Skip to main content
Advanced
Level 3 · Secure Developer

Secure Automotive Architect

Design zonal and domain architectures with defence in depth built in from the start.

Duration
8 weeks
Delivery format
Hybrid
Certification
AutoSec Security Architect

Overview

What This Program Is For

Architecture is where security is either designed in or permanently compromised. This program covers the patterns that make a vehicle defensible by construction — segregation, gateway policy, secure onboard communication and OTA paths — and the review discipline that keeps them intact through a programme.

Architect vehicles that are defensible by construction. Covers network segregation, gateway policy, secure onboard communication, OTA design and architecture-level security review.

Who should attend

  • E/E and software architects owning vehicle-level design
  • Senior engineers moving into architecture roles
  • Security engineers reviewing architecture on behalf of an OEM
  • Technical leads responsible for OTA update design

Prerequisites

  • TARA Specialist or equivalent
  • E/E architecture experience

Curriculum

4 Modules Across 8 weeks

Every module is assessed. Durations are indicative for open cohorts and are compressed or extended for corporate delivery.

  1. Zonal and domain architecture patterns

    2 weeks
  2. Gateway policy and network segregation

    2 weeks
  3. Secure onboard communication

    2 weeks
  4. OTA architecture and R156

    2 weeks

Learning outcomes

What You Take Back to Your Programme

Capability you can demonstrate, not topics you have been exposed to.

What you will be able to do

  • Design segregated zonal and domain architectures
  • Specify gateway and firewall policy for vehicle networks
  • Architect secure OTA update paths to R156
  • Lead architecture-level security reviews
  • Career outcomes

    • Security Architect
    • E/E Architect
    • Technical Lead
  • Capability levels

    • Secure Developer
  • Tools and skills

    • Architecture modelling toolchain
    • Gateway policy specification templates
    • SecOC configuration workbench
    • OTA campaign design patterns

Labs included

Hands-On Time on Real Hardware

Lab access is included with this program, and the exercises below are assessed rather than optional.

  • Included lab
    2 assessed exercises

    AutoSec TARA Lab

    Model threats against real vehicle architectures

    Objectives

    • Define items and assets from a real vehicle architecture
    • Derive attack paths and rate feasibility
    • Produce cybersecurity goals and requirements

    Practical exercises

    • Central gateway TARA
      intermediate
      4 hours

      Full assessment of a domain gateway including diagnostic and OTA interfaces.

    • Telematics unit attack paths
      advanced
      3 hours

      Derive and rate attack paths across cellular, Bluetooth and Wi-Fi interfaces.

  • Included lab
    2 assessed exercises

    AutoSec Secure Development Lab

    Harden ECU software on real hardware

    Objectives

    • Implement secure boot on an automotive microcontroller
    • Integrate an HSM-backed key hierarchy
    • Apply SecOC to a CAN communication matrix

    Practical exercises

    • Secure boot chain of trust
      advanced
      5 hours

      Build and verify a signed bootloader with rollback protection.

    • SecOC on a CAN bus
      advanced
      4 hours

      Add authentication and freshness to safety-relevant CAN frames.

Certification mapping

Where This Sits in the Framework

How the program maps to the AutoSec Automotive Cybersecurity Capability Framework™ and the certification ladder.

Capability Framework

Secure Developer

Build secure ECU software, crypto stack integration, SecOC, Secure Boot and HSM skills.

  • Secure ECU development lifecycle
  • Automotive crypto stack
  • Secure Boot, HSM, SecOC and Secure Flash
  • Hardware security features of automotive microcontrollers

Certification

AutoSec Certified Professional

Confirms hands-on capability to design and build secure vehicle systems — architecture segregation, secure boot, HSM-backed key handling and SecOC.

Level 3 · Professional

Exam preparation

Format
hybrid
Duration
3 hours
Passing score
75%
Valid for
3 years
  • Hold the Practitioner certification
  • Complete Secure ECU Developer or Secure Automotive Architect
  • Pass a supervised practical assessment on lab hardware
See the full certification ladder

Common questions

Secure Automotive Architect FAQ

What candidates and their managers ask before enrolling.

Is this program design-only, or is there implementation work?
It is design-led with implementation context. You will configure SecOC and reason about secure boot on lab hardware, but the assessed output is architectural — segregation decisions, gateway policy and an OTA design that satisfies UNECE R156.
Do I need TARA Specialist first?
Strongly recommended rather than mandatory. Architecture decisions in this program are justified against rated attack paths, and candidates without TARA experience spend the first week catching up on the risk vocabulary.
Does it cover zonal architectures specifically?
Yes. Zonal and domain patterns are treated side by side, including where zonal consolidation weakens the segregation assumptions that domain architectures relied on.

Ready to Start AutoSec Security Architect?

Enrol as an individual, or talk to us about running this program for your engineering team.