Secure Automotive Architect
Design zonal and domain architectures with defence in depth built in from the start.
- Duration
- 8 weeks
- Delivery format
- Hybrid
- Certification
- AutoSec Security Architect
Overview
What This Program Is For
Architecture is where security is either designed in or permanently compromised. This program covers the patterns that make a vehicle defensible by construction — segregation, gateway policy, secure onboard communication and OTA paths — and the review discipline that keeps them intact through a programme.
Architect vehicles that are defensible by construction. Covers network segregation, gateway policy, secure onboard communication, OTA design and architecture-level security review.
Who should attend
- E/E and software architects owning vehicle-level design
- Senior engineers moving into architecture roles
- Security engineers reviewing architecture on behalf of an OEM
- Technical leads responsible for OTA update design
Prerequisites
- TARA Specialist or equivalent
- E/E architecture experience
Curriculum
4 Modules Across 8 weeks
Every module is assessed. Durations are indicative for open cohorts and are compressed or extended for corporate delivery.
Zonal and domain architecture patterns
2 weeksGateway policy and network segregation
2 weeksSecure onboard communication
2 weeksOTA architecture and R156
2 weeks
Learning outcomes
What You Take Back to Your Programme
Capability you can demonstrate, not topics you have been exposed to.
What you will be able to do
- Design segregated zonal and domain architectures
- Specify gateway and firewall policy for vehicle networks
- Architect secure OTA update paths to R156
- Lead architecture-level security reviews
Career outcomes
- Security Architect
- E/E Architect
- Technical Lead
Capability levels
- Secure Developer
Tools and skills
- Architecture modelling toolchain
- Gateway policy specification templates
- SecOC configuration workbench
- OTA campaign design patterns
Labs included
Hands-On Time on Real Hardware
Lab access is included with this program, and the exercises below are assessed rather than optional.
- Included lab2 assessed exercises
AutoSec TARA Lab
Model threats against real vehicle architectures
Objectives
- Define items and assets from a real vehicle architecture
- Derive attack paths and rate feasibility
- Produce cybersecurity goals and requirements
Practical exercises
- Central gateway TARAintermediate4 hours
Full assessment of a domain gateway including diagnostic and OTA interfaces.
- Telematics unit attack pathsadvanced3 hours
Derive and rate attack paths across cellular, Bluetooth and Wi-Fi interfaces.
- Included lab2 assessed exercises
AutoSec Secure Development Lab
Harden ECU software on real hardware
Objectives
- Implement secure boot on an automotive microcontroller
- Integrate an HSM-backed key hierarchy
- Apply SecOC to a CAN communication matrix
Practical exercises
- Secure boot chain of trustadvanced5 hours
Build and verify a signed bootloader with rollback protection.
- SecOC on a CAN busadvanced4 hours
Add authentication and freshness to safety-relevant CAN frames.
Certification mapping
Where This Sits in the Framework
How the program maps to the AutoSec Automotive Cybersecurity Capability Framework™ and the certification ladder.
Capability Framework
Secure Developer
Build secure ECU software, crypto stack integration, SecOC, Secure Boot and HSM skills.
- Secure ECU development lifecycle
- Automotive crypto stack
- Secure Boot, HSM, SecOC and Secure Flash
- Hardware security features of automotive microcontrollers
Certification
AutoSec Certified Professional
Confirms hands-on capability to design and build secure vehicle systems — architecture segregation, secure boot, HSM-backed key handling and SecOC.
Exam preparation
- Format
- hybrid
- Duration
- 3 hours
- Passing score
- 75%
- Valid for
- 3 years
- Hold the Practitioner certification
- Complete Secure ECU Developer or Secure Automotive Architect
- Pass a supervised practical assessment on lab hardware
Common questions
Secure Automotive Architect FAQ
What candidates and their managers ask before enrolling.
- Is this program design-only, or is there implementation work?
- It is design-led with implementation context. You will configure SecOC and reason about secure boot on lab hardware, but the assessed output is architectural — segregation decisions, gateway policy and an OTA design that satisfies UNECE R156.
- Do I need TARA Specialist first?
- Strongly recommended rather than mandatory. Architecture decisions in this program are justified against rated attack paths, and candidates without TARA experience spend the first week catching up on the risk vocabulary.
- Does it cover zonal architectures specifically?
- Yes. Zonal and domain patterns are treated side by side, including where zonal consolidation weakens the segregation assumptions that domain architectures relied on.
Ready to Start AutoSec Security Architect?
Enrol as an individual, or talk to us about running this program for your engineering team.