Position Overview
We are seeking an experienced Senior Embedded Security Engineer to join our Cybersecurity Lab in Singapore. This role sits at the heart of Desay SV's security left-shift strategy, responsible for designing and executing end-to-end security test programmes across embedded automotive systems — from ECU firmware and BSP layers through to in-vehicle network protocols and OTA update pipelines.
The ideal candidate brings deep hands-on expertise in embedded systems security, proven experience with automotive communication protocols, and the practical mindset to operate both as a technical practitioner and as a collaborator with AI-assisted toolchains. You will play a central role in validating agent-generated threat assessments, providing real-world evidence that feeds into TARA workflows, SBOM analysis, and compliance submissions for OEM customers.
Key Responsibilities
Security Testing & Vulnerability Research
- Lead and execute security test programmes for ECUs, SoCs, and in-vehicle network components across the full embedded stack: firmware, RTOS (QNX, Linux, AUTOSAR), middleware, and application layers.
- Design and perform penetration testing, fuzzing, and reverse engineering on automotive hardware and firmware.
- Conduct vulnerability analysis on BSP components, device drivers, cryptographic implementations, and secure boot chains; develop and validate remediation patches.
- Build and maintain CyberLab test infrastructure: ECU bench setups, network simulators, hardware-in-the-loop (HiL) rigs, and custom security tooling.
SBOM & Supply Chain Security
- Perform binary SCA on .img firmware, .a/.so libraries, and embedded binaries to identify undeclared open-source components and known vulnerabilities.
- Validate SBOM completeness against CyberLab test findings; document discrepancies between declared and detected components for OEM compliance submissions.
CI/CD Integration & Automation
- Integrate security test suites into CI/CD pipelines, enabling automated security regression at the merge request stage for embedded software changes.
- Develop custom scripts and tooling (Python, C/C++) to automate fuzz test case generation, crash triage, and vulnerability deduplication.
- Provide real-world attack evidence to the AI-assisted TARA agent pipeline — translating lab findings into structured threat data that improves agent accuracy.
Compliance & OEM Support
- Prepare security test evidence packages for OEM audit submissions (ISO/SAE 21434, UNECE WP.29 R155/R156, ISO 26262); ensure traceability from test results to cybersecurity requirements.
- Support cybersecurity case development by supplying empirical attack feasibility data used in TARA risk ratings.
- Participate in threat modelling and security architecture reviews as the lab's embedded security subject matter expert.
Mentoring & Knowledge Sharing
- Provide technical guidance to junior engineers in embedded security testing practices, tool usage, and vulnerability documentation.
- Contribute to internal security research publications, tooling documentation, and knowledge-base articles.
Qualifications
Required
- Bachelor's degree or above in Computer Science, Electrical/Electronic Engineering, Cybersecurity, or a related field.
- Proven experience in embedded or automotive cybersecurity testing.
- Proven hands-on experience in penetration testing, fuzzing, and vulnerability assessment and validation on embedded targets (MCUs, SoCs, automotive ECUs).
- Strong knowledge of embedded operating systems: Linux (BSP/kernel level), QNX, and AUTOSAR Classic/Adaptive.
- Solid understanding of automotive communication protocols: CAN, CAN-FD, Ethernet/IP, DoIP.
- Proficiency in Python, C/C++, and shell scripting for test automation and tool development.
- Familiarity with cryptographic principles and their automotive implementations: secure boot, SecOC, HSM, TLS.
- Working knowledge of ISO/SAE 21434 cybersecurity engineering requirements
- Excellent written and spoken English; ability to produce clear technical documentation for international OEM audiences.
Preferred
- Experience with binary analysis tools (Ghidra, IDA Pro, Binwalk) applied to automotive firmware.
- Exposure to SBOM tools (BlackDuck, JFrog Xray, and etc) and binary SCA workflows.
- Knowledge of OTA update security mechanisms and cloud-connected vehicle architectures.
- Prior experience working directly on OEM-directed security projects.
- Security certifications: OSCP, GXPN, CEH, CISSP, or automotive-specific equivalents
- Experience using or validating AI-assisted threat modelling tools.
Why Join Us
- Work on live automotive programmes spanning ADAS, IVI, and autonomous driving — security decisions you make directly affect products on the road.
- Access to a purpose-built CyberLab with real ECU hardware, vehicle networks, and dedicated test infrastructure.
- Collaborate with a global team across Singapore, Shenzhen, Germany, and Japan on next-generation AI-assisted cybersecurity toolchains.
- Direct interface with OEM and Tier-1 supplier security teams — building expertise no pure-lab environment can offer.