Architect - Cybersecurity
HARMAN International Bangalore, Karnataka, India
Computers and Electronics Manufacturing · 10,001+ employees
About the role
The Cybersecurity Architect will define and guide security concepts and architectures for connected vehicle systems, including infotainment and telematics platforms. They will collaborate with cross-functional teams to ensure cybersecurity compliance throughout the product lifecycle, from threat analysis to verification and validation.
What they look for
Requirements
Candidates must hold a bachelor's degree in a technical discipline and possess professional experience in automotive cybersecurity or embedded security. Proficiency in ISO/SAE 21434, UNECE regulations, and secure engineering practices for Android and Linux-based systems is required.
Benefits
Full description
HARMAN’s engineers and designers are creative, purposeful and agile. As part of this team, you’ll combine your technical expertise with innovative ideas to help drive cutting-edge solutions in the car, enterprise and connected ecosystem. Every day, you will push the boundaries of creative design, and HARMAN is committed to providing you with the opportunities, innovative technologies and resources to build a successful career.
A Career at HARMAN
As a technology leader that is rapidly on the move, HARMAN is filled with people who are focused on making life better. Innovation, inclusivity and teamwork are a part of our DNA. When you add that to the challenges we take on and solve together, you’ll discover that at HARMAN you can grow, make a difference and be proud of the work you do everyday.
Introduction: A Career at HARMAN Automotive
We’re a global, multi-disciplinary team that’s putting the innovative power of technology to work and transforming tomorrow. At HARMAN Automotive, we give you the keys to fast-track your career.
- Engineer audio systems and integrated technology platforms that augment the driving experience
- Combine ingenuity, in-depth research, and a spirit of collaboration with design and engineering excellence
- Advance in-vehicle infotainment, safety, efficiency, and enjoyment
About the Role
As an Automotive Cybersecurity Architect, you will define and guide cybersecurity concepts and architectures for connected vehicle systems, including Android Automotive and Linux-based infotainment platforms, telematics, connectivity, and supporting backend services. You will translate cybersecurity risks, regulatory obligations, and product requirements into implementable controls, engineering work products, and compliance evidence. You will collaborate with systems, software, hardware, validation, quality, and program teams to ensure cybersecurity is addressed throughout the product lifecycle. This is an individual contributor role, and the reporting relationship is to be confirmed.
What You Will Do
- Develop and maintain cybersecurity concepts, cybersecurity requirements, security architectures, interface specifications, and verification criteria for automotive products.
- Plan, facilitate, document, and maintain Threat Analysis and Risk Assessment activities, including asset identification, attack-path analysis, impact assessment, risk determination, cybersecurity goals, and risk-treatment decisions.
- Create, review, and maintain applicable ISO/SAE 21434 work products, ensuring bidirectional traceability between identified risks, cybersecurity goals, requirements, architecture decisions, implemented controls, verification evidence, and residual-risk decisions.
- Perform cybersecurity architecture reviews and provide actionable guidance to system, software, hardware, cloud, and validation teams.
- Define security controls for Android Automotive and Linux-based IVI systems, including secure boot, chain of trust, SELinux policy, application sandboxing, Trusted Execution Environment integration, Trusted Applications, key protection, and secure storage.
- Define and review cryptographic designs involving PKI, certificate and key lifecycle management, authentication, authorization, encryption, TLS/SSL, OpenSSL, JSSE, and secure communications.
- Define security controls for telematics and connected systems, including connectivity, diagnostics, vehicle-to-backend communication, OTA software updates, software authenticity, integrity validation, rollback protection, and secure update authorization.
- Support implementation of Cybersecurity Management System processes and product evidence needed for UNECE R155 compliance, cybersecurity audits, assessments, and Vehicle Type Approval activities.
- Support Software Update Management System processes and product evidence needed for UNECE R156 compliance, including software update governance, update traceability, integrity and authenticity controls, compatibility assessment, and update verification evidence.
- Contribute to cybersecurity case development by consolidating requirements, analyses, architecture decisions, test results, vulnerability information, open risks, assumptions, deviations, and residual-risk acceptance evidence.
- Support cybersecurity planning, cybersecurity interface agreements, supplier cybersecurity reviews, distributed-development coordination, and review of supplier-provided cybersecurity evidence.
- Define cybersecurity verification and validation strategies, including security requirements testing, robustness testing, vulnerability scanning, fuzz testing, penetration-testing support, and remediation verification.
- Assess vulnerabilities and coordinate their treatment through triage, applicability analysis, risk evaluation, remediation planning, security patch integration, verification, disclosure coordination, and post-production monitoring.
- Support incident-response readiness and product cybersecurity monitoring by defining logging, detection, escalation, investigation, containment, and evidence-retention expectations.
- Review backend and API security controls, including identity and access management, authentication, authorization, encryption, secrets management, secure API design, logging, monitoring, and cloud security fundamentals.
- Support alignment between automotive product cybersecurity activities and relevant ISO/IEC 27001 controls where product, development, operational, or backend environments intersect with the organizational information security management system.
- Prepare and present cybersecurity status, risks, assumptions, compliance gaps, remediation plans, and technical decisions to engineering and program stakeholders.
- Support internal and external cybersecurity assessments by providing objective evidence, responding to findings, and tracking corrective actions to closure.
