Architect - Cybersecurity

Posted 5 Days Ago
Be an Early Applicant
Bangalore, Bengaluru Urban, Karnataka, IND
In-Office
Entry level
Consumer Web • Information Technology
The Role
Designs and governs cybersecurity architectures for connected automotive systems, including Android Automotive, Linux infotainment, telematics, OTA updates, and backend services. Conducts TARA, defines security requirements and controls, supports ISO/SAE 21434, UNECE R155/R156 compliance, verification, vulnerability remediation, incident readiness, supplier reviews, and cybersecurity assessments. The role collaborates with engineering, quality, validation, program, cloud, and supplier teams to maintain risk-to-control traceability and security evidence throughout the product lifecycle.
Summary Generated by Built In
HARMAN’s engineers and designers are creative, purposeful and agile. As part of this team, you’ll combine your technical expertise with innovative ideas to help drive cutting-edge solutions in the car, enterprise and connected ecosystem. Every day, you will push the boundaries of creative design, and HARMAN is committed to providing you with the opportunities, innovative technologies and resources to build a successful career.

A Career at HARMAN

As a technology leader that is rapidly on the move, HARMAN is filled with people who are focused on making life better. Innovation, inclusivity and teamwork are a part of our DNA. When you add that to the challenges we take on and solve together, you’ll discover that at HARMAN you can grow, make a difference and be proud of the work you do everyday.

Introduction: A Career at HARMAN Automotive

We’re a global, multi-disciplinary team that’s putting the innovative power of technology to work and transforming tomorrow. At HARMAN Automotive, we give you the keys to fast-track your career.

  • Engineer audio systems and integrated technology platforms that augment the driving experience
  • Combine ingenuity, in-depth research, and a spirit of collaboration with design and engineering excellence
  • Advance in-vehicle infotainment, safety, efficiency, and enjoyment

About the Role

As an Automotive Cybersecurity Architect, you will define and guide cybersecurity concepts and architectures for connected vehicle systems, including Android Automotive and Linux-based infotainment platforms, telematics, connectivity, and supporting backend services. You will translate cybersecurity risks, regulatory obligations, and product requirements into implementable controls, engineering work products, and compliance evidence. You will collaborate with systems, software, hardware, validation, quality, and program teams to ensure cybersecurity is addressed throughout the product lifecycle. This is an individual contributor role, and the reporting relationship is to be confirmed.

What You Will Do

  • Develop and maintain cybersecurity concepts, cybersecurity requirements, security architectures, interface specifications, and verification criteria for automotive products.
  • Plan, facilitate, document, and maintain Threat Analysis and Risk Assessment activities, including asset identification, attack-path analysis, impact assessment, risk determination, cybersecurity goals, and risk-treatment decisions.
  • Create, review, and maintain applicable ISO/SAE 21434 work products, ensuring bidirectional traceability between identified risks, cybersecurity goals, requirements, architecture decisions, implemented controls, verification evidence, and residual-risk decisions.
  • Perform cybersecurity architecture reviews and provide actionable guidance to system, software, hardware, cloud, and validation teams.
  • Define security controls for Android Automotive and Linux-based IVI systems, including secure boot, chain of trust, SELinux policy, application sandboxing, Trusted Execution Environment integration, Trusted Applications, key protection, and secure storage.
  • Define and review cryptographic designs involving PKI, certificate and key lifecycle management, authentication, authorization, encryption, TLS/SSL, OpenSSL, JSSE, and secure communications.
  • Define security controls for telematics and connected systems, including connectivity, diagnostics, vehicle-to-backend communication, OTA software updates, software authenticity, integrity validation, rollback protection, and secure update authorization.
  • Support implementation of Cybersecurity Management System processes and product evidence needed for UNECE R155 compliance, cybersecurity audits, assessments, and Vehicle Type Approval activities.
  • Support Software Update Management System processes and product evidence needed for UNECE R156 compliance, including software update governance, update traceability, integrity and authenticity controls, compatibility assessment, and update verification evidence.
  • Contribute to cybersecurity case development by consolidating requirements, analyses, architecture decisions, test results, vulnerability information, open risks, assumptions, deviations, and residual-risk acceptance evidence.
  • Support cybersecurity planning, cybersecurity interface agreements, supplier cybersecurity reviews, distributed-development coordination, and review of supplier-provided cybersecurity evidence.
  • Define cybersecurity verification and validation strategies, including security requirements testing, robustness testing, vulnerability scanning, fuzz testing, penetration-testing support, and remediation verification.
  • Assess vulnerabilities and coordinate their treatment through triage, applicability analysis, risk evaluation, remediation planning, security patch integration, verification, disclosure coordination, and post-production monitoring.
  • Support incident-response readiness and product cybersecurity monitoring by defining logging, detection, escalation, investigation, containment, and evidence-retention expectations.
  • Review backend and API security controls, including identity and access management, authentication, authorization, encryption, secrets management, secure API design, logging, monitoring, and cloud security fundamentals.
  • Support alignment between automotive product cybersecurity activities and relevant ISO/IEC 27001 controls where product, development, operational, or backend environments intersect with the organizational information security management system.
  • Prepare and present cybersecurity status, risks, assumptions, compliance gaps, remediation plans, and technical decisions to engineering and program stakeholders.
  • Support internal and external cybersecurity assessments by providing objective evidence, responding to findings, and tracking corrective actions to closure.
  • Promote security-by-design practices, reusable security patterns, secure engineering guidance, and lessons learned across automotive development teams.

