Forensic Analysis & Offensive Security for Product Cybersecurity This role supports shift left forensic and offensive security evaluations for embedded and connected products across on highway and off highway platforms. The role is focused on hands on technical execution, including early vulnerability discovery, exploit feasibility analysis, architecture reviews, reverse engineering, and pre certification penetration testing, to provide actionable technical findings ahead of external certification testing. This role does not own security capability strategy, tooling ownership, or organizational maturity and does not replace external penetration testing or certification mandated evaluations.
KEY RESPONSIBILITIES
- Vulnerability Scanning & Analysis
- Perform firmware, binary, and configuration vulnerability scanning, side channel attacks on embedded products.
- Identify known weaknesses such as insecure configurations, outdated components, and cryptographic issues.
- Assess vulnerabilities based on practical exploitability and product context,
in addition to standard severity scoring.
- Document findings clearly with technical evidence and reproducible observations. B. Product & ECU Penetration Testing
- Execute pre certification penetration testing activities early in the product lifecycle.
- Perform attacker perspective testing to identify realistic product weaknesses prior to engagement with external labs.
- Conduct hands on testing using defined test setups for: o ECU level penetration testing o System level penetration testing o CAN / UDS / J1939 / Ethernet / MODBUS and related protocol fuzzing
- Provide test results, observations, and technical inputs that complement external penetration testing efforts.
- Architecture & Threat Assessments
- Perform shift left architecture reviews focused on identifying implementation weaknesses related to, Trust boundaries o Cryptographic usage and key handling o Secure boot and firmware integrity o OT