Penetration Testing Engineer

Gtech Llc — United States · Posted ~3 hours ago

Mid Contract Hybrid

Skills

penetration testing automotive cybersecurity ECU security testing CAN protocols embedded systems security security testing CAN ECU Bluetooth USB embedded systems

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A cybersecurity engineering role focused on testing and improving the security of automotive and embedded technologies. The position requires hands-on penetration testing experience beyond basic fuzzing, with knowledge of communication protocols and connected device security.

Highlights

Opportunity to work on automotive cybersecurity projects involving embedded systems, connected devices, and advanced security testing in a stable long-term engagement.

Description

Good Day, My name is Shivam and I am a Recruitment Specialist. I have a exclusive Job opportunity, let me know if you are interested. Job Title Pen Testing Engineer Job Location Plymouth, MI Work Mode Hybrid Job Type C2C Job Duration 6-12+ Months Interview Process Video Call Instructions Payment term 60/45 2+ year contract until headcount opens up. ETAS is on a hiring freeze. Work is stable so they would like to convert down the road. Job Description:- Key Requirements Automotive industry background requiredExperience with Electronic Control Units (ECUs)Strong understanding of CAN (Controller Area Network) protocols Technical Skills Penetration testing experienceMust have experience beyond fuzz testingLooking for candidates with security testing experience in one or more of the following areas:USBWireless communicationsBluetoothSimilar embedded/connected device technologies Interview Feedback Recently interviewed two candidates whose experience was limited to fuzz testingCandidates lacked the broader hands-on security testing experience needed for the role Ideal Candidate Profile Automotive cybersecurity professional with ECU and CAN expertiseExperienced in penetration testing of connected vehicle systems and embedded technologiesComfortable working onsite and interfacing with customers and engineering teams regularly Automotive Embedded Security Tester (BH ID) Embedded Systems Penetration & Fuzz Testing Design & Execute Campaigns: Build and execute comprehensive penetration testing campaigns against a wide variety of automotive embedded targets.Advanced Fuzzing: Configure and deploy targeted fuzzing frameworks (e.g., AFL++, libFuzzer, Peach, Defensics) against vehicle computers, ECUs, and clusters.Vulnerability Discovery: Uncover memory corruption vulnerabilities (buffer overflows, use-after-free), resource exhaustion, and complex logic flaws that automated static analyzers often miss. Comprehensive Wireless & Wired Protocol Analysis Wired Vehicle Networks: Intercept, manipulate, and inject traffic across internal wired topologies, including CAN, CAN-FD, Automotive Ethernet (SOME/IP, DoIP), LIN, and FlexRay. You will utilize industry-standard tools like Vector CANoe/CANalyzer and Vehicle Spy.Wireless Ecosystems: Aggressively analyze and exploit vulnerabilities across every wireless communication interface. This includes deep-dive assessments of Bluetooth/BLE, Wi-Fi (802.11), Cellular networks (4G/LTE, 5G, and C-V2X), UWB, NFC, and traditional RF/Keyless Entry Systems (RKE/PEPS) using Software Defined Radios (SDRs like HackRF, USRP). Hardware & Firmware Reverse Engineering Physical Attack Vectors: Conduct hands-on, hardware-level security testing to identify physical attack vectors.Hardware Debugging & Exploitation: Utilize tools like Logic Analyzers, Bus Pirate, J-Link, and UART/JTAG/SPI debuggers, side-channel analysis (SCA), and voltage/clock fault injection techniques.Firmware Analysis: Extract firmware from flash memory for subsequent reverse engineering and static analysis using disassemblers like IDA Pro. AI-Enhanced Fuzzing and Vulnerability Discovery Develop and apply AI-driven fuzzing techniques, using machine learning to intelligently guide test case generation and uncover complex vulnerabilities in vehicle software.Utilize ML models to perform automated analysis of source code and binaries, identifying potential zero-day vulnerabilities that evade traditional static and dynamic analysis tools. Automated Anomaly Detection in Vehicle Networks Implement and manage machine learning systems to analyze real-time data from CAN, Automotive Ethernet, and wireless channels, automatically detecting anomalous patterns indicative of a cyberattack. Adversarial AI/ML System Testing Conduct security assessments of on-board AI/ML systems (e.g., those used for perception, sensor fusion, or decision-making in autonomous driving).Design