What You Need to Be Successful

  • Bachelor’s degree in computer science, cybersecurity, electrical engineering, software engineering, telecommunications, or a related technical discipline.
  • Professional experience in automotive cybersecurity, embedded security, product security, or security architecture. The required number of years is to be confirmed.
  • Hands-on experience applying ISO/SAE 21434 within an automotive product lifecycle and producing or reviewing cybersecurity engineering work products.
  • Practical experience conducting and documenting TARA activities and deriving cybersecurity goals, claims, requirements, and risk-treatment measures.
  • Working knowledge of UNECE R155, CSMS expectations, audit evidence, and cybersecurity contributions to Vehicle Type Approval.
  • Working knowledge of UNECE R156, SUMS expectations, and security considerations for automotive software update and OTA processes.
  • Experience developing or reviewing cybersecurity concepts, system security architectures, cybersecurity requirements, design decisions, interface controls, and verification strategies.
  • Strong understanding of embedded and connected-system security, including secure boot, roots of trust, hardware-backed key storage, Trusted Execution Environments, cryptography, PKI, authentication, authorization, secure communications, and secure diagnostics.
  • Knowledge of Android Automotive or Android platform security, including SELinux, application permissions, sandboxing, keystore concepts, Trusted Applications, JSSE, and platform update security.
  • Knowledge of Linux security concepts, including access control, privilege separation, hardening, service isolation, secure configuration, logging, and OpenSSL-based communications.
  • Understanding of telematics, connected-vehicle interfaces, OTA systems, vehicle-to-cloud communication, and backend or API security fundamentals.
  • Experience with cybersecurity verification methods such as security testing, vulnerability analysis, fuzz testing, penetration-testing coordination, and remediation verification.
  • Ability to establish and maintain requirements-to-test and risk-to-control traceability using structured engineering lifecycle processes.
  • Ability to assess technical findings, communicate risk accurately, and recommend proportionate mitigations without losing sight of product, safety, usability, performance, and delivery constraints.
  • Strong written and verbal communication skills, with the ability to explain cybersecurity topics to engineering, management, quality, compliance, and non-security stakeholders.
  • Working proficiency in English.

Bonus Points if You Have

  • Master’s degree in cybersecurity, computer science, electrical engineering, software engineering, or a related discipline.
  • Recognized cybersecurity certifications such as CISSP, CSSLP, CCSP, OSCP, or an automotive cybersecurity certification.
  • Experience supporting Certification Authorities, technical services, OEM compliance teams, or approval authorities during CSMS, SUMS, UNECE R155, UNECE R156, or Vehicle Type Approval activities.
  • Experience with ISO 24089 software update engineering, ISO 26262 functional safety, Automotive SPICE, TISAX, or ISO/IEC 27001.
  • Experience creating cybersecurity cases, assurance arguments, compliance matrices, audit packages, or release-readiness evidence.
  • Experience with hardware security modules, secure elements, TPMs, TrustZone, hypervisors, domain isolation, secure provisioning, code signing, or manufacturing security.
  • Experience securing automotive communication technologies and protocols such as CAN, LIN, Automotive Ethernet, SOME/IP, DoIP, UDS, Bluetooth, Wi-Fi, cellular, or GNSS-related services.
  • Experience with software composition analysis, Software Bill of Materials, open-source compliance, vulnerability management, security scanning, or DevSecOps integration.
  • Experience with cloud security, connected-vehicle backends, API gateways, IAM, OAuth 2.0, OpenID Connect, certificate management, or security monitoring.
  • Experience collaborating with globally distributed engineering teams, suppliers, third-party laboratories, or independent cybersecurity assessors.

What Makes You Eligible

  • You are eligible to work in the country of employment. Country and any applicable work-authorization requirements are to be confirmed.
  • You are able to work from the designated HARMAN or customer location when required. Location and hybrid-working expectations are to be confirmed.
  • You are willing to travel as required. Expected travel frequency is to be confirmed.
  • You can collaborate effectively across global time zones when program activities require it.

