Embedded Product Cybersecurity Expert / ISO 21434, IEC 62443

Sopra Steria

$90K — $120K *
Manufacturing & Automotive
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's or Master's in Software, Electrical, Computer, or Automotive Engineering.
  • 3-10 years in automotive or embedded systems cybersecurity, specifically with TARA.
  • Strong knowledge of embedded systems architecture and design constraints.
  • Experience with low-level debugging and boot architectures.
  • Familiarity with various communication protocols and embedded security mechanisms.
  • Ability to define and trace Cybersecurity Goals and Requirements.
  • Excellent analytical and documentation skills.

Responsibilities

  • Conduct thorough risk assessments using the TARA process.
  • Define critical assets and attack vectors to evaluate risks at ECU and vehicle levels.
  • Derive and ensure traceability of Cybersecurity Goals and Requirements from TARA results.
  • Contribute to the Cybersecurity Concept aligning with industry standards.
  • Collaborate with various engineering teams to implement security measures.
  • Evaluate protocols and suggest effective cybersecurity countermeasures.
  • Participate in validation, audits, and documentation of cybersecurity findings.

Benefits

  • Hybrid Work option available.
  • Comprehensive medical, dental, and vision insurance.
  • Access to telemedicine services.
  • RRSP retirement savings program.
  • Personal and sick leave days.
  • Recreation room with leisure activities.
Full Job Description
Job Description

As a Cybersecurity Engineer - Embedded Products, you will play a central role in ensuring the security and compliance of our customers' vehicle systems and ECU architectures. Your responsibilities include:
  • Perform a comprehensive risk assessment of the current system architecture and identify item-level functions by applying the TARA process via recognized methods (e.g., ISO/SAE 21434 TARA, STRIDE, or similar).
  • Build and review item definitions, identify critical assets, potential attack vectors, threat scenarios, and evaluate associated risks at both ECU and vehicle levels.
  • Derive Cybersecurity Goals and Cybersecurity Requirements (hardware, firmware, and system-level design) from the TARA results and ensure traceability throughout the product development lifecycle.
  • Contribute to the Cybersecurity Concept (CSC) and ensure alignment with ISO/SAE 21434 and regulatory requirements.
  • Collaborate with system, software, and hardware engineering teams to integrate recommended security measures (cryptography, secure boot, secure communication, key management, hardware root of trust, debug protections, memory protection, key storage and secure update mechanisms).
  • Evaluate protocols usage and propose cybersecurity countermeasures such as authentication, encryption, replay protection, secure pairing, and robust key management.
  • Support validation activities for cybersecurity controls and participate in audits, reviews, and documentation of findings.
  • Support compliance and customer requirements aligned with standards and frameworks (as applicable): CRA, ISO/SAE 21434, RED-DA, IEC 62443, NIST, etc.


Qualifications
  • Bachelor's or Master's degree in Software, Electrical, Computer, or Automotive Engineering or a related field.
  • 3-10 years of experience in automotive cybersecurity or embedded systems cybersecurity, with hands-on experience on TARA based on ISO/SAE 21434 processes.
  • Solid foundation in embedded systems architecture, including deep understanding of MCU/SoC design constraints, real-time and Linux-based environments.
  • Proficient with boot architectures and low-level debugging using interfaces such as JTAG, XCP and SWD.
  • Solid understanding of communication protocols (CAN, CAN-FD, Automotive Ethernet, SOME/IP, UDS, UART, SPI, BT, Wi-Fi, USB, NFC, cellular, RF, etc.), and embedded security mechanisms (cryptography, secure boot, secure communication, key management, hardware root of trust, debug protections, memory protection, key storage and secure update mechanisms).
  • Proven ability to define Cybersecurity Goals and claims, derive Requirements, and ensure traceability through the development lifecycle.
  • Excellent analytical, problem-solving, and documentation skills.
  • Ability to work collaboratively with multi-disciplinary, multi-site engineering teams.

Preferred / Asset Qualifications:
  • Experience with embedded systems, or safety-critical ECUs.
  • Hands-on experience in cybersecurity validation and testing (fuzzing, robustness testing, penetration testing).
  • Knowledge of Cybersecurity Case preparation and internal/external audit processes.
  • Familiarity with regulatory requirements such as UNECE R155/R156, CRA and standards such as ISO 21434, IEC 62443.
  • Exposure to hardware security modules (TPM, Secure Element, HSM), TrustZone, MPU/MMU
  • Understanding of Software Bill of Material (SBOM), product security incident response (PSIRT) processes and vulnerability monitoring and management (CVE/CWE/CVSS).


Additional Information

Please note that only selected candidates and Permanent Residents/Canadian Citizens will be contacted.

Job Types: Full-time, Permanent

Benefits:
  • Hybrid Work
  • Industry leading medical, dental, and vision Insurance
  • Access to a telemedicine service
  • RRSP program
  • Personal and sick days
  • Recreation room with pool table and foosball table

Similar Jobs

More Jobs at Sopra Steria

More Manufacturing & Automotive Jobs

Find similar Embedded Product Cybersecurity Expert / ISO 21434, IEC 62443 jobs: