Staff Security Engineer - GRC
Aurora InnovationAbout the role
Who We Are
Aurora (Nasdaq: AUR) is delivering the benefits of self-driving technology safely, quickly, and broadly to make transportation safer, increasingly accessible, and more reliable and efficient than ever before. The Aurora Driver is a self-driving system designed to operate multiple vehicle types, from freight-hauling semi-trucks to ride-hailing passenger vehicles, and underpins Aurora Horizon and Aurora Connect, its driver-as-a-service products for trucking and ride-hailing. Aurora is working with industry leaders across the transportation ecosystem, including Toyota, FedEx, Volvo Trucks, PACCAR, Uber, Uber Freight, U.S. Xpress, Werner, Covenant, Schneider, and Ryder. For Aurora’s latest news, visit aurora.tech and @aurora_inno on Twitter.
Aurora’s Security Governance, Risk and Compliance (GRC) team’s mission is to accelerate Aurora’s maturity and improve overall business performance by bridging people, processes and technology together in order to drive strategy, design and implementation.
Our team is responsible for ensuring that an organization's security policies and procedures are aligned with its business objectives, and that it is compliant with industry and government regulations. The team is also responsible for identifying potential threats and managing security risks across Aurora. This team also ensures that the organization complies with relevant industry and government regulations and standards such as ISO (21434 / 27001), NIST, HIPAA, GDPR, etc.. We work closely with various teams (Engineering and Non Engineering) across Aurora as well as 3rd party partners to develop and integrate the proper initiatives to enhance the security posture and security maturity of Aurora and its products.
We are searching for an experienced Security Engineer with strong GRC experience that is excited to lead the assurance of the overall security posture and maturity of the organization to join us on this mission.
In this role, you will:
- Developing, implementing and maintaining security policies and standards that aligns with business objectives and industry best practices
- Conduct risk assessments to identify potential threats and deficiencies in the organization's security infrastructure and products
- Manage, align, and enforce security compliance requirements for the organization and products
- Monitor security incidents and breaches, investigate their root cause, and take appropriate measures to prevent future incidents
- Provide security training to employees, contractors, and partners to help them understand their responsibilities and the importance of security best practices.
- Conduct periodic audits of security controls and assess the effectiveness of the organization and product’s security measures.
- Drive and coordinate security incident response efforts while ensuring that all stakeholders are informed, and provide guidance on the appropriate course of action.
- Review, develop and document security best practices, and provide security guidance for engineers and various internal and external partners
- Lead successful verification of security capabilities, components and remediation work with partner teams
- Work with Engineering teams and OEMs to ensure successful security assurance of the Aurora and the Aurora Driver platform
- Guide and mentor both security and non-security engineers.
Required Qualifications
- Foundational knowledge of operating system security for Linux, Windows, MacOS
- Foundational knowledge of the CWE Top 25
- Ability to assess software and/or hardware risks with and without full knowledge
- Ability to work well with other security team members and engineering partners
- Ability to communicate effectively with technical and non-technical audiences
- Experience in two or more of the following: risk assessment, threat modeling, incident and emergency response, OS hardening, vulnerability management, pentesting, offensive security or cryptographic protocols and concepts
- Experience in vulnerability discovery and analysis, design review, and code-level security reviews
- Experience in, and technical knowledge of security engineering, computer and network security, authentication and security protocols, and applied cryptography.
- Experience with assessment, development, implementation, and documentation of a comprehensive and broad set of security technologies and processes
- Familiarity in Security Compliance / Secure-SDLC processes in an agile / waterfall enviro
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s