What We Offer

  • A hybrid work environment that balances flexibility with in-person collaboration, with most office-based roles onsite three days a week.
  • Access to employee discounts on world-class Harman and Samsung products (JBL, HARMAN Kardon, AKG, etc.)
  • Extensive training opportunities through our own HARMAN University
  • Competitive wellness benefits
  • Tuition reimbursement
  • “Be Brilliant” employee recognition and rewards program
  • An inclusive and diverse work environment that fosters and encourages professional and personal development

HARMAN is proud to be an Equal Opportunity / Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

Skills Required

  • Bachelor's degree in computer science, cybersecurity, electrical engineering, software engineering, telecommunications, or a related technical discipline
  • Professional experience in automotive cybersecurity, embedded security, product security, or security architecture
  • Hands-on experience applying ISO/SAE 21434 across an automotive product lifecycle
  • Experience producing or reviewing automotive cybersecurity engineering work products
  • Practical experience conducting and documenting Threat Analysis and Risk Assessment activities
  • Working knowledge of UNECE R155, CSMS expectations, audit evidence, and Vehicle Type Approval
  • Working knowledge of UNECE R156, SUMS expectations, and automotive OTA security
  • Experience developing or reviewing cybersecurity concepts, security architectures, requirements, interface controls, and verification strategies
  • Understanding of embedded and connected-system security, secure boot, roots of trust, hardware-backed key storage, Trusted Execution Environments, cryptography, PKI, authentication, authorization, and secure communications
  • Knowledge of Android Automotive or Android platform security, including SELinux, permissions, sandboxing, keystore concepts, Trusted Applications, JSSE, and platform update security
  • Knowledge of Linux security, including access control, privilege separation, hardening, service isolation, secure configuration, logging, and OpenSSL communications
  • Understanding of telematics, connected-vehicle interfaces, OTA systems, vehicle-to-cloud communication, and backend or API security
  • Experience with security testing, vulnerability analysis, fuzz testing, penetration-testing coordination, and remediation verification
  • Ability to maintain requirements-to-test and risk-to-control traceability
  • Strong written and verbal communication skills
  • Working proficiency in English
  • Master's degree in cybersecurity, computer science, electrical engineering, software engineering, or a related discipline
  • CISSP, CSSLP, CCSP, OSCP, or automotive cybersecurity certification
  • Experience supporting Certification Authorities, technical services, OEM compliance teams, or approval authorities
  • Experience with ISO 24089, ISO 26262, Automotive SPICE, TISAX, or ISO/IEC 27001
  • Experience creating cybersecurity cases, assurance arguments, compliance matrices, audit packages, or release-readiness evidence
  • Experience with hardware security modules, secure elements, TPMs, TrustZone, hypervisors, domain isolation, secure provisioning, code signing, or manufacturing security
  • Experience securing automotive communication technologies and protocols
  • Experience with software composition analysis, SBOMs, open-source compliance, vulnerability management, security scanning, or DevSecOps
  • Experience with cloud security, connected-vehicle backends, API gateways, IAM, OAuth 2.0, OpenID Connect, certificate management, or security monitoring
  • Experience collaborating with globally distributed engineering teams, suppliers, third-party laboratories, or independent cybersecurity assessors

Harman Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Harman and has not been reviewed or approved by Harman.

  • Healthcare Strength Healthcare coverage is described as comprehensive, often including medical, dental, and vision plans, with HSAs/FSAs and disability or life insurance also referenced. Wellbeing support such as EAP access and onsite occupational health services is also part of the package in some regions.
  • Wellbeing & Lifestyle Benefits Lifestyle-oriented benefits include employee product discounts and region-specific perks like free fruit deliveries, Cycle to Work schemes, and meal coupons or allowances. Flexible schedules and work-from-home options are also part of the overall offering where roles and projects allow.
  • Fair & Transparent Compensation Pay is repeatedly characterized as solid or market-aligned for many roles, with salary payments described as consistent and on time. Compensation is also tied to performance in some accounts, reinforcing a perception of basic fairness for a portion of employees.

Harman Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Stamford, CT
22,291 Employees
Year Founded: 1980

What We Do

Headquartered in Stamford, Connecticut, HARMAN (harman.com) designs and engineers connected products and solutions for automakers, consumers, and enterprises worldwide, including connected car systems, audio and visual products, enterprise automation solutions; and services supporting the Internet of Things. With leading brands including AKG®, Harman Kardon®, Infinity®, JBL®, Lexicon®, Mark Levinson® and Revel®, HARMAN is admired by audiophiles, musicians and the entertainment venues where they perform around the world. More than 50 million automobiles on the road today are equipped with HARMAN audio and connected car systems. Our software services power billions of mobile devices and systems that are connected, integrated and secure across all platforms, from work and home to car and mobile. HARMAN has a workforce of approximately 30,000 people across the Americas, Europe, and Asia. In March 2017, HARMAN became a wholly-owned subsidiary of Samsung Electronics Co., Ltd. HARMAN is an Equal Opportunity, Affirmative Action employer. Minorities, women, veterans and individuals with disabilities are encouraged to apply. HARMAN offers a great work environment, challenging career opportunities, professional training and competitive compensation. Looking for a challenge where your experience is valued? Come see what you can achieve as a leader with HARMAN!

Similar Jobs

MLabs Logo MLabs

Architect

Artificial Intelligence • Blockchain • Information Technology • Consulting
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND

Smiths Group plc Logo Smiths Group plc

Architect

Aerospace • Security • Energy • Defense
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
9512 Employees

onsemi Logo onsemi

Architect

Automotive • Cloud • Energy
In-Office
2 Locations
11712 Employees

Similar Companies Hiring

Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account