCP/IP)
- Experience with AUTOSAR (Classic)
- Knowledge of Security requirements from UNECE and GB/T 204 is a benefit
- Team player, good communication skills
- Fluent English language skill is mandatory
- German knowledge is a plus