Sopra Steria Logo

Sopra Steria

Embedded Product Cybersecurity Expert / ISO 21434, IEC 62443

Posted 11 Days Ago
Be an Early Applicant
In-Office
Montréal, QC, CAN
Mid level
In-Office
Montréal, QC, CAN
Mid level
As a Cybersecurity Engineer, you'll assess vehicle systems for risks, derive cybersecurity goals, collaborate with engineering, and ensure compliance with automotive standards.
The summary above was generated by AI
Company Description

CS Group Canada, a subsidiary of CS Group (part of the Sopra Steria Group), is a leader in the development and certification of safety-critical systems in the aerospace, electric, and autonomous driving industries.

Joining CS Group Canada means taking part in complex, high-tech projects for some of the most prestigious system manufacturers in North America, while benefiting from competitive salaries, comprehensive benefits, and flexible work arrangements.

Job Description

As a Cybersecurity Engineer – Embedded Products, you will play a central role in ensuring the security and compliance of our customers’ vehicle systems and ECU architectures. Your responsibilities include:

  • Perform a comprehensive risk assessment of the current system architecture and identify item-level functions by applying the TARA process via recognized methods (e.g., ISO/SAE 21434 TARA, STRIDE, or similar).
  • Build and review item definitions, identify critical assets, potential attack vectors, threat scenarios, and evaluate associated risks at both ECU and vehicle levels.
  • Derive Cybersecurity Goals and Cybersecurity Requirements (hardware, firmware, and system-level design) from the TARA results and ensure traceability throughout the product development lifecycle.
  • Contribute to the Cybersecurity Concept (CSC) and ensure alignment with ISO/SAE 21434 and regulatory requirements.
  • Collaborate with system, software, and hardware engineering teams to integrate recommended security measures (cryptography, secure boot, secure communication, key management, hardware root of trust, debug protections, memory protection, key storage and secure update mechanisms).
  • Evaluate protocols usage and propose cybersecurity countermeasures such as authentication, encryption, replay protection, secure pairing, and robust key management.
  • Support validation activities for cybersecurity controls and participate in audits, reviews, and documentation of findings.
  • Support compliance and customer requirements aligned with standards and frameworks (as applicable): CRA, ISO/SAE 21434, RED-DA, IEC 62443, NIST, etc.

Qualifications

  • Bachelor’s or Master’s degree in Software, Electrical, Computer, or Automotive Engineering or a related field.
  • 3–10 years of experience in automotive cybersecurity or embedded systems cybersecurity, with hands-on experience on TARA based on ISO/SAE 21434 processes.
  • Solid foundation in embedded systems architecture, including deep understanding of MCU/SoC design constraints, real-time and Linux-based environments.
  • Proficient with boot architectures and low-level debugging using interfaces such as JTAG, XCP and SWD.
  • Solid understanding of communication protocols (CAN, CAN-FD, Automotive Ethernet, SOME/IP, UDS, UART, SPI, BT, Wi-Fi, USB, NFC, cellular, RF, etc.), and embedded security mechanisms (cryptography, secure boot, secure communication, key management, hardware root of trust, debug protections, memory protection, key storage and secure update mechanisms).
  • Proven ability to define Cybersecurity Goals and claims, derive Requirements, and ensure traceability through the development lifecycle.
  • Excellent analytical, problem-solving, and documentation skills.
  • Ability to work collaboratively with multi-disciplinary, multi-site engineering teams.

Preferred / Asset Qualifications:

  • Experience with embedded systems, or safety-critical ECUs.
  • Hands-on experience in cybersecurity validation and testing (fuzzing, robustness testing, penetration testing).
  • Knowledge of Cybersecurity Case preparation and internal/external audit processes.
  • Familiarity with regulatory requirements such as UNECE R155/R156, CRA and standards such as ISO 21434, IEC 62443.
  • Exposure to hardware security modules (TPM, Secure Element, HSM), TrustZone, MPU/MMU
  • Understanding of Software Bill of Material (SBOM), product security incident response (PSIRT) processes and vulnerability monitoring and management (CVE/CWE/CVSS).

Additional Information

Please note that only selected candidates and Permanent Residents/Canadian Citizens will be contacted.

Job Types: Full-time, Permanent

CS Group Canada values ​​diversity in the workplace and encourages women, visible minorities, ethnic minorities, aboriginal people, and people with disabilities to apply.

Benefits:

  • Hybrid Work 
  • Industry leading medical, dental, and vision Insurance
  • Access to a telemedicine service
  • RRSP program
  • Personal and sick days
  • Recreation room with pool table and foosball table

All your information will be kept confidential according to EEO guidelines.

Sopra Steria Montréal, Québec, CAN Office

2001 Boulevard Robert Bourassa, Suite 1700, Montréal, Quebec, Canada

Similar Jobs

18 Minutes Ago
Remote or Hybrid
CA
Expert/Leader
Expert/Leader
Blockchain • Fintech • Mobile • Payments • Software • Financial Services
Senior individual contributor building and maintaining underwriting and credit decisioning ML systems for Cash App Borrow and Afterpay. Responsibilities include feature engineering, model training, calibration, experimentation, deployment, monitoring, and portfolio-level analysis. Collaborate with cross-functional teams to align models with business and regulatory goals and develop AI-native engineering workflows and governance for reliable, auditable model development.
Top Skills: AirflowAWSClaude CodeCopilotCursorGCPGitInternal Feature StoreLightgbmMlflowModel Hosting PlatformNumpyPandasPrefectPythonPyTorchScikit-LearnSnowflakeSQLXgboost
6 Hours Ago
Hybrid
Montréal, QC, CAN
Expert/Leader
Expert/Leader
Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Lead the legacy modernization team as a Mainframe Database Administrator managing Supra databases, including installation, performance tuning, backup, and security management.
Top Skills: CicsCobolIbm Z/OsJcl
10 Hours Ago
In-Office
Montréal, QC, CAN
Internship
Internship
Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
The Software Developer Intern will work on the EVCN project, focusing on end-to-end testing, automation using Playwright, and bug fixing within an Agile team.
Top Skills: Playwright

What you need to know about the Montreal Tech Scene

With roots dating back to 1642, Montreal is often recognized for its French-inspired architecture and cobblestone streets lined with traditional shops and cafés. But what truly sets the city apart is how it blends its rich tradition with a modern edge, reflected in its evolving skyline and fast-growing tech industry. According to economic promotion agency Montréal International, the city ranks among the top in North America to invest in artificial intelligence, making it le spot idéal for job seekers who want the best of both worlds.

Key Facts About Montreal Tech

  • Number of Tech Workers: 255,000+ (2024, Tourisme Montréal)
  • Major Tech Employers: SAP, Google, Microsoft, Cisco
  • Key Industries: Artificial intelligence, machine learning, cybersecurity, cloud computing, web development
  • Funding Landscape: $1.47 billion in venture capital funding in 2024 (BetaKit)
  • Notable Investors: CIBC Innovation Banking, BDC Capital, Investissement Québec, Fonds de solidarité FTQ
  • Research Centers and Universities: McGill University, Université de Montréal, Concordia University, Mila Quebec, ÉTS Montréal

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account