Building an automotive cybersecurity career in India
The roles, the skills, and the routes in — for engineers moving into vehicle security
A field that is hiring before it is crowded
Automotive cybersecurity in India is at an unusual point: the demand is arriving faster than the trained supply. India's CSMS standard, AIS-189, is aligned to UN R155, and its software-update counterpart AIS-190 to UN R156; enforcement is proposed in MoRTH's June 2026 draft (G.S.R. 503(E)) but not yet finalised, and OEMs and Tier-1s are already building the capability those standards will require. Someone has to run the threat analyses, the penetration tests, the monitoring and the compliance evidence. Right now there are more roles than people who can fill them well. For an engineer weighing a move, that is a rare position to enter a specialism.
This piece maps the roles, the skills each needs, and the practical routes in for someone in India today.
The roles, and what each actually does
"Automotive cybersecurity" is not one job. It spans hands-on hardware work, process-heavy compliance work, and operational monitoring. The main roles, and the skills that dominate each:
| Role | What the work is | Skills that dominate |
|---|---|---|
| Security engineer | Design secure architecture and controls into the vehicle | Embedded, cryptography, ISO/SAE 21434 concept phase |
| TARA analyst | Run threat analysis and risk assessment; derive cybersecurity goals | ISO/SAE 21434 clause 15 method, systems thinking |
| Penetration tester | Attack ECUs and interfaces on benches; produce evidence | CAN/UDS, firmware, hardware, exploitation |
| VSOC analyst | Monitor the fleet and back end for attacks after approval | Detection, telematics data, incident response |
| Compliance lead | Own the CSMS/SUMS and carry it to assessment | UN R155/R156, AIS-189/190, evidence and audit |
The two ends of that table — pentester and compliance lead — look like different professions, and to a degree they are. But the field rewards people who understand both, because a good penetration test only matters if its findings become type-approval evidence, and a good compliance case only holds if it rests on real technical work.
The skills, layer by layer
Think of the skill set as three layers stacked on a base you may already have.
The base is what most entrants bring from elsewhere: embedded software, IT security, or automotive systems engineering. None of that is wasted.
The in-vehicle layer is the one that makes you specifically an automotive security person. It is the in-vehicle network — CAN and CAN-FD — and diagnostics over UDS. The CAN protocol has no built-in authentication, which is why so many vehicle attacks start there; the mechanics are in CAN bus attacks explained. This layer is best learned with your hands on real hardware, not from slides.
The process layer is the engineering and regulatory framework: the ISO/SAE 21434 lifecycle and its threat-analysis method, and the requirements of UN R155 and UN R156. The TARA in particular — asset, threat scenario, impact, attack path, feasibility, risk, treatment — is the method at the centre of the standard and worth learning early; see TARA, step by step. Even a hardware-focused pentester is more valuable for understanding how findings feed the process layer.
The cryptographic layer cuts across the others: PKI and key management underpin secure updates, V2X and EV charging, and a security engineer who understands them can work across all three surfaces.
The routes in
There is no single door. The practical routes, roughly in order of hands-on intensity:
- Learn the in-vehicle network for real. Get access to CAN tooling and an ECU bench and practise capturing, injecting and fuzzing traffic, and driving UDS diagnostics. This is the fastest way to become credible.
- Do structured penetration testing. Understanding how a vehicle pentest is scoped, run against representative benches, and reported turns curiosity into a marketable skill — the shape of that work is in penetration testing a vehicle.
- Engage the community. Car hacking villages and capture-the-flag events are where hands-on skill is built and demonstrated, and they are a hiring pool in their own right; India's own community is still forming, which is an opportunity as much as a gap.
- Certify in the framework. Certifications that build genuine competence in the regulatory and engineering framework matter, because AIS-189 and UN R155 assessments turn on demonstrated capability. In India, the CSIP (Certified SUMS Implementation Professional) certification, co-built by AutoSifu and CIRT (Pune), targets the software-update-management side.
Why the Indian context makes this a good time
Two structural facts favour someone entering now. First, the standards are aligned to the international regime — an engineer who learns UN R155, UN R156 and ISO/SAE 21434 in an Indian context is building skills that also travel to UNECE and EU markets, which matters for OEMs exporting from India. Second, competence is being taken seriously on the assessor side too: being named in Rule 126 of the CMVR as a test agency does not by itself confer cybersecurity scope, because AIS-189 clause 5.3.1 requires the assessing agency to hold automotive cybersecurity and risk-assessment competence of its own. Competence is the currency of the whole regime, on both sides of the table — and competence is exactly what a career is built on.
India's first SUMS workshop, co-built by AutoSifu and CIRT and run at CIRT Pune in November 2025, and the CSIP certification that came with it, exist precisely because the country needs to build this depth locally rather than import it. For an engineer, initiatives like these are both a way in and a signal of where the demand is heading.
The practical takeaway
Pick an end of the table to start from — hardware or process — and build the layer above your existing base deliberately: in-vehicle network first, then the ISO/SAE 21434 and R155/R156 framework, with cryptography threaded through. Get your hands on real ECUs early, engage the community, and certify in the framework rather than collecting generic badges. The field is hiring ahead of supply; the people who build genuine, demonstrable competence now will be the ones OEMs and assessors are short of.
The AutoSifu view
AutoSifu builds capability the same way it delivers compliance — as one route, not a training aside. Working CSMS and SUMS to assessment, secure solutioning, and CoC/VTA support under R155/R156 and AIS-189/AIS-190, with our strategic partner CIRT, the approval body, in the room, means the people we train and hire learn on real programmes against real evidence. That is also why we co-built India's first SUMS workshop and the CSIP certification: the competence the regime demands has to be grown, not assumed.
Questions
- How do I start a career in automotive cybersecurity in India?
- Start from where you already are: embedded engineers, IT security professionals and automotive test engineers all have transferable ground. Build the vehicle-specific layer — CAN and UDS, ISO/SAE 21434 and UN R155, and hands-on work on ECU benches — through workshops, certifications and capture-the-flag events. In India, industry initiatives such as the CIRT × AutoSifu SUMS workshop and the CSIP certification are concrete routes to build the compliance-and-software-update side of that layer.
- What skills does automotive security need?
- The core technical skills are the in-vehicle network stack (CAN and CAN-FD, UDS diagnostics), embedded systems and firmware, and cryptography and PKI for updates and V2X. On top sits the process layer: threat analysis and risk assessment (TARA) under ISO/SAE 21434 and the requirements of UN R155 and UN R156. Which skills matter most depends on the role — a penetration tester leans hardware, a compliance lead leans process.
- What certifications help?
- Certifications that build genuine competence in the regulatory and engineering framework are the most useful, because AIS-189 and UN R155 assessments turn on demonstrated capability, not badges alone. In India, the CSIP (Certified SUMS Implementation Professional) certification, co-built by AutoSifu and CIRT, targets the software-update-management side of the work. Broader value comes from hands-on skill in ISO/SAE 21434 methods, CAN and UDS, and practical penetration testing.