and execute adversarial attacks (e.g., data poisoning, evasion attacks) to test the resilience and integrity of automotive AI models. Strategic Remediation Actionable Reporting: Document findings in meticulous, highly technical reports that include mitigation strategies.Engineering Collaboration: Partner directly with other security tester/consultants to craft actionable, robust remediation strategies that fix the root cause of vulnerabilities. What We Are Looking For Experience & Education Bachelor s or Master s degree in Computer Science, Cybersecurity, Computer Engineering, or a heavily related technical discipline.Proven experience in applying AI/ML techniques to cybersecurity challenges, such as intelligent fuzzing, anomaly detection, or securing machine learning systems.3+ years of hands-on experience in penetration testing, vulnerability research, or reverse engineering, specifically focused on automotive embedded systems, IoT devices, or specialized custom hardware. Deep Technical Expertise & Certifications Deep understanding of automotive E/E architectures, RTOS (e.g., QNX, VxWorks, AUTOSAR OS), and POSIX-based systems (Automotive Linux).Familiarity with automotive microcontrollers (e.g., Infineon AURIX TriCore, Renesas RH850, ARM Cortex-R/M) and hardware security modules (HSM/SHE).Strong grasp of industry-standard cybersecurity regulations and frameworks, specifically ISO/SAE 21434, UNECE WP.29 R155, and MITRE ATT&CK.Knowledge of common machine learning frameworks (e.g., TensorFlow, PyTorch, scikit-learn) and their application in a security context.Understanding of adversarial ML concepts and defenses.Preferred Certifications: OSCP, OSCE, OSWE, eCPTX, GXPN, or specialized automotive/IoT security certifications. Programming & Tooling Proficiency Proficiency in scripting and low-level programming languages such as Python, C/C++, Bash, or Assembly (ARM/x86/TriCore).Experience with data science and machine learning libraries within Python (e.g., Pandas, NumPy).Extensive hands-on experience with hardware/software testing tools (e.g., Oscilloscopes, Wireshark, Burp Suite, GNU Radio, Binwalk). GTECH LLC Shivam Tiwari | Technical Recruiter Mobile (469)224-4693| Fax: (469) 336-1672 IT and Telecom Staffing | Consulting | Digital Transformation Data Analytics and Data Governance | 5G Network Design We believe great people deliver great technology In the event that I am unavailable, please do not hesitate to contact my manager, Pradip Sarkar at psarkar@greattechglobal.com Disclaimer: "Under Bill s. 1618 Title III passed by the 105th U.S. Congress this mail cannot be considered spam as long as we include a way to be removed from our mailing list. Simply send us an e-mail with REMOVE in the subject to remove@greattechglobal.com and we will gladly REMOVE you from our mail. Good Day, My name is Shivam and I am a Recruitment Specialist. I have a exclusive Job opportunity, let me know if you are interested. Job Title Pen Testing Engineer Job Location Plymouth, MI Work Mode Hybrid Job Type C2C Job Duration 6-12+ Months Interview Process Video Call Instructions Payment term 60/45 2+ year contract until headcount opens up. ETAS is on a hiring freeze. Work is stable so they would like to convert down the road. Job Description:- Technical Skills Penetration testing experienceMust have experience beyond fuzz testingLooking for candidates with security testing experience in one or more of the following areas:USBWireless communicationsBluetoothSimilar embedded/connected device technologies Interview Feedback Recently interviewed two candidates whose experience was limited to fuzz testingCandidates lacked the broader hands-on security testing experience needed for the role Ideal Candidate Profile Automotive cybersecurity professional with ECU and CAN expertiseExperienced in penetration testing of connected vehicle systems and embedded technologiesComfortable working onsite and interfacing with customers and engineering teams regularly Automotive Embedded Security Tester (BH ID) Embedded Systems Penetration & Fuzz Testing Design & Execute Campaigns: Build and execute comprehensive penetration testing campaigns against a wide variety of automotive embedded targets.Advanced Fuzzing: Configure and deploy targeted fuzzing frameworks (e.g., AFL++, libFuzzer, Peach, Defensics) against vehicle computers, ECUs, and clusters.Vulnerability Discovery: Uncover memory corruption vulnerabilities (buffer overflows, use-after-free), resource exhaustion, and complex logic flaws that automated static analyzers often miss. Comprehensive Wireless & Wired Protocol Analysis Wired Vehicle Networks: Intercept, manipulate, and inject