- Having 6-8 years of hands-on experience, working as a Threat Analysis and Risk Assessments engineer in automotive Cyber Security in the Application and Infrastructure/Cloud space
Must have :
- Experience with automotive cybersecurity standards - ISO21434, SAE J3061, WP.29, R155/R156
- Performed Threat Analysis and Risk Assessments (TARAs), and attack tree analysis
- Overall hands-on experience with threat analysis in embedded software systems within the automotive industry
- Identifying and evaluating potential risks related to automotive cybersecurity, analyzing their potential impact, and proposing mitigation strategies.
- Ensure teams and suppliers are correctly following Cyber Security processes, ensuring compliance with regulations and standards such as UNECE.R155 or ISO21434
- Develop and maintain documentation related to security procedures and risk assessment
- Review Software applications for potential security vulnerabilities by conducting application security reviews i.e. Secure Design review, Threat Modelling
- Perform vulnerability analysis, vulnerability management including risk treatment decision regarding the specific topic, communicate with various stakeholders including management at all levels and vendors
- Positive understanding of high integrity systems, and secure software and / or hardware design principles, in an embedded environment.