- Promote security-by-design practices, reusable security patterns, secure engineering guidance, and lessons learned across automotive development teams.
What You Need to Be Successful
- Bachelor’s degree in computer science, cybersecurity, electrical engineering, software engineering, telecommunications, or a related technical discipline.
- Professional experience in automotive cybersecurity, embedded security, product security, or security architecture. The required number of years is to be confirmed.
- Hands-on experience applying ISO/SAE 21434 within an automotive product lifecycle and producing or reviewing cybersecurity engineering work products.
- Practical experience conducting and documenting TARA activities and deriving cybersecurity goals, claims, requirements, and risk-treatment measures.
- Working knowledge of UNECE R155, CSMS expectations, audit evidence, and cybersecurity contributions to Vehicle Type Approval.
- Working knowledge of UNECE R156, SUMS expectations, and security considerations for automotive software update and OTA processes.
- Experience developing or reviewing cybersecurity concepts, system security architectures, cybersecurity requirements, design decisions, interface controls, and verification strategies.
- Strong understanding of embedded and connected-system security, including secure boot, roots of trust, hardware-backed key storage, Trusted Execution Environments, cryptography, PKI, authentication, authorization, secure communications, and secure diagnostics.
- Knowledge of Android Automotive or Android platform security, including SELinux, application permissions, sandboxing, keystore concepts, Trusted Applications, JSSE, and platform update security.
- Knowledge of Linux security concepts, including access control, privilege separation, hardening, service isolation, secure configuration, logging, and OpenSSL-based communications.
- Understanding of telematics, connected-vehicle interfaces, OTA systems, vehicle-to-cloud communication, and backend or API security fundamentals.
- Experience with cybersecurity verification methods such as security testing, vulnerability analysis, fuzz testing, penetration-testing coordination, and remediation verification.
- Ability to establish and maintain requirements-to-test and risk-to-control traceability using structured engineering lifecycle processes.
- Ability to assess technical findings, communicate risk accurately, and recommend proportionate mitigations without losing sight of product, safety, usability, performance, and delivery constraints.
- Strong written and verbal communication skills, with the ability to explain cybersecurity topics to engineering, management, quality, compliance, and non-security stakeholders.
- Working proficiency in English.
Bonus Points if You Have
- Master’s degree in cybersecurity, computer science, electrical engineering, software engineering, or a related discipline.
- Recognized cybersecurity certifications such as CISSP, CSSLP, CCSP, OSCP, or an automotive cybersecurity certification.
- Experience supporting Certification Authorities, technical services, OEM compliance teams, or approval authorities during CSMS, SUMS, UNECE R155, UNECE R156, or Vehicle Type Approval activities.
- Experience with ISO 24089 software update engineering, ISO 26262 functional safety, Automotive SPICE, TISAX, or ISO/IEC 27001.
- Experience creating cybersecurity cases, assurance arguments, compliance matrices, audit packages, or release-readiness evidence.
- Experience with hardware security modules, secure elements, TPMs, TrustZone, hypervisors, domain isolation, secure provisioning, code signing, or manufacturing security.
- Experience securing automotive communication technologies and protocols such as CAN, LIN, Automotive Ethernet, SOME/IP, DoIP, UDS, Bluetooth, Wi-Fi, cellular, or GNSS-related services.
- Experience with software composition analysis, Software Bill of Materials, open-source compliance, vulnerability management, security scanning, or DevSecOps integration.
- Experience with cloud security, connected-vehicle backends, API gateways, IAM, OAuth 2.0, OpenID Connect, certificate management, or security monitoring.
- Experience collaborating with globally distributed engineering teams, suppliers, third-party laboratories, or independent cybersecurity assessors.
What Makes You Eligible
- You are eligible to work in the country of employment. Country and any applicable work-authorization requirements are to be confirmed.
- You are able to work from the designated HARMAN or customer location when required. Location and hybrid-working expectations are to be confirmed.
- You are willing to travel as required. Expected travel frequency is to be confirmed.
- You can collaborate effectively across global time zones when program activities require it.
What We Offer
- A hybrid work environment that balances flexibility with in-person collaboration, with most office-based roles onsite three days a week.
- Access to employee discounts on world-class Harman and Samsung products (JBL, HARMAN Kardon, AKG, etc.)
- Extensive training opportunities through our own HARMAN University
- Competitive wellness benefits
- Tuition reimbursement
- “Be Brilliant” employee recognition and rewards program
- An inclusive and diverse work environment that fosters and encourages professional and personal development
HARMAN is proud to be an Equal Opportunity / Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
Similar roles
-
Staff Security Engineer, Abuse Control
Stripe London, England, United Kingdom
-
Senior Infrastructure and Cloud Security Engineer (m/f/d)
ICE Services London, England, United Kingdom
-
Lead - Product Security Engineer
Rocketlane Chennai, Tamil Nadu, India
-
Lead Manager, IT Security Engineer
Make-A-Wish America $70K–$84K/yr
-
Staff Cloud Security Engineer
Xometry Quinte West, Ontario, Canada · $205K–$233K/yr
-
Fire Security Engineer
Allsaved Ltd Glasgow, Scotland, United Kingdom · £38K–£45K/yr