Your Car Can Be Hacked — And the Engineers Who Stop That Are in Short Supply
Table of Contents

Your Car Can Be Hacked — And the Engineers Who Stop That Are in Short Supply

Connected cars have over 100 million lines of code and dozens of attack surfaces. Automotive cybersecurity engineers are among the most urgently needed professionals in tech — and the career path starts earlier than you think.

In 2015, two cybersecurity researchers remotely killed the engine of a Jeep Cherokee doing 70 mph on a St. Louis highway. The driver had agreed to the demonstration, but the vulnerability was real — and so was the recall of 1.4 million vehicles that followed. A modern connected car has 100–150 million lines of code, communicates with dozens of external networks, and has dozens of attack surfaces a malicious actor could exploit. The automotive industry realized around 2017 that it had a massive security problem. It still doesn’t have enough people to fix it.

The Car Is Now a Computer on Wheels — With Consequences

Most parents think of cybersecurity as a concern for banks, hospitals, and social media accounts. The mental model hasn’t caught up to the physical reality: your car is running more software than most enterprise systems, and it’s connected to the internet.

Modern vehicles have multiple electronic control units (ECUs) — often 70 to 100 or more — each running software that controls everything from braking to entertainment. The infotainment system connects to your phone. The telematics system connects to the manufacturer’s cloud. Advanced Driver Assistance Systems (ADAS) receive over-the-air (OTA) software updates. Some vehicles communicate with roadside infrastructure, fleet management systems, and third-party apps.

Every connection is a potential entry point.

The 2015 Jeep hack demonstrated that researchers could access the vehicle through the cellular connection to the infotainment system and pivot from there to the CAN bus — the internal communication network that connects a vehicle’s ECUs. From the CAN bus, they could send commands to the braking system, transmission, and steering. The patch Chrysler issued couldn’t be delivered OTA — it required a USB update mailed to owners. The industry has improved since then. The attack surface has grown faster than the improvements.

In 2022, security researcher Sam Curry discovered a series of vulnerabilities across 16 major automakers — including BMW, Mercedes-Benz, Ferrari, Porsche, and others — that allowed him to remotely track vehicle locations, unlock cars, start engines, and access personal information on owners. These weren’t obscure manufacturers; they were the most sophisticated vehicle brands in the world.

What Automotive Cybersecurity Engineers Actually Do

The field sits at the intersection of traditional cybersecurity, embedded systems engineering, and automotive engineering. It’s genuinely interdisciplinary, which is both what makes it hard to staff and what makes it intellectually rewarding.

Threat analysis and risk assessment (TARA) engineers systematically model how a vehicle system could be attacked — identifying assets worth protecting, threat actors, attack vectors, and the potential impact of compromise. This is strategic security work that informs design decisions early in the vehicle development cycle.

Embedded security engineers harden the ECUs themselves. This means secure boot processes, cryptographic authentication between ECUs on the CAN bus, intrusion detection at the firmware level, and ensuring that an attacker who penetrates one ECU can’t immediately access all others. This is low-level work — often in C and assembly — that requires understanding both security principles and the constraints of resource-limited embedded hardware.

Penetration testers (automotive) are the ethical hackers of the field. They attempt to break vehicle systems before malicious actors do, using specialized tools, fuzzing techniques, and the kind of creative adversarial thinking that characterizes offensive security work generally. Automotive pen testing has its own toolchain — hardware interfaces like the CANtact, specialized protocol analyzers, JTAG debuggers for ECU firmware extraction.

OTA security engineers protect the update pipeline. As vehicles move toward software-defined architectures where major functionality can be updated wirelessly, securing that pipeline becomes critical. A compromised OTA system is catastrophic — an attacker who can push malicious updates to a vehicle fleet can effectively own every car from that manufacturer at once.

Compliance and standards engineers navigate a growing regulatory landscape. The UN’s WP.29 regulation (effective 2022) mandates cybersecurity management systems for vehicles sold in the EU, Japan, and South Korea. ISO/SAE 21434 is the technical standard that defines automotive cybersecurity engineering requirements. Someone needs to implement these frameworks — and translate them into concrete engineering practices.

