Source description
About the role
Responsbilities Lifecycle Management: Execute and document each stage of the Product Security Incident Response Lifecycle, from initial detection of a vulnerability to resolution and formal communication. Triage & Risk Assessment: Conduct technical triage for automotive security incidents and customer-reported issues to determine scope, urgency, and impact on vehicle safety (ISO 26262) and security. Real-time Decision Making: Make swift, informed decisions to mitigate risks, protecting Valeo's reputation and safeguarding vehicles from active exploits. Stakeholder Communication: Provide clear technical briefings and executive updates to internal engineering teams, legal counsel, OEMs, and regulatory bodies during and after an incident. Deep-dive Analysis: Perform root-cause analysis on affected products, generate forensic reports, and analyze automotive threat landscape trends to improve future product design. Plan Development: Develop and maintain Incident Response Plans tailored to specific electronic control units (ECUs) and vehicle platforms. Customer Guidance: Validate security notifications and provide authoritative guidance to OEMs regarding patch implementation and risk mitigation. Required Qualifications Minimum 5–6 years of experience in Automotive Product Development or Testing with exposure and knowledge on product cybersecurity. Proven experience in Product Cybersecurity, specifically in reviewing Threat Analysis and Risk Assessment (TARA). Preferred - hands-on experience in incident response, vulnerability analysis, or product security research. Direct experience with security/ vulnerability investigations in embedded systems, IoT, or ECUs. Hands-on investigative experience involving automotive communication protocols (e.g., CAN, LIN, Automotive Ethernet). Robust understanding of embedded OS (e.g., QNX, Embedded Linux), Hardware Security Modules (HSMs), and basic cryptography applied to vehicle networks. Ability to translate complex technical vulnerabilities into actionable executive reports. Preferred Qualifications Sound knowledge and familiarity with ISO/SAE 21434 and UN R155/R156 regulations. Experience in SAST/DAST methodologies and FOSS (Open Source) security risk analysis. Experience handling incidents related to V2X, Telematics, Infotainment (IVI), or Powertrain security. Certifications: eCIR or CEH or OSCP or other Incident Handler certifications are a plus.
More at Valeo