← Back to jobs

Lead Software Architect – Offensive Security & Penetration Testing

  • On-site
  • Sweden
  • English
  • Posted 01.09.26 03:22

We are looking for an experienced Lead Software Architect – Offensive Security & Penetration Testing to lead cybersecurity validation across a large-scale Client.

The role will focus on defining and executing penetration testing strategies, leading internal and external security assessments, identifying vulnerabilities and attack paths, and driving remediation activities across product and engineering teams.

You will work closely with cybersecurity engineers, system architects, software development teams, suppliers, and other key stakeholders to ensure connected platforms and vehicle technologies are resilient against evolving cyber threats and meet relevant security and compliance requirements.

Key Responsibilities

Define and lead offensive security and penetration testing strategies for connected automotive platforms and services.Plan and execute advanced white-box, gray-box, and black-box penetration testing across embedded systems and connected platforms.Conduct security assessments of IHU, DHU, UXC, TCAM, Android Automotive, QNX-based platforms, vehicle communications, and connected cloud services.Perform vulnerability research, exploit development, fuzz testing, and protocol analysis.Identify vulnerabilities, attack paths, security weaknesses, and potential exploitation scenarios.Validate vulnerabilities through controlled exploitation and provide clear recommendations for remediation.Assess security across CAN, Automotive Ethernet, SOME/IP, Bluetooth, Wi-Fi, USB, and other vehicle connectivity technologies.Conduct security assessments of cloud platforms, APIs, connected services, and communication interfaces.Review secure communication mechanisms, cryptographic implementations, and security protocols.Perform threat modeling, attack path analysis, and security architecture reviews.Collaborate with product teams and development organizations to drive timely vulnerability remediation.Provide technical guidance on security controls and secure design principles.Support and contribute to Secure Software Development Lifecycle (SSDLC) activities.Ensure security validation activities align with relevant automotive cybersecurity standards and regulatory requirements.Provide technical leadership and communicate complex security findings to both technical and non-technical stakeholders.Coordinate with internal teams, external security partners, suppliers, and other stakeholders throughout security assessment activities.

Key Technical Skills

Offensive Security & Penetration Testing

Advanced penetration testing – White-box, Gray-box, and Embedded SystemsOffensive security and vulnerability researchFuzz testing and protocol analysisExploit development and vulnerability validationSecurity testing of connected and embedded platforms

Automotive & Embedded Security

Android Automotive OS (AAOS) / AOSP securityQNX security architectureEmbedded Linux securityAutomotive cybersecurityVehicle network security – CAN, Ethernet, SOME/IPBluetooth, Wi-Fi, USB, and connectivity security

Cloud & Application Security

Cloud security assessmentsAPI security testingSecure communication protocolsCryptographic protocols and implementationsThreat modeling and attack path analysis

Security Engineering & Architecture

Security validation and exploit verificationVulnerability management and risk assessmentSecurity architecture reviewsSecure Software Development Lifecycle (SSDLC)Security requirements and remediation management

Standards & Compliance

ISO/SAE 21434UNECE R155Automotive cybersecurity engineering and security validation practices

Required Qualifications

Bachelor's or Master's degree in Cybersecurity, Software Engineering, Computer Science, Electronics, or a related field, or equivalent practical experience.10+ years of experience in cybersecurity, penetration testing, offensive security, vulnerability research, or security architecture.Proven experience conducting advanced penetration testing of embedded systems, automotive platforms, or connected products.Strong understanding of Linux, Android, QNX, and embedded operating systems.Strong knowledge of networking protocols, communication technologies, and secure communications.Hands-on experience with vulnerability research, fuzzing, exploit development, and security testing.Experience with automotive cybersecurity, connected vehicle technologies, or embedded security is highly desirable.Strong analytical and problem-solving skills with the ability to identify complex attack paths.Ability to translate highly technical security findings into clear, actionable remediation recommendations.Strong communication, stakeholder management, and technical leadership skills.Ability to work effectively across multidisciplinary engineering and cybersecurity teams.

Preferred Certifications

ISO/SAE 21434 Cybersecurity Engineering CertificationTÜV Automotive Cybersecurity CertificationAutomotive SPICE (ASPICE) Cybersecurity Assessor Certification – preferredOther recognized offensive security or penetration testing certifications are an advantage.

What You’ll Bring

Strong hands-on expertise in offensive security and advanced penetration testing.Deep understanding of automotive, embedded, and connected platform security.Experience researching vulnerabilities and developing proof-of-concept exploits.Strong technical leadership and the ability to influence security decisions across engineering teams.A structured approach to threat modeling, security validation, vulnerability management, and remediation.The ability to work collaboratively with architects, developers, cybersecurity specialists, suppliers, and external security partners.Strong understanding of emerging cybersecurity threats and modern attack techniques.