The Research and Industry Landscape

Upstream Security’s Global Automotive Cybersecurity Report 2024 found that automotive cyber incidents increased by 50% year-over-year, with a significant proportion targeting EV charging infrastructure and connected services APIs. The average cost of a major automotive cyber incident now exceeds $100 million when accounting for recalls, legal exposure, and reputational damage.

The Ponemon Institute’s automotive cybersecurity surveys consistently find that the industry lacks the talent to meet current demand. Most automotive OEMs have cybersecurity teams of 10–30 people to cover vehicles that have millions of lines of code and hundreds of interconnected systems. Tier 1 suppliers — companies like Bosch, Continental, and Aptiv that supply ECUs and systems to automakers — have their own cybersecurity requirements and their own staffing gaps.

McKinsey’s 2023 automotive cybersecurity report estimated that the industry will spend $9.7 billion annually on vehicle cybersecurity by 2030, up from approximately $4.9 billion in 2023. That spending buys tools, but primarily, it buys talent.

Salary data reflects the scarcity. Automotive cybersecurity engineers earn notably more than equivalent-experience cybersecurity professionals in other verticals:

RoleEntry LevelMid-CareerSenior
Automotive Security Analyst$85K–$105K$130K–$165K$180K–$220K
Embedded Security Engineer$95K–$120K$145K–$185K$195K–$240K
Automotive Penetration Tester$90K–$115K$140K–$175K$185K–$230K
OTA Security Architect$110K–$135K$160K–$200K$210K–$260K
TARA / Standards Engineer$88K–$110K$135K–$170K$180K–$220K

Sources: Glassdoor, LinkedIn Salary, ISC2, automotive industry surveys 2024–2025

The field is also geographically distributed differently from general tech. While San Francisco and Seattle dominate software engineering jobs, automotive cybersecurity roles are concentrated in Detroit, Munich, Stuttgart, Tokyo, and increasingly in Austin and Atlanta as automakers and suppliers build out American R&D presence.

What This Means for Your Kid

The honest starting point: cybersecurity interest at any age is a good signal. A kid who enjoys CTF (capture-the-flag) competitions, who tinkered with network analysis tools, who got curious about how software vulnerabilities work — that curiosity maps directly onto what automotive cybersecurity rewards.

But the automotive side adds a layer that general cybersecurity doesn’t require: comfort with physical systems and embedded hardware. The connection between software and the physical world — understanding that a CAN message doesn’t just change a value on a screen, it moves a physical actuator — is something that’s built through hands-on experience, not just coding practice. This is exactly the intuition that comes from projects like Arduino-based motor control, building simple communication protocols between microcontrollers, or working with hardware interfaces.

There’s genuine crossover here with broader trends in AI-driven autonomous vehicles — the security of autonomous systems is even more critical than that of conventional connected cars, because the attack surface is larger and the consequences of compromise are more severe.

For parents thinking about educational pathways:

  • Ages 10–13: Introduction to networking concepts, basic programming (Python), and if possible, some electronics basics. CTF competitions designed for kids (picoCTF, for example) are excellent for building adversarial thinking without any specialized hardware
  • Ages 14–17: Formal cybersecurity coursework, networking fundamentals (CompTIA Network+ is accessible), and increasingly, embedded systems exposure — Arduino, Raspberry Pi projects that involve communication protocols
  • Ages 17–22: Computer science or computer engineering degree programs, with electives in cybersecurity, embedded systems, and if available, automotive or transportation systems. SANS Institute certifications in security are respected in industry

The cybersecurity career path is one of the few in technology where demonstrated skills via CTF competitions, bug bounty programs, and personal projects carry almost as much weight as formal credentials. A high school student who can demonstrate they’ve found a real vulnerability — documented and responsibly disclosed — is already competitive for internship positions.

