汽车信息安全运营工程师(VSOC)
Indexed description
该职位来源于猎聘 Mission of the Role: To protect our connected vehicle fleet in the wild. You will be our frontline defender, monitoring live threats, leading incident response, and ensuring the continuous security health of our vehicles after they leave the factory. Your work directly safeguards our customers and maintains trust in our brand. Key Responsibilities: Proactive Fleet Monitoring & Analysis: Monitor and analyze security alerts and telemetry data from the global vehicle fleet using SIEM and dedicated automotive security operation center (VSOC) tools. Triage potential security incidents, conduct initial investigation, and assess impact severity. Develop and refine detection rules and use cases to identify novel attack patterns. Incident Response & Forensics: Lead and coordinate the technical response to verified cybersecurity incidents following established playbooks. Perform digital forensics on vehicle logs and data to determine root cause, attack vectors, and scope of compromise. Document incident timelines, actions taken, and lessons learned for post-mortem reviews. Vulnerability Management & Remediation: Manage the intake, assessment, and prioritization of vulnerabilities reported from bug bounties, internal tests, or external researchers for fielded vehicles. Collaborate with Engineering and Supplier teams to develop, validate, and deploy security updates (Over-The-Air or via dealerships). Track remediation campaigns and verify their effectiveness across the fleet. Continuous Improvement & Reporting: Generate regular reports on fleet security posture, incident metrics, and threat landscape trends for management. Contribute to the improvement of post-production security tools, processes, and response playbooks. Stay current with emerging automotive threats, attacker techniques, and industry best practices in fleet security. Qualifications (Must-Have): Bachelor’s degree in Computer Science, Electrical Engineering, Cybersecurity, or a related field. 3+ years of hands-on experience in cybersecurity, with at least 1 year focused on automotive or IoT/embedded systems. Practical experience with incident response and security monitoring in a live operations environment. Strong understanding of in-vehicle networks (CAN, Ethernet, SOME/IP), ECUs, and automotive protocols. Familiarity with common automotive cybersecurity standards and regulations (e.g., ISO/SAE 21434, UN R155, GB44495). Proficiency in analyzing system logs, network traffic, and security event data. Excellent problem-solving, analytical, and communication skills. Qualifications (Nice-to-Have): Experience with Vehicle Security Operation Center (VSOC) tools or automotive threat detection platforms (e.g., Upstream, Karamba, Argus). Knowledge of OTA update mechanics and security. Experience with scripting for automation (Python, PowerShell). Relevant certifications (e.g., GIAC GCIA, GCIH, CISSP, or automotive-specific ones).
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search