Jobs and Careers
AU

Staff Technical Program Manager - Security Risk Management

Aurora Innovation
Pittsburgh, United Statesfull_timeVerifiedPosted 29 Aug 2024
💰 $317,000/yr

About the role

Who We Are

Aurora (Nasdaq: AUR) is delivering the benefits of self-driving technology safely, quickly, and broadly to make transportation safer, increasingly accessible, and more reliable and efficient than ever before. The Aurora Driver is a self-driving system designed to operate multiple vehicle types, from freight-hauling semi-trucks to ride-hailing passenger vehicles, and underpins Aurora Horizon and Aurora Connect, its driver-as-a-service products for trucking and ride-hailing. Aurora is working with industry leaders across the transportation ecosystem, including Toyota, FedEx, Volvo Trucks, PACCAR, Uber, Uber Freight, U.S. Xpress, Werner, Covenant, Schneider, and Ryder. For Aurora’s latest news, visit aurora.tech and @aurora_inno on Twitter.

Aurora hires talented people with diverse backgrounds who are ready to help build a transportation ecosystem that will make our roads safer, get crucial goods where they need to go, and make mobility more efficient and accessible for all. The mission of Aurora’s Security Technical Program Management (TPM) team is to embed security into every aspect of Aurora’s products—spanning software, hardware, and services. As a key member of this team, you will be responsible for driving security strategy and initiatives across the organization, ensuring that security is a fundamental part of the product development process.  You will act as a bridge between Security and Product teams, moving seamlessly between high-level strategy and detailed execution to ensure that complex, cross-functional security programs are successfully integrated into product development. Your ability to lead, influence, and manage large-scale security initiatives will be essential in safeguarding Aurora’s products and ensuring they meet the highest security standards.

Job level is negotiable based on experience. Flexible work locations are available (MTV, SFO, PIT, SEA) for US-based employees (Full remote is not available for this role).

In this role, you will

  • Lead security integration: Develop and execute security assurance, governance, and risk management programs, ensuring they are deeply embedded into all phases of product development and aligned with company objectives.
  • Collaborate with product teams: Work closely with product management, engineering, and security teams to assess product risks, prioritize security initiatives, and implement strategic controls that protect both product integrity and user trust.
  • Drive external assessments: Oversee external security assessments and penetration tests, translating findings into actionable risk mitigation strategies that enhance product security.
  • Manage product risk: Lead the security risk management program with a focus on product-related risks, ensuring alignment with enterprise risk management efforts and compliance with industry regulations.
  • Monitor and report: Define and report on key performance indicators (KPIs) related to product and security risks, ensuring transparency and data-driven decision-making across the organization.

Required Qualifications

  • 10+ years of experience in Technical Program Management, with a strong focus on cybersecurity, particularly within the context of product development.
  • Bachelor’s or Master’s degree in Computer Science, Information Security, or a related technical field, or equivalent experience.
  • Proven experience leading large-scale security programs with an emphasis on integrating security into product development cycles.
  • Strong communication and leadership skills, with the ability to influence and collaborate with cross-functional product teams.
  • Hands-on experience managing external security assessments and penetration tests, with the ability to translate technical findings into practical security improvements for products.

Desirable Qualifications 

  • Advanced certifications such as CISSP, OSCP, GIAC-PEN, CISM, or equivalent, demonstrating expertise in cybersecurity and product risk management.
  • Experience building and scaling security programs from the ground up, particularly in product-focused environments or industries with stringent security requirements.
  • Strong knowledge of industry security standards and regulations (e.g., ISO 27001, SOC2, NIST, GDPR), with proven exp

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Aurora Innovation

View company profile →