CybersecurityJobs.io
← Back to all jobs

Job Description

Automotive penetration testing role on a Red Team focused on offensive security research and client-ready reporting.

Responsibilities

  • Partner with customers to clarify security objectives, vehicle architectures, and compliance requirements, then translate needs into defined test scopes and proposals
  • Author penetration test proposals covering methodology, scope, timelines, and expected deliverables
  • Communicate the value of Block Harbor’s approach to both technical and non-technical stakeholders
  • Run activity-based penetration tests across physical and wireless interfaces including CAN, LIN, Automotive Ethernet, UDS, DoIP, Bluetooth, Wi-Fi, and Web APIs
  • Reverse engineer and perform binary composition analysis on embedded vehicle controllers to identify configuration flaws, logic bugs, and memory corruption vulnerabilities
  • Use advanced fuzzing to uncover zero-day vulnerabilities and stability weaknesses in vehicle communication stacks and diagnostic services
  • Leverage the VSEC Test platform to accelerate execution and centralize vulnerability management; provide feedback that informs platform development
  • Deliver comprehensive, client-ready reports mapped to relevant standards and regulatory frameworks including ISO/SAE 21434, UN R155, and NIST
  • Present findings to customer engineering teams with clear risk communication and prioritized mitigation guidance
  • Represent Block Harbor in the automotive security ecosystem (ASRG, DEF CON Car Hacking Village, SAE international committees) through ongoing threat research and thought leadership

Requirements

  • 3+ years professional experience in offensive security, penetration testing, or hardware security assessment in automotive, embedded systems, or IoT
  • Hands-on expertise in vehicle electrical architectures (E/E) and protocols, especially CAN/CAN-FD, UDS, and Automotive Ethernet
  • Proficiency with hardware and network exploitation tools including Wireshark, Vector CANalyzer/CANoe, Ghidra, IDA Pro, and JTAG/SWD debuggers, plus software fuzzers
  • Hands-on experience with AI and LLMs in a security or research context
  • Working knowledge of automotive cybersecurity compliance frameworks, specifically ISO/SAE 21434 and UN R155
  • Security-focused mindset and collaborative approach aligned with “full throttle collaboration” culture
  • Willingness to travel internationally

Technologies

  • CAN, CAN-FD, LIN, Automotive Ethernet
  • UDS, DoIP, Bluetooth, Wi-Fi, Web APIs
  • Wireshark
  • Vector CANalyzer, Vector CANoe
  • Ghidra, IDA Pro
  • JTAG, SWD
  • VSEC Test platform
  • Software fuzzers, AI, LLMs
  • ISO/SAE 21434, UN R155, NIST

Benefits

  • 401(k)
  • 401(k) matching
  • Dental insurance
  • Employee assistance program
  • Flexible schedule
  • Flexible spending account
  • Health insurance
  • Health savings account
  • Paid time off
  • Parental leave
  • Referral program
  • Retirement plan
  • Vision insurance

Preferred / Nice-to-Have

  • Experience with cloud platforms and API security
  • Comfort engaging directly with customers and presenting technical findings

Location and Travel

  • Detroit, MI (onsite)
  • In person
  • Willingness to travel internationally

Compensation

  • $70,000 - $120,000 per year

Application Questions

  • Do you have 3+ years of professional experience in offensive security, penetration testing, or hardware security assessment within the automotive, embedded systems, or IoT domains?
  • Do you have hands-on expertise with vehicle electrical architectures (E/E) and protocols, particularly CAN/CAN-FD, UDS, and Automotive Ethernet?
  • Do you have experience with hardware and network exploitation tools including Wireshark, Vector CANalyzer/CANoe, Ghidra, IDA Pro, JTAG/SWD debuggers, and software fuzzers?
  • On a scale of 1-5 with 5 being a subject matter expert, how familiar are you with automotive cybersecurity compliance frameworks, specifically ISO/SAE 21434 and UN R155?

Similar Jobs