Staff Product Security Engineer
Aurora InnovationAbout the role
Who We Are
Aurora (Nasdaq: AUR) is delivering the benefits of self-driving technology safely, quickly, and broadly to make transportation safer, increasingly accessible, and more reliable and efficient than ever before. The Aurora Driver is a self-driving system designed to operate multiple vehicle types, from freight-hauling semi-trucks to ride-hailing passenger vehicles, and underpins Aurora Horizon and Aurora Connect, its driver-as-a-service products for trucking and ride-hailing. Aurora is working with industry leaders across the transportation ecosystem, including Toyota, FedEx, Volvo Trucks, PACCAR, Uber, Uber Freight, U.S. Xpress, Werner, Covenant, Schneider, and Ryder. For Aurora’s latest news, visit aurora.tech and @aurora_inno on Twitter.
Aurora hires talented people with diverse backgrounds who are ready to help build a transportation ecosystem that will make our roads safer, get crucial goods where they need to go, and make mobility more efficient and accessible for all. Aurora’s Product Security team’s mission is to discover, mitigate, and prevent security risks in the software, hardware, and services developed by Aurora.
Our team is responsible for ensuring the secure design and implementation of secure technologies used by the Aurora Driver as well as continually improving the assurance levels of security across all of Aurora’s Products. This team is also responsible for developing, contributing and documenting security engineering processes and the resulting product security requirements used by the company. Additionally team members support and perform technical security assessments, threat modeling, security code reviews and vulnerability testing to highlight and document risks. This team works closely with engineers across Aurora as well as 3rd party partners to design and proactively integrate initiatives to enhance security across a wide variety of software or hardware domains and technology stacks. We are searching for an experienced Security Engineer with strong automotive security assessment experience that is excited to lead the assurance of the overall security posture for the autonomous vehicle platform to join us on this mission.
In this role, you will
- Provide consulting and advisory services to engineering teams heavily focused on automotive cybersecurity
- Work directly with engineering and non-engineering teams to drive improvements in internal processes, procedures and technical fundamentals
- Develop, document, improve, implement and execute cybersecurity best practices and processes for autonomous vehicles across internal and external engineering partners
- Perform technical automotive cybersecurity assessments and reviews, research, uncover, and reproduce vulnerabilities, design secure protocols and systems, and write tests and fuzzers to drive architecture changes
- Assess the risks across the Aurora Driver Platform and prioritize high value components (software and/or hardware) for critical and high security vulnerabilities
- Conduct research to identify new and novel attack vectors against Aurora’s products and services
- Review, develop and document secure operational best practices, and provide security guidance for engineers and various internal and external partners
- Lead successful integration of security capabilities, components and remediation work with partner teams
- Further develop, refine, and establish methods, processes and new products in automotive cybersecurity
- Work with Engineering teams and OEMs to ensure successful security assurance of the Aurora Driver platform
- Guide, mentor and train both security and non-security engineers
Required Qualifications
- Foundational knowledge of Automotive Cybersecurity (ISO21434/UNECE/NHTSA)
- Foundational knowledge of operating system security for Linux
- Foundational knowledge of the CWE Top 25
- Develop, document and execute structured processes and procedures around automotive cybersecurity
- Ability to assess software and/or hardware components with and without full knowledge
- Ability to work well with other assessment members and engineering partners
- Ability to communicate effectively with technical and non-technical audiences
- Experience in one or more of the following: risk assessment, threat modeling, incident and emergency response, OS hardenin
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s