Cybersecurity CSMS & Type Approval Engineer

Mahindra

Chennai
Full time
7 - 10 Yrs
Job Openings: 3

Required Skills:

Automotive Cybersecurity

CSMS

Type Approval

Responsibilities:


1. Lead security validation activities for both on-board and off-board vehicle systems, ensuring robust testing coverage across ECUs, gateways, telematics, and backend services.

2. Drive security testing at the production line level to validate cybersecurity controls during vehicle manufacturing and delivery stages.

3. Manage supplier security audits and ensure timely closure of findings through collaborative action planning and follow-ups.

4. Support Vehicle Security Operations Center (VSOC) activities including incident detection, triage, and response coordination.

5. Lead digital vehicle forensics investigations in case of cybersecurity incidents, ensuring evidence collection, analysis, and reporting.

6. Contribute to cybersecurity type approval documentation and validation activities in alignment with UNECE R155 and AIS 189 requirements


Key Deliverables:


1. Security test plans, execution reports, and validation summaries for vehicle systems and interfaces.

2. Closure reports for supplier audit findings and production line security assessments.

3. Incident response documentation including forensic analysis and mitigation actions.

4. Support documentation for type approval submissions including validation evidence and compliance matrices.

5. Continuous improvement inputs to enhance security validation processes and tooling.
Experience

7-10 years of experience in automotive cybersecurity testing, validation, or incident response.
Hands-on experience with penetration testing, vulnerability scanning, and secure system validation.
Exposure to VSOC operations, digital forensics, and supplier security audits.
Familiarity with UNECE WP.29 R155, AIS 189, and ISO/SAE 21434 standards.

Qualification
Bachelor’s or Master’s degree in Automotive Electronics, Computer Science, Cybersecurity, or a related field.Certifications in ethical hacking, penetration testing, or incident response (e.g., CEH, OSCP, GCIH) are desirable.

About Company

Mahindra
Learn more about the company