Lead Software Architect – Offensive Security & Penetration Testing
We are looking for an experienced Lead Software Architect – Offensive Security & Penetration Testing to lead cybersecurity validation across a large-scale Client.
The role will focus on defining and executing penetration testing strategies, leading internal and external security assessments, identifying vulnerabilities and attack paths, and driving remediation activities across product and engineering teams.
You will work closely with cybersecurity engineers, system architects, software development teams, suppliers, and other key stakeholders to ensure connected platforms and vehicle technologies are resilient against evolving cyber threats and meet relevant security and compliance requirements.
Key Responsibilities
Define and lead offensive security and penetration testing strategies for connected automotive platforms and services.
Plan and execute advanced white-box, gray-box, and black-box penetration testing across embedded systems and connected platforms.
Conduct security assessments of IHU, DHU, UXC, TCAM, Android Automotive, QNX-based platforms, vehicle communications, and connected cloud services.
Perform vulnerability research, exploit development, fuzz testing, and protocol analysis.
Identify vulnerabilities, attack paths, security weaknesses, and potential exploitation scenarios.
Validate vulnerabilities through controlled exploitation and provide clear recommendations for remediation.
Assess security across CAN, Automotive Ethernet, SOME/IP, Bluetooth, Wi-Fi, USB, and other vehicle connectivity technologies.
Conduct security assessments of cloud platforms, APIs, connected services, and communication interfaces.
Review secure communication mechanisms, cryptographic implementations, and security protocols.
Perform threat modeling, attack path analysis, and security architecture reviews.
Collaborate with product teams and development organizations to drive timely vulnerability remediation.
Provide technical guidance on security controls and secure design principles.
Support and contribute to Secure Software Development Lifecycle (SSDLC) activities.
Ensure security validation activities align with relevant automotive cybersecurity standards and regulatory requirements.
Provide technical leadership and communicate complex security findings to both technical and non-technical stakeholders.
Coordinate with internal teams, external security partners, suppliers, and other stakeholders throughout security assessment activities.
Key Technical Skills
Offensive Security & Penetration Testing
Advanced penetration testing – White-box, Gray-box, and Embedded Systems
Offensive security and vulnerability research
Fuzz testing and protocol analysis
Exploit development and vulnerability validation
Security testing of connected and embedded platforms
Automotive & Embedded Security
Android Automotive OS (AAOS) / AOSP security
QNX security architecture
Embedded Linux security
Automotive cybersecurity
Vehicle network security – CAN, Ethernet, SOME/IP
Bluetooth, Wi-Fi, USB, and connectivity security
Cloud & Application Security
Cloud security assessments
API security testing
Secure communication protocols
Cryptographic protocols and implementations
Threat modeling and attack path analysis
Security Engineering & Architecture
Security validation and exploit verification
Vulnerability management and risk assessment
Security architecture reviews
Secure Software Development Lifecycle (SSDLC)
Security requirements and remediation management
Standards & Compliance
ISO/SAE 21434
UNECE R155
Automotive cybersecurity engineering and security validation practices
Required Qualifications
Bachelor's or Master's degree in Cybersecurity, Software Engineering, Computer Science, Electronics, or a related field, or equivalent practical experience.
10+ years of experience in cybersecurity, penetration testing, offensive security, vulnerability research, or security architecture.
Proven experience conducting advanced penetration testing of embedded systems, automotive platforms, or connected products.
Strong understanding of Linux, Android, QNX, and embedded operating systems.
Strong knowledge of networking protocols, communication technologies, and secure communications.
Hands-on experience with vulnerability research, fuzzing, exploit development, and security testing.
Experience with automotive cybersecurity, connected vehicle technologies, or embedded security is highly desirable.
Strong analytical and problem-solving skills with the ability to identify complex attack paths.
Ability to translate highly technical security findings into clear, actionable remediation recommendations.
Strong communication, stakeholder management, and technical leadership skills.
Ability to work effectively across multidisciplinary engineering and cybersecurity teams.
Preferred Certifications
ISO/SAE 21434 Cybersecurity Engineering Certification
TÜV Automotive Cybersecurity Certification
Automotive SPICE (ASPICE) Cybersecurity Assessor Certification – preferred
Other recognized offensive security or penetration testing certifications are an advantage.
What You’ll Bring
Strong hands-on expertise in offensive security and advanced penetration testing.
Deep understanding of automotive, embedded, and connected platform security.
Experience researching vulnerabilities and developing proof-of-concept exploits.
Strong technical leadership and the ability to influence security decisions across engineering teams.
A structured approach to threat modeling, security validation, vulnerability management, and remediation.
The ability to work collaboratively with architects, developers, cybersecurity specialists, suppliers, and external security partners.
Strong understanding of emerging cybersecurity threats and modern attack techniques.
- Locations
- Gothenburg , Sweden
About Aurora Engineering AB
Aurora Engineering AB is a Swedish engineering consultancy providing technical expertise and project support within the automotive and industrial sectors. We connect skilled engineers with innovative companies to deliver high-quality solutions in product development, design, testing, and digital engineering.