Posted 12 August, 2026
Lead Engineer- Software and Cyber Security
Mahindra Finance
Chennai,Bang,IN
Full Time
Reference: 118_401312_1395025600
Responsibilities & Key Deliverables
1. Key Tasks and Deliverables
- Lead endtoend cybersecurity engineering for safetycritical powertrain ECUs (Engine ECU, VCU, MCU, BMS, HCU, OCDC) across ICE, Hybrid, and Electric platforms.
- Act as Cybersecurity Technical Owner for assigned powertrain programs, accountable for design robustness, compliance, and SOP readiness.
- Define, review, and approve secure ECU architectures, including secure boot, secure flashing, secure communication, OTA/FOTA security, HSM integration, and key lifecycle management.
- Perform and lead Threat Analysis and Risk Assessment (TARA) in compliance with ISO/SAE 21434, ensuring traceability to cybersecurity goals and mitigations.
- Translate cybersecurity threats into clear system and software security requirements aligned with vehicle and powertrain performance goals.
- Ensure crossfunctional execution by coordinating cybersecurity activities with system, software, hardware, validation, vehicle integration, and supplier teams.
- Lead cybersecurity design and compliance reviews with internal stakeholders, vehicle programs, and Tier1 suppliers.
- Oversee vulnerability management, incident response, and postSOP cybersecurity monitoring for powertrain ECUs.
- Define and execute penetration testing, fuzz testing, and robustness validation to close vulnerabilities during development and validation phases.
2. Critical MustHave Deliverables
- ISO/SAE 21434compliant cybersecurity lifecycle execution for powertrain ECUs.
- UNECE R155 / R156 (AIS 189 / AIS 190) evidence readiness supporting vehicle type approval.
- Cybersecure ECU architectures protecting torque, propulsion, charging, and energy management functions.
- Demonstrated alignment between cybersecurity and functional safety (ISO 26262) without system tradeoffs.
- Zero critical cybersecurity nonconformities at SOP and regulatory audits.
3. GoodtoHave Deliverables
- Experience supporting global OEM vehicle cybersecurity audits and homologation activities.
- Contribution to cybersecurity strategy definition for nextgeneration powertrain platforms.
- Automation of vulnerability scanning, penetration testing, or compliance reporting.
- Exposure to EVspecific cybersecurity challenges (BMS, charging interfaces, energy management systems).
Experience
- 10-12+ years of experience in automotive embedded systems or powertrain ECU development.
- 3-6+ years of handson automotive cybersecurity engineering experience, preferably in OEM or Tier1 environments.
- Proven experience leading multiECU cybersecurity implementations across full Vcycle.
Industry Preferred
- Automotive OEMs
- Tier1 Automotive Suppliers (Powertrain / EV Systems / Embedded Platforms)
- Automotive cybersecurity or embedded systems engineering organizations
Qualifications
Bachelor's or Master's degree in Electronics, Embedded Systems, Automotive Engineering, Computer Science, or Cyber Security.
Formal training or certification in automotive cybersecurity standards (ISO/SAE 21434, UNECE R155/R156) is highly desirable.
General Requirements
Competencies and Skills
Functional Competencies
- Powertrain control systems and realtime embedded software architectures.
- ECUlevel cybersecurity controls: secure boot, HSM, secure diagnostics, secure flashing.
- Automotive communication protocols: CAN, CANFD, Automotive Ethernet, UDS.
- Threat modeling, vulnerability analysis, and cybersecurity risk mitigation.
- OTA/FOTA security and backend interaction models.
Tools and Techniques Used
- Threat modeling frameworks aligned to ISO/SAE 21434.
- Penetration testing and fuzz testing tools for embedded ECUs.
- Cryptographic key management, PKI, and certificate handling tools.
Behavioral Competencies
- Strong technical leadership and ownership mindset in safetycritical systems.
- Riskbased decision making under regulatory and program constraints.
- Clear, confident crossfunctional communication with engineering, vehicle teams, and suppliers.
- Mentorship capability to guide and review work of cybersecurity engineers.