Automotive Penetration Tester
Api Penetration Testing
Automotive Cybersecurity Testing
Automotive Embedded Security
Automotive Protocol Security
Cybersecurity Tools
Information Security
InfoSec
Offensive Security
Offensive Security Testing
Penetration Testing
Pentesting Tools
Security
Security Compliance
Security Standards
Security Testing
Security Testing Tools
Software Security
Vehicle Penetration Testing
Job Description
Automotive penetration testing role on a Red Team focused on offensive security research and client-ready reporting.
Responsibilities
- Partner with customers to clarify security objectives, vehicle architectures, and compliance requirements, then translate needs into defined test scopes and proposals
- Author penetration test proposals covering methodology, scope, timelines, and expected deliverables
- Communicate the value of Block Harbor’s approach to both technical and non-technical stakeholders
- Run activity-based penetration tests across physical and wireless interfaces including CAN, LIN, Automotive Ethernet, UDS, DoIP, Bluetooth, Wi-Fi, and Web APIs
- Reverse engineer and perform binary composition analysis on embedded vehicle controllers to identify configuration flaws, logic bugs, and memory corruption vulnerabilities
- Use advanced fuzzing to uncover zero-day vulnerabilities and stability weaknesses in vehicle communication stacks and diagnostic services
- Leverage the VSEC Test platform to accelerate execution and centralize vulnerability management; provide feedback that informs platform development
- Deliver comprehensive, client-ready reports mapped to relevant standards and regulatory frameworks including ISO/SAE 21434, UN R155, and NIST
- Present findings to customer engineering teams with clear risk communication and prioritized mitigation guidance
- Represent Block Harbor in the automotive security ecosystem (ASRG, DEF CON Car Hacking Village, SAE international committees) through ongoing threat research and thought leadership
Requirements
- 3+ years professional experience in offensive security, penetration testing, or hardware security assessment in automotive, embedded systems, or IoT
- Hands-on expertise in vehicle electrical architectures (E/E) and protocols, especially CAN/CAN-FD, UDS, and Automotive Ethernet
- Proficiency with hardware and network exploitation tools including Wireshark, Vector CANalyzer/CANoe, Ghidra, IDA Pro, and JTAG/SWD debuggers, plus software fuzzers
- Hands-on experience with AI and LLMs in a security or research context
- Working knowledge of automotive cybersecurity compliance frameworks, specifically ISO/SAE 21434 and UN R155
- Security-focused mindset and collaborative approach aligned with “full throttle collaboration” culture
- Willingness to travel internationally
Technologies
- CAN, CAN-FD, LIN, Automotive Ethernet
- UDS, DoIP, Bluetooth, Wi-Fi, Web APIs
- Wireshark
- Vector CANalyzer, Vector CANoe
- Ghidra, IDA Pro
- JTAG, SWD
- VSEC Test platform
- Software fuzzers, AI, LLMs
- ISO/SAE 21434, UN R155, NIST
Benefits
- 401(k)
- 401(k) matching
- Dental insurance
- Employee assistance program
- Flexible schedule
- Flexible spending account
- Health insurance
- Health savings account
- Paid time off
- Parental leave
- Referral program
- Retirement plan
- Vision insurance
Preferred / Nice-to-Have
- Experience with cloud platforms and API security
- Comfort engaging directly with customers and presenting technical findings
Location and Travel
- Detroit, MI (onsite)
- In person
- Willingness to travel internationally
Compensation
- $70,000 - $120,000 per year
Application Questions
- Do you have 3+ years of professional experience in offensive security, penetration testing, or hardware security assessment within the automotive, embedded systems, or IoT domains?
- Do you have hands-on expertise with vehicle electrical architectures (E/E) and protocols, particularly CAN/CAN-FD, UDS, and Automotive Ethernet?
- Do you have experience with hardware and network exploitation tools including Wireshark, Vector CANalyzer/CANoe, Ghidra, IDA Pro, JTAG/SWD debuggers, and software fuzzers?
- On a scale of 1-5 with 5 being a subject matter expert, how familiar are you with automotive cybersecurity compliance frameworks, specifically ISO/SAE 21434 and UN R155?