What to Watch Over the Next 3 Months

  • News about vehicle recalls with cybersecurity components. They’re happening more frequently, and each one is a real-world case study in what’s at stake
  • OTA update announcements from automakers. Tesla pioneered this; now every major brand does it. When an automaker pushes a significant OTA update, ask your kid: how do you think they make sure only the real update can be installed?
  • Bug bounty program expansions. Companies like Tesla and GM have public bug bounty programs that invite researchers to find vulnerabilities. Some of these programs accept submissions from researchers of any age
  • ISO/SAE 21434 compliance deadlines. International regulatory pressure is forcing every automaker to build security into new vehicle development. This isn’t a trend — it’s now mandatory, which means the hiring is mandatory too

Pay attention to whether your kid shows more interest in “how does this work” or “how could this break.” Both are valuable orientations. The second is what security engineers live in every day.

FAQ

Does automotive cybersecurity require a car-specific degree? No. Most automotive cybersecurity engineers come from computer science, electrical engineering, or general cybersecurity backgrounds and specialize on the job or through targeted training. Some universities (Auburn, Clemson) have developed automotive-specific programs, but they’re the exception rather than the rule.

Is ethical hacking legal for teenagers? Bug bounty programs and CTF competitions are specifically designed for legal, structured security research. Major platforms like HackerOne and Bugcrowd have programs open to minors with parental consent. The key distinction is always: authorized testing only, on systems explicitly offered for testing.

How does this relate to self-driving cars? Intimately. Autonomous vehicles have larger attack surfaces and more severe consequences of compromise. The security principles are the same, but the stakes are higher. Cybersecurity skills built in the automotive context transfer directly to autonomous systems.

Are cybersecurity jobs at risk from AI? AI is creating new attack vectors at the same time it’s automating some defense tasks. Net demand for cybersecurity professionals has increased alongside AI adoption, not decreased. Automotive cybersecurity specifically requires physical-world expertise that AI tools currently can’t replicate.

What programming languages matter most? C and C++ for embedded security work. Python for security tooling, scripting, and automation. Some Rust for newer secure systems development. Knowledge of CAN bus protocols and automotive-specific communication standards (UDS, DoIP) is specialized but valuable.

Where do automotive cybersecurity engineers work? Traditional automakers (Ford, GM, Toyota, Stellantis), EV companies (Tesla, Rivian, Lucid), Tier 1 suppliers (Bosch, Continental, Aptiv), specialized cybersecurity firms (Argus, Upstream, GuardKnox), and government agencies involved in transportation security.


About the author Ricky Flores is the founder of HiWave Makers and an electrical engineer with 15+ years of experience building consumer technology at Apple, Samsung, and Texas Instruments. He writes about how kids learn to build, think, and create in a tech-saturated world. Read more at hiwavemakers.com.


Sources

  1. Greenberg, Andy. “Hackers Remotely Kill a Jeep on the Highway.” Wired, July 2015. https://www.wired.com/2015/07/hackers-remotely-kill-jeep-highway/
  2. Curry, Sam. “Web Hackers vs. The Auto Industry.” samcurry.net, 2022. https://samcurry.net/web-hackers-vs-the-auto-industry
  3. Upstream Security. Global Automotive Cybersecurity Report 2024. https://upstream.auto/reports/
  4. McKinsey & Company. Cybersecurity in Automotive. (2023) https://www.mckinsey.com/industries/automotive-and-assembly/our-insights
  5. ISO/SAE 21434:2021 Road Vehicles — Cybersecurity Engineering. https://www.iso.org/standard/70918.html
  6. UNECE WP.29 Regulation No. 155 on Cybersecurity. https://unece.org/transport/vehicle-regulations/working-party-automated-connected-vehicles
  7. Ponemon Institute. Securing the Connected Car. https://www.ponemon.org
Ricky Flores
Written by Ricky Flores

Founder of HiWave Makers and electrical engineer with 15+ years working on projects with Apple, Samsung, Texas Instruments, and other Fortune 500 companies. He writes about how kids learn to build, think, and create in a tech-driven world.