Position Overview
We are seeking an experienced Senior Embedded Security Engineer to join our Cybersecurity Lab in Singapore. This role sits at the heart of Desay SV's security left-shift strategy, responsible for designing and executing end-to-end security test programmes across embedded automotive systems β from ECU firmware and BSP layers through to in-vehicle network protocols and OTA update pipelines.
The ideal candidate brings deep hands-on expertise in embedded systems security, proven experience with automotive communication protocols, and the practical mindset to operate both as a technical practitioner and as a collaborator with AI-assisted toolchains. You will play a central role in validating agent-generated threat assessments, providing real-world evidence that feeds into TARA workflows, SBOM analysis, and compliance submissions for OEM customers.
Key Responsibilities
Security Testing & Vulnerability Research
-
Lead and execute security test programmes for ECUs, SoCs, and in-vehicle network components across the full embedded stack: firmware, RTOS (QNX, Linux, AUTOSAR), middleware, and application layers.
-
Design and perform penetration testing, fuzzing, and reverse engineering on automotive hardware and firmware.
-
Conduct vulnerability analysis on BSP components, device drivers, cryptographic implementations, and secure boot chains; develop and validate remediation patches.
-
Build and maintain CyberLab test infrastructure: ECU bench setups, network simulators, hardware-in-the-loop (HiL) rigs, and custom security tooling.
SBOM & Supply Chain Security
-
Perform binary SCA on .img firmware, .a/.so libraries, and embedded binaries to identify undeclared open-source components and known vulnerabilities.
-
Validate SBOM completeness against CyberLab test findings; document discrepancies between declared and detected components for OEM compliance submissions.
CI/CD Integration & Automation
-
Integrate security test suites into CI/CD pipelines, enabling automated security regression at the merge request stage for embedded software changes.
-
Develop custom scripts and tooling (Python, C/C++) to automate fuzz test case generation, crash triage, and vulnerability deduplication.
-
Provide real-world attack evidence to the AI-assisted TARA agent pipeline β translating lab findings into structured threat data that improves agent accuracy.
Compliance & OEM Support
-
Prepare security test evidence packages for OEM audit submissions (ISO/SAE 21434, UNECE WP.29 R155/R156, ISO 26262); ensure traceability from test results to cybersecurity requirements.
-
Support cybersecurity case development by supplying empirical attack feasibility data used in TARA risk ratings.
-
Participate in threat modelling and security architecture reviews as the lab's embedded security subject matter expert.
Mentoring & Knowledge Sharing
-
Provide technical guidance to junior engineers in embedded security testing practices, tool usage, and vulnerability documentation.
-
Contribute to internal security research publications, tooling documentation, and knowledge-base articles.
Qualifications
Required
-
Bachelor's degree or above in Computer Science, Electrical/Electronic Engineering, Cybersecurity, or a related field.
-
Proven experience in embedded or automotive cybersecurity testing.
-
Proven hands-on experience in penetration testing, fuzzing, and vulnerability assessment and validation on embedded targets (MCUs, SoCs, automotive ECUs).
-
Strong knowledge of embedded operating systems: Linux (BSP/kernel level), QNX, and AUTOSAR Classic/Adaptive.
-
Solid understanding of automotive communication protocols: CAN, CAN-FD, Ethernet/IP, DoIP.
-
Proficiency in Python, C/C++, and shell scripting for test automation and tool development.
-
Familiarity with cryptographic principles and their automotive implementations: secure boot, SecOC, HSM, TLS.
-
Working knowledge of ISO/SAE 21434 cybersecurity engineering requirements
-
Excellent written and spoken English; ability to produce clear technical documentation for international OEM audiences.
Preferred
-
Experience with binary analysis tools (Ghidra, IDA Pro, Binwalk) applied to automotive firmware.
-
Exposure to SBOM tools (BlackDuck, JFrog Xray, and etc) and binary SCA workflows.
-
Knowledge of OTA update security mechanisms and cloud-connected vehicle architectures.
-
Prior experience working directly on OEM-directed security projects.
-
Security certifications: OSCP, GXPN, CEH, CISSP, or automotive-specific equivalents
-
Experience using or validating AI-assisted threat modelling tools.
Why Join Us
-
Work on live automotive programmes spanning ADAS, IVI, and autonomous driving β security decisions you make directly affect products on the road.
-
Access to a purpose-built CyberLab with real ECU hardware, vehicle networks, and dedicated test infrastructure.
-
Collaborate with a global team across Singapore, Shenzhen, Germany, and Japan on next-generation AI-assisted cybersecurity toolchains.
-
Direct interface with OEM and Tier-1 supplier security teams β building expertise no pure-lab environment can offer.