SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Zoox is seeking a Staff/Senior Staff Software Engineer for Product Security to lead the design and implementation of secure, scalable infrastructure across the company's autonomous vehicle fleet and supporting ecosystem. This is a strategic, architecture-focused role responsible for establishing best-in-class security practices and driving an automation-first, infrastructure-as-code approach to security.
Key Responsibilities:
- Define and own the multi-year security architecture and roadmap for Zoox's robots and fleet, spanning embedded/firmware, in-vehicle networks, cloud, and supporting infrastructure.
- Partner with hardware, firmware, autonomy, and infrastructure engineering teams to embed security requirements into system design from inception, rather than retrofitting security after development.
- Lead threat modeling and architecture reviews for new vehicle platforms and major feature launches, identifying and prioritizing systemic risk across the fleet.
- Set technical standards and guardrails—including secure boot, key management, network segmentation, update/OTA security—and drive their adoption across engineering teams.
- Represent Product Security in cross-functional and leadership discussions, translating technical risk into business and safety impact for the organization.
- Act as a security champion, ensuring infrastructure designs meet the highest standards of confidentiality, integrity, and availability while maintaining operational efficiency and scalability.
The role requires driving cross-functional technical strategy and influencing engineering leadership without direct authority, positioning this as a principal-level individual contributor role within a fast-moving, execution-oriented team.
Requirements:
- 10+ years of experience in security engineering, including significant time in an architect, staff, or technical lead capacity.
- Deep expertise in embedded/IoT security, including secure boot, TPM/TEE, cryptographic key management, and hardened firmware/OS design.
- Demonstrated experience architecting security for complex, physical/cyber-physical systems (automotive, robotics, aerospace, industrial control, or similar).
- Strong track record of driving cross-functional technical strategy and influencing engineering leadership without direct authority.
- Solid understanding of network security, cloud security, and secure software development lifecycle practices.
Bonus Qualifications:
- Experience securing autonomous vehicles, robotics platforms, or other safety-critical connected systems at scale.
- Background in offensive security (red teaming, penetration testing) that informs strong architectural/defensive judgment.
- Contributