- Location
- Chennai, Tamil Nadu, India
- Job type
- Full-time
Required skills
- Open Source
- cryptography
- embedded systems
- ethernet
- incident response
- IoT
- ISO 26262
- Linux
- product design
- Swift
About the role
Valeo
Website:
valeo.com
Job details:
Responsbilities
- Lifecycle Management: Execute and document each stage of the Product Security Incident Response Lifecycle, from initial detection of a vulnerability to resolution and formal communication.
- Triage & Risk Assessment: Conduct technical triage for automotive security incidents and customer-reported issues to determine scope, urgency, and impact on vehicle safety (ISO 26262) and security.
- Real-time Decision Making: Make swift, informed decisions to mitigate risks, protecting Valeo’s reputation and safeguarding vehicles from active exploits.
- Stakeholder Communication: Provide clear technical briefings and executive updates to internal engineering teams, legal counsel, OEMs, and regulatory bodies during and after an incident.
- Deep-dive Analysis: Perform root-cause analysis on affected products, generate forensic reports, and analyze automotive threat landscape trends to improve future product design.
- Plan Development: Develop and maintain Incident Response Plans tailored to specific electronic control units (ECUs) and vehicle platforms.
- Customer Guidance: Validate security notifications and provide authoritative guidance to OEMs regarding patch implementation and risk mitigation.
Required Qualifications
- Minimum 5–6 years of experience in Automotive Product Development or Testing with exposure and knowledge on product cybersecurity.
- Proven experience in Product Cybersecurity, specifically in reviewing Threat Analysis and Risk Assessment (TARA).
- Preferred - hands-on experience in incident response, vulnerability analysis, or product security research.
- Direct experience with security/ vulnerability investigations in embedded systems, IoT, or ECUs.
- Hands-on investigative experience involving automotive communication protocols (e.g., CAN, LIN, Automotive Ethernet).
- Robust understanding of embedded OS (e.g., QNX, Embedded Linux), Hardware Security Modules (HSMs), and basic cryptography applied to vehicle networks.
- Ability to translate complex technical vulnerabilities into actionable executive reports.
Preferred Qualifications
- Sound knowledge and familiarity with ISO/SAE 21434 and UN R155/R156 regulations.
- Experience in SAST/DAST methodologies and FOSS (Open Source) security risk analysis.
- Experience handling incidents related to V2X, Telematics, Infotainment (IVI), or Powertrain security.
- Certifications: eCIR or CEH or OSCP or other Incident Handler certifications are a plus.
Click on Apply to know more.
This page is fully interactive when JavaScript is enabled. Please enable JavaScript to apply or browse related roles.