Ph3Overview /h3pbRole purpose : /b Ensure the TCU is conceived and developed according to a security-by-design approach, fully compliant with automotive cybersecurity standards (ISO 21434, UNECE R155 / R156). The role drives security architecture definition, influencing early system and software decisions to safeguard data, communication channels, and the boot path. /ph3Responsibilities decision ownership /h3ulliTARA Mitigation – Perform and maintain Threat Analysis and Risk Assessment, converting risks into actionable security requirements. /liliSecurity architecture definition – Configure Secure Boot, integrate HSM, set firewall rules and Secure Storage in close partnership with System and Software Architects. /liliSecure protocol cryptography integration – Support TLS, IPsec, MACsec; advise on crypto libraries (wolfSSL, PKCS#11) and crypto hardware. /liliKey trust management – Implement root-of-trust, manage X.509 certificates, authenticated OTA and firmware rollback protection. /liliDocumentation compliance – Author Cybersecurity Concept, Security Case; prepare for audits / certifications (UNECE R155 / R156). /liliSecurity testing vulnerability management – Lead pen-testing, fuzzing, SBOM-based vulnerability mitigation within a DevSecOps framework. /li /ulh3Core competencies, knowledge and experience /h3ulliStandards regulations – Mastery of ISO / SAE 21434, UNECE R155 / R156, AUTOSAR Security. /liliSecurity architectures – Secure Boot, HSM / TPM, Secure Element, key provisioning strategies. /liliApplied cryptography – TLS / IPsec protocols, certificate management, side-channel defenses. /liliHW / SW integration – Close work with Linux, AUTOSAR developers and hardware teams. /liliSecurity testing – Pen-testing, fuzzing, embedded vulnerability scanning. /liliSoft skills – Clear communication, technical negotiation, cross-functional teamwork. /li /ulh3Must have technical / professional qualifications /h3ulliDegree in Computer or Electronics Engineering (or equivalent). /lili8–10 years in embedded / automotive cybersecurity roles. /liliHands-on expertise with Secure Boot, HSM / TPM, embedded crypto libraries. /liliFluent English for technical documentation and international audits. /liliFamiliarity with DevSecOps processes, SBOM, pen-test and fuzzing tools. /li /ul /p #J-18808-Ljbffr