Skip to main content
All posts

Functional Safety Is the ADAS Hire Generalists Keep Missing

By Game 7 Staff6 min read
Functional safety engineer reviewing ASIL-D AEB hazard and FMEDA documents in office

A functional safety engineer is not a senior embedded engineer with ISO 26262 on the resume. It is a distinct discipline built on HARA, FMEDA, and a V-model paper trail an assessor will scrutinize. Here is what the work actually is, how ASIL level changes who you need, and why generalist staffing keeps missing the seat.

The program is an ASIL-D automatic emergency braking function. The safety case is due to the assessor in a quarter, the HARA needs an owner, and the requisition for a functional safety engineer has been open for four months. The generalist firm keeps sending senior embedded resumes with “ISO 26262” in the skills list. None of them has authored a hazard analysis or closed an FMEDA. The req is not hard because the market is empty. It is hard because it is being screened for the wrong thing.

Functional safety is a distinct engineering discipline, not a flavor of embedded work, and that difference is exactly what generalist screening misses. It has its own artifacts, its own process, and a talent pool that a keyword search cannot see. For an ADAS or EV program with a certification gate in front of it, hiring for the discipline instead of the buzzword is the whole game.


What Functional Safety Work Actually Is

ISO 26262 is the automotive adaptation of the IEC 61508 functional safety standard, and it governs the safety lifecycle of electrical and electronic systems from concept through decommissioning (TÜV SÜD overview). The engineer who does this work is not primarily writing application code. They are producing the evidence that the system is acceptably safe, in a form an external assessor will pull apart.

The lifecycle has a recognizable spine. It starts with a HARA, the Hazard Analysis and Risk Assessment, where the team identifies hazards and rates each one by severity, exposure, and controllability. Those ratings assign an ASIL. From the safety goals that fall out of the HARA, the engineer derives a Functional Safety Concept and then a Technical Safety Concept: safety goals become functional safety requirements, which become technical safety requirements allocated to specific hardware and software.

On the hardware side, an FMEDA (Failure Modes, Effects, and Diagnostic Analysis) computes the metrics that prove the design meets its ASIL: the Single Point Fault Metric, the Latent Fault Metric, and the probabilistic metric for random hardware failures. All of it hangs on the V-model. Requirements and analysis run down the left side, integration and verification climb the right, and traceability ties every safety requirement to the test that closes it. The output is a safety case, and it lives or dies on rigor, not on clever firmware.


ASIL-A Through ASIL-D: How the Level Changes Who You Need

The ASIL is set by the HARA, combining severity, probability of exposure, and controllability into one of five outcomes: QM, then ASIL A, B, C, and D (Synopsys, What is ISO 26262). The letter is not a label. It dictates how much rigor the work demands, and therefore who you actually need in the seat.

At ASIL A and B, the job is real but more forgiving. Process discipline, MISRA-C, FMEA, and requirements traceability carry most of it, and a strong embedded engineer with genuine functional-safety exposure can often own it under a safety manager’s oversight. The risk is lower, so the diagnostic and architectural demands are lighter.

ASIL D is the top tier, reserved for hazards that can kill: braking, steering, propulsion. It brings hardware redundancy such as lockstep cores, high diagnostic-coverage targets, freedom from interference between mixed-criticality software, dependent-failure analysis, and sometimes formal methods (NXP functional safety). You need a practitioner who has taken an ASIL-D item through assessment, not someone who has read the standard. A fast seniority test: ask whether they have used ASIL decomposition to split a D-rated goal across redundant lower-rated elements. A practitioner has a concrete example. A keyword candidate has never heard the question.


Why Demand Outruns Supply, and Generalist Firms Whiff on These Reqs

Two forces are pulling in the same direction. The first is regulation. NHTSA’s final rule, FMVSS No. 127, makes automatic emergency braking, pedestrian AEB, and forward collision warning mandatory on all new light vehicles by September 2029 (NHTSA). Every automaker and Tier 1 selling into the US now needs ASIL-rated ADAS in the pipeline, and Euro NCAP already rewards it. Functional safety has moved from differentiator to table stakes.

The second is the software-defined vehicle transition. McKinsey projects automotive software demand growing three to four times by 2030 and describes a persistent annual shortfall of tens of thousands of trained professionals, with OEMs now competing directly against Big Tech and aerospace for the same people (McKinsey). Functional safety sits at the rarest intersection of that market: embedded depth, plus process rigor, plus automotive domain. The overlap is small, and it is not growing as fast as the mandates that need it.

