Search by job, company or skills

Senior Embedded Security Engineer

5-7 Years
  • Posted 4 days ago
  • Be among the first 10 applicants

Job Description

Position Overview

We are seeking an experienced Senior Embedded Security Engineer to join our Cybersecurity Lab in Singapore. This role sits at the heart of Desay SV's security left-shift strategy, responsible for designing and executing end-to-end security test programmes across embedded automotive systems — from ECU firmware and BSP layers through to in-vehicle network protocols and OTA update pipelines.

The ideal candidate brings deep hands-on expertise in embedded systems security, proven experience with automotive communication protocols, and the practical mindset to operate both as a technical practitioner and as a collaborator with AI-assisted toolchains. You will play a central role in validating agent-generated threat assessments, providing real-world evidence that feeds into TARA workflows, SBOM analysis, and compliance submissions for OEM customers.

Key Responsibilities

Security Testing & Vulnerability Research

  • Lead and execute security test programmes for ECUs, SoCs, and in-vehicle network components across the full embedded stack: firmware, RTOS (QNX, Linux, AUTOSAR), middleware, and application layers.
  • Design and perform penetration testing, fuzzing, and reverse engineering on automotive hardware and firmware.
  • Conduct vulnerability analysis on BSP components, device drivers, cryptographic implementations, and secure boot chains; develop and validate remediation patches.
  • Build and maintain CyberLab test infrastructure: ECU bench setups, network simulators, hardware-in-the-loop (HiL) rigs, and custom security tooling.

SBOM & Supply Chain Security

  • Perform binary SCA on .img firmware, .a/.so libraries, and embedded binaries to identify undeclared open-source components and known vulnerabilities.
  • Validate SBOM completeness against CyberLab test findings; document discrepancies between declared and detected components for OEM compliance submissions.

CI/CD Integration & Automation

  • Integrate security test suites into CI/CD pipelines, enabling automated security regression at the merge request stage for embedded software changes.
  • Develop custom scripts and tooling (Python, C/C++) to automate fuzz test case generation, crash triage, and vulnerability deduplication.
  • Provide real-world attack evidence to the AI-assisted TARA agent pipeline — translating lab findings into structured threat data that improves agent accuracy.

Compliance & OEM Support

  • Prepare security test evidence packages for OEM audit submissions (ISO/SAE 21434, UNECE WP.29 R155/R156, ISO 26262); ensure traceability from test results to cybersecurity requirements.
  • Support cybersecurity case development by supplying empirical attack feasibility data used in TARA risk ratings.
  • Participate in threat modelling and security architecture reviews as the lab's embedded security subject matter expert.

Mentoring & Knowledge Sharing

  • Provide technical guidance to junior engineers in embedded security testing practices, tool usage, and vulnerability documentation.
  • Contribute to internal security research publications, tooling documentation, and knowledge-base articles.

Qualifications

Required

  • Bachelor's degree or above in Computer Science, Electrical/Electronic Engineering, Cybersecurity, or a related field.
  • Proven experience in embedded or automotive cybersecurity testing.
  • Proven hands-on experience in penetration testing, fuzzing, and vulnerability assessment and validation on embedded targets (MCUs, SoCs, automotive ECUs).
  • Strong knowledge of embedded operating systems: Linux (BSP/kernel level), QNX, and AUTOSAR Classic/Adaptive.
  • Solid understanding of automotive communication protocols: CAN, CAN-FD, Ethernet/IP, DoIP.
  • Proficiency in Python, C/C++, and shell scripting for test automation and tool development.
  • Familiarity with cryptographic principles and their automotive implementations: secure boot, SecOC, HSM, TLS.
  • Working knowledge of ISO/SAE 21434 cybersecurity engineering requirements
  • Excellent written and spoken English; ability to produce clear technical documentation for international OEM audiences.

Preferred

  • Experience with binary analysis tools (Ghidra, IDA Pro, Binwalk) applied to automotive firmware.
  • Exposure to SBOM tools (BlackDuck, JFrog Xray, and etc) and binary SCA workflows.
  • Knowledge of OTA update security mechanisms and cloud-connected vehicle architectures.
  • Prior experience working directly on OEM-directed security projects.
  • Security certifications: OSCP, GXPN, CEH, CISSP, or automotive-specific equivalents
  • Experience using or validating AI-assisted threat modelling tools.

Why Join Us

  • Work on live automotive programmes spanning ADAS, IVI, and autonomous driving — security decisions you make directly affect products on the road.
  • Access to a purpose-built CyberLab with real ECU hardware, vehicle networks, and dedicated test infrastructure.
  • Collaborate with a global team across Singapore, Shenzhen, Germany, and Japan on next-generation AI-assisted cybersecurity toolchains.
  • Direct interface with OEM and Tier-1 supplier security teams — building expertise no pure-lab environment can offer.

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 151349415