Confidential mandate

Automotive Firmware Trust-Chain Expert — Electric Mobility

Planned Hiring / New

Automotive Firmware Trust-Chain Expert mandate in Pune, India · Electric Mobility

An electric-mobility manufacturer needs an independent expert to prove firmware provenance from supplier build through vehicle update, closing trust-chain gaps across four months in Pune.

The mandate

Supplier binaries enter vehicle releases without reproducible build evidence, while OTA approvals cannot always link installed firmware to reviewed source and signing policy. The component inventory confuses package names with deployable artefacts and loses lineage when suppliers rebuild after vulnerability remediation. The bounded problem is to establish trustworthy provenance for safety-relevant firmware without replacing the vehicle platform or supplier lifecycle.

Deliverables include a component inventory, build-and-signing architecture, supplier attestation, SBOM and vulnerability flow, release evidence pack, key-rotation procedure and vehicle-verification runbook. They must distinguish source availability from build reproducibility, show where proprietary toolchains prevent hermetic execution and preserve an authorised exception path for legacy controllers.

Milestone one on 9 October 2026 closes with the gap and threat model; milestone two on 6 November delivers signed-build and supplier patterns; milestone three on 11 December concludes pilot releases on two electronic control units; final acceptance on 15 January 2027 requires training and transition. Supplier-quality and safety representatives attend every milestone decision.

The CTO, product safety lead and supplier-quality director will accept delivery when sampled binaries reproduce or carry a documented controlled-build exception, signatures chain to approved keys, rollback works on vehicles, vulnerable components route to decisions and client engineers repeat the release unaided. A deliberately revoked supplier key and corrupted package must fail at the expected gates without stranding the test vehicle.

The client provides repositories, build systems, signing infrastructure, supplier contracts, ECUs and proving-ground access, with owners resolving supplier and safety questions within two working days. The consultant cannot approve road release, alter safety requirements or hold production signing keys and will use segregated test material for every ceremony.

Why this is external work

Internal teams own fragments of the chain and have normalised manual trust between them. Supplier relationships make independent challenge difficult. External expertise provides an end-to-end acceptance test without becoming permanent release capacity.

What you will own

  • Map source, dependency, compiler, build, signature, package, campaign and vehicle-install provenance for each pilot controller, retaining identifiers that survive supplier rebuilds.
  • Define hermetic or controlled build evidence appropriate to embedded supplier constraints.
  • Specify supplier attestations, SBOM quality gates and vulnerability-response obligations with named evidence, notification clocks and rejected-delivery consequences.
  • Redesign signing ceremonies, key custody, rotation and emergency revocation.
  • Pilot verified boot, update, rollback and installed-version proof on two controllers.
  • Test compromised dependency and leaked-signing-key scenarios through the release chain.
  • Transfer technical patterns, test fixtures, evidence packs and exception governance through two releases operated by client engineers.

Candidate qualifications

  • Led automotive embedded-software or firmware supply-chain assurance through homologated or production vehicle release.
  • Can evidence reproducible or tightly controlled builds across supplier-delivered binaries, proprietary toolchains and emergency remediation releases.
  • Designed code-signing and key-management controls for safety-relevant devices, including rotation, revocation, recovery and manufacturing provisioning.
  • Operationalised SBOM, reachability and vulnerability decisions for controllers with constrained updateability and long field lives.
  • Tested secure OTA, rollback and installed-version attestation on physical vehicles.
  • Delivered traceable artefacts accepted by product safety, embedded engineering, manufacturing release and supplier-quality leaders.

Non-negotiables

  • Available for Pune and Bengaluru delivery across all sixteen weeks.
  • Independent of incumbent ECU, build-platform and signing vendors.
  • Will never retain production signing material.
  • Has director or principal-level automotive product-security authority.
  1. 49 words maximum. Which artefact proves a supplier binary came from the reviewed source?
  2. 49 words maximum. Describe a signing-key failure mode you exercised on an embedded product.
  3. 49 words maximum. What vehicle-level test would make you reject an otherwise valid OTA package?

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.