Generalist firms whiff because they screen for “ISO 26262” as a string on a resume. They cannot tell a HARA author from an engineer who once sat in safety meetings. They do not know to probe SPFM targets, diagnostic coverage, or ASIL decomposition, so they forward senior embedded profiles and call it a match. The only well-known alternative in this space is a safety consultancy billing at consulting day-rates, which solves the capability problem and creates a cost one. What is missing is the same depth at staffing economics: a contract engineer embedded in your team, not an outside firm renting you hours.


Contract Functional-Safety Engineers: Where They Fit in a Certification-Gated Program

Certification-gated programs have a shape. The safety workload is heavy at concept and design, when the HARA, the FSC, and the TSC get built, and heavy again at the verification and assessment push. In between, it eases. Carrying a full roster of ASIL-D practitioners as permanent headcount across that entire curve rarely matches the actual need.

Contract matches the curve. You bring an ASIL-D practitioner in to stand up the safety case and the core analyses, then scale the engagement down as the program moves into steadier work. Contract safety engineers tend to have carried multiple items through assessment across different OEMs and Tier 1s, so they arrive with a pattern library and a working relationship with how assessors think. Full-time hiring earns its place where functional safety is a permanent organizational capability: a safety manager who owns the process and the culture across programs. Many teams run both, keeping the safety manager on staff and surging analysis-heavy phases with contract practitioners.

This is the pool Game 7 works in. When we put an engineer in front of a hiring manager, close to two out of three receive an offer, a 1.46:1 interview-to-offer ratio in 2025–26 against an industry norm of three to five interviews per offer. On a discipline this specialized, that ratio is the difference between a safety case that ships and a milestone that slips.


Screening Questions That Separate a Practitioner From a Resume Keyword

If you take one thing from this piece into your next interview loop, take these questions. Each one is easy to answer for someone who has done the work and nearly impossible to fake.

  • “Walk me through a HARA you authored. How did you assign the ASIL?” A practitioner reasons out loud about severity, exposure, and controllability. A keyword candidate says a tool produced it.
  • “How did you compute SPFM and LFM on your last program, and what diagnostic coverage did you target?” You want real numbers and the safety mechanisms behind them, not a definition.
  • “Have you used ASIL decomposition, and on what item?” Listen for a concrete example and an understanding of the rules for allocating decomposed requirements.
  • “In ISO 26262 terms, what is the difference between a fault, an error, and a failure?” A thirty-second fundamentals check that filters out the resume-deep candidates fast.
  • “Describe freedom from interference in a mixed-criticality system you worked on.” You want partitioning, memory protection, and hypervisor or lockstep detail from real experience.
  • “Who was your assessor, and what did they push back on?” Real assessment experience produces a specific story. A keyword candidate has none to tell.


If you have an ISO 26262 seat open and an assessment date that will not move, that is the search we run. Tell us the ASIL, the item, and the program phase, and we will come back with practitioners who have done it before.

FAQ

Frequently Asked Questions

Do I Need an ISO 26262 Specialist, or Can a Senior Embedded Engineer Cover It?

It depends on the ASIL. At ASIL A or B, a strong embedded engineer with real functional-safety exposure can often carry the work under a safety manager. At ASIL C or D, you need a specialist who has taken a comparable item through assessment. The gap is not coding skill. It is the ability to produce and defend HARA, FMEDA, and the safety case, which most embedded engineers have never done.

What Is the Difference Between ASIL-D and Lower ASIL Levels for Hiring?

ASIL D applies to hazards that can be fatal and demands the heaviest rigor: hardware redundancy, high diagnostic coverage, dependent-failure analysis, and freedom from interference. Lower levels relax those requirements. For hiring, ASIL D means you must verify hands-on assessment experience; lower levels leave more room for a capable embedded engineer to grow into the role with oversight.

What Does a Functional Safety Engineer Actually Deliver?

Evidence, not just code. The core deliverables are the HARA, the Functional and Technical Safety Concepts, the FMEDA and its hardware metrics (SPFM, LFM, PMHF), the verification and traceability records, and the safety case that ties them together for an external assessor. Application firmware may be part of the job, but the safety artifacts are the point.

Why Can’t Generalist Staffing Firms Fill Functional Safety Roles?

They screen for “ISO 26262” as a keyword instead of the discipline behind it. Without knowing to probe HARA authorship, SPFM targets, or ASIL decomposition, they cannot distinguish a practitioner from someone who attended safety reviews, so they forward senior embedded resumes that do not match the seat.

Should Functional Safety Engineers Be Contract or Full-Time?

Often both. Keep a safety manager on staff to own the process across programs, and use contract ASIL-D practitioners to cover the analysis-heavy concept and assessment phases. Contract engineers who have cleared assessments at multiple OEMs and Tier 1s ramp fast and match the pulsed shape of certification work.

Written by

Game 7 Staff