Lead Engineer - Software and Cyber Security
Mahindra & Mahindra Limited Bengaluru, Karnataka, India
Motor Vehicle Manufacturing · 10,001+ employees
About the role
The Lead Engineer will oversee cybersecurity engineering activities for powertrain control systems, ensuring compliance with global automotive regulations and safety standards. They will define secure architectures, conduct threat assessments, and mentor engineering teams to protect critical vehicle functions.
What they look for
Requirements
Candidates must have 7-9 years of experience in automotive embedded or powertrain systems with a strong understanding of the development lifecycle. A Bachelor's or Master's degree in a relevant engineering or computer science field is required.
Full description
Responsibilities & Key Deliverables
Position Overview
We are looking for an Automotive Cyber Security Testing Lead Engineer for Powertrain ECUs to lead cybersecurity engineering activities for safety-critical powertrain control systems, including ICE, Hybrid, and Electric Powertrain ECUs. The role is responsible for ensuring that powertrain functions are protected against cyber threats and comply with global automotive cybersecurity regulations throughout the product lifecycle.
Key Responsibilities
- Lead cybersecurity engineering activities for Powertrain ECUs such as Engine ECU, VCU, MCU, BMS, HCU, OCDC, etc.
- Serve as the cybersecurity technical owner for assigned powertrain programs.
- Define and review test requirements for cybersecurity controls, including fuzz testing and penetration testing.
- Define and review secure architectures covering secure boot, secure communication, OTA security, and key management.
- Perform and lead Threat Analysis and Risk Assessment (TARA) as per ISO/SAE 21434.
- Define cybersecurity goals, requirements, and mitigation strategies for powertrain systems.
- Guide implementation of cybersecurity controls such as secure boot, secure flashing, and secure communication.
- Ensure alignment between cybersecurity and Functional Safety (ISO 26262) requirements.
- Support compliance activities related to UNECE R155/R156 and AIS 189/190.
- Coordinate cybersecurity activities with system, software, hardware, and validation teams.
- Lead cybersecurity reviews with vehicle teams, suppliers, and internal stakeholders.
- Mentor cybersecurity engineers and review technical deliverables.
- Support vulnerability management, incident response, and post-SOP cybersecurity activities.
Powertrain-Specific Cybersecurity Scope
- Protection of torque, speed, propulsion, charging, and energy management functions.
- Secure diagnostics and calibration access (UDS).
- Secure production and service software updates.
- Protection against unauthorized software or calibration modifications.
Standards & Compliance
- ISO/SAE 21434 – Road Vehicles Cybersecurity Engineering
- UNECE R155 / AIS 189 – Cybersecurity Management System
- UNECE R156 / AIS 190 – Software Update Management System
- ISO 26262 – Functional Safety
Experience
7-9 years of experience in automotive embedded or powertrain systems.Strong understanding of the powertrain ECU development lifecycle.
Industry Preferred
Automotive
Qualifications
Bachelor's or Master's degree in Electronics, Embedded Systems, Automotive Engineering, Computer Science, or Cyber Security
General Requirements
Technical Skills
- Powertrain control systems and real-time embedded software.
- CAN, CAN-FD, Automotive Ethernet, UDS, and ECU communication interfaces.
- Cryptography fundamentals, PKI, and key management.
- Secure boot, HSM, secure diagnostics, and other cybersecurity controls.
- Vulnerability and incident management.
- OTA/FOTA security and backend integration.
- Threat modelling and vulnerability analysis.
Soft Skills & Leadership
- Strong technical leadership and ownership mindset.
- Effective communication with cross-functional teams.
- Risk-based decision-making in safety-critical environments.
- Mentoring and coaching engineers.
Our commitment to Diversity, Equity, and Inclusion