traffic across internal wired topologies, including CAN, CAN-FD, Automotive Ethernet (SOME/IP, DoIP), LIN, and FlexRay. You will utilize industry-standard tools like Vector CANoe/CANalyzer and Vehicle Spy.Wireless Ecosystems: Aggressively analyze and exploit vulnerabilities across every wireless communication interface. This includes deep-dive assessments of Bluetooth/BLE, Wi-Fi (802.11), Cellular networks (4G/LTE, 5G, and C-V2X), UWB, NFC, and traditional RF/Keyless Entry Systems (RKE/PEPS) using Software Defined Radios (SDRs like HackRF, USRP). Hardware & Firmware Reverse Engineering Physical Attack Vectors: Conduct hands-on, hardware-level security testing to identify physical attack vectors.Hardware Debugging & Exploitation: Utilize tools like Logic Analyzers, Bus Pirate, J-Link, and UART/JTAG/SPI debuggers, side-channel analysis (SCA), and voltage/clock fault injection techniques.Firmware Analysis: Extract firmware from flash memory for subsequent reverse engineering and static analysis using disassemblers like IDA Pro. AI-Enhanced Fuzzing and Vulnerability Discovery Develop and apply AI-driven fuzzing techniques, using machine learning to intelligently guide test case generation and uncover complex vulnerabilities in vehicle software.Utilize ML models to perform automated analysis of source code and binaries, identifying potential zero-day vulnerabilities that evade traditional static and dynamic analysis tools. Automated Anomaly Detection in Vehicle Networks Implement and manage machine learning systems to analyze real-time data from CAN, Automotive Ethernet, and wireless channels, automatically detecting anomalous patterns indicative of a cyberattack. Adversarial AI/ML System Testing Conduct security assessments of on-board AI/ML systems (e.g., those used for perception, sensor fusion, or decision-making in autonomous driving).Design and execute adversarial attacks (e.g., data poisoning, evasion attacks) to test the resilience and integrity of automotive AI models. Strategic Remediation Actionable Reporting: Document findings in meticulous, highly technical reports that include mitigation strategies.Engineering Collaboration: Partner directly with other security tester/consultants to craft actionable, robust remediation strategies that fix the root cause of vulnerabilities. What We Are Looking For Experience & Education Bachelor s or Master s degree in Computer Science, Cybersecurity, Computer Engineering, or a heavily related technical discipline.Proven experience in applying AI/ML techniques to cybersecurity challenges, such as intelligent fuzzing, anomaly detection, or securing machine learning systems.3+ years of hands-on experience in penetration testing, vulnerability research, or reverse engineering, specifically focused on automotive embedded systems, IoT devices, or specialized custom hardware. Deep Technical Expertise & Certifications Deep understanding of automotive E/E architectures, RTOS (e.g., QNX, VxWorks, AUTOSAR OS), and POSIX-based systems (Automotive Linux).Familiarity with automotive microcontrollers (e.g., Infineon AURIX TriCore, Renesas RH850, ARM Cortex-R/M) and hardware security modules (HSM/SHE).Strong grasp of industry-standard cybersecurity regulations and frameworks, specifically ISO/SAE 21434, UNECE WP.29 R155, and MITRE ATT&CK.Knowledge of common machine learning frameworks (e.g., TensorFlow, PyTorch, scikit-learn) and their application in a security context.Understanding of adversarial ML concepts and defenses.Preferred Certifications: OSCP, OSCE, OSWE, eCPTX, GXPN, or specialized automotive/IoT security certifications. Programming & Tooling Proficiency Proficiency in scripting and low-level programming languages such as Python, C/C++, Bash, or Assembly (ARM/x86/TriCore).Experience with data science and machine learning libraries within Python (e.g., Pandas, NumPy).Extensive hands-on experience with hardware/software testing tools (e.g., Oscilloscopes, Wireshark, Burp Suite, GNU Radio, Binwalk). GTECH LLC Shivam Tiwari | Technical Recruiter Mobile (469)224-4693| Fax: (469) 336-1672 IT and Telecom Staffing | Consulting | Digital Transformation Data Analytics and Data Governance | 5G Network Design We believe great people deliver great technology In the event that I am unavailable, please do not hesitate to contact my manager, Pradip Sarkar at psarkar@greattechglobal.com Disclaimer: "Under Bill s. 1618 Title III passed by the 105th U.S. Congress this mail cannot be considered spam as long as we include a way to be removed from our mailing list. Simply send us an e-mail with REMOVE in the subject to remove@greattechglobal.com and we will gladly REMOVE you from our mail.