Senior Staff Security Product Architect
About the role
Aurora’s OneTech Security Architect team embeds security into every aspect of Aurora’s products—spanning software, hardware, and services. As a Senior Staff Security Product Architect, you will serve as a primary technical authority driving the end-to-end security architecture across Aurora’s autonomous vehicle platform, hardware system controls, embedded systems, and connected cloud services. You will act as a technical liaison between Security, System Engineering, and Product teams, moving seamlessly between high-level architectural strategy and detailed technical execution to ensure robust, defense-in-depth security is integrated into products developed across the company.
The job level is negotiable based on experience. Flexible work locations are available (MTV preferred, SFO, PIT, SEA, BJC, DET, BZN) for US-based employees; full remote is not available for this role.
Responsibilities
- Define End-to-End Security Onboard and Offboard Architecture: Design and specify system-level security architectures and trust boundaries across vehicle hardware, onboard systems and software, safety-critical ECUs, and connected offboard platforms, services, infrastructure, and applications. Establish secure boot flows, cryptographic key management, and hardware security module (HSM/TPM) integrations and secure protocols to protect data at rest, in transit, and between cloud-to-vehicle interactions.
- Lead Threat Modeling & Design Reviews: Direct threat modeling (e.g., TARA, STRIDE) and vulnerability analysis for complex autonomous cloud and compute systems, sensor suites, networks, and cloud infrastructure.
- Collaborate with Engineering & Product Teams: Work closely with Product Management, Software and Hardware Development, and Core Security teams to support security requirements and goal development, translate them into implementable engineering designs, assess product risk, and protect product integrity.
- Engage with Suppliers and Tier 1 Partners: Drive architectural security requirements with hardware/software suppliers and Tier 1 development partners, ensuring third-party components and IP meet Aurora’s cybersecurity standards.
- Build Technical Security Roadmaps: Partner with program management, technical leads, and engineers to develop roadmaps for key security investments, resolve cross-functional technical dependencies, and meet standard design patterns within Aurora.
- Embed Security Assurance & Controls: Develop and enforce architectural security assurance, governance, and risk mitigation strategies into all phases of the hardware and software product lifecycle.
Requirements
- 15+ years of experience in security architecture, system security engineering, or product security roles within automotive, autonomous vehicles, embedded systems, or complex hardware/software systems.
- Bachelor’s or Master’s degree in Computer Science, Computer Engineering, Electrical Engineering, Cybersecurity, or a related STEM field.
- Deep technical domain expertise in embedded security principles, hardware security anchors (e.g., Secure Boot, ARM TrustZone, HSMs, TPMs), applied cryptography, and secure protocol design (e.g., SecOC, CAN/Ethernet security, TLS).
- Proven experience performing architectural security assessments, system-level threat modeling, and secure design reviews for hardware and software platforms.
- Strong communication and technical leadership skills, with a demonstrated ability to influence cross-functional engineering teams and drive architectural decisions.
Qualifications
- Experience with and knowledge of automotive and cloud security standards and regulations, such as ISO/SAE 21434, ASPICE, ISO 27001, or UNECE R155/R156.
- Strong foundation of experience to successfully engage, communicate, and influence OEMs, Tier-1s, Suppliers, or commercial partners in order to further Aurora’s security posture.
- Practical experience designing secure systems between autonomous vehicle stacks, safety-critical ECUs, off-board telemetry/cloud infrastructures, and cloud/cloud applications.
- Experience building and scaling security architecture frameworks from the ground up in safety-critical or heavily regulated industries.
- Advanced security architecture or engineering certifications such as CISSP-ISSAP, CISM, or equivalent.
Pay
For roles based in Mountain View, CA and Seattle, WA: The salary range for this position is $212,000 - $307,000 per year. For roles based in Pittsburgh, PA: The salary range is $191,000 - $277,000 per year. Aurora’s pay ranges are determined by role, level, and location. Within the range, starting base pay will be determined based on job-related skills, experience, qualifications, relevant education or training, and market conditions. The successful candidate will also be eligible for an annual bonus, equity compensation, and benefits.
Schedule
Aurora operates in a hybrid work environment where employees are in the office at least 3 days per week.
Benefits
At Aurora, we bring together extraordinarily talented and experienced people united by our values. We operate with integrity, set outrageous goals, and build a culture where we win together—all without any jerks. Our benefits include:
- Annual bonus and equity compensation.
- Commitment to safety, with every employee contributing to building best-in-class self-driving technology.
- Inclusive culture where Aurora considers candidates without regard to race, color, religion, national origin, age, sex, gender, gender identity, sexual orientation, marital status, pregnancy status, parent or caregiver status, ancestry, political affiliation, veteran and/or military status, physical or mental disability, or any other status protected by law.
- Reasonable accommodations for qualified individuals with disabilities and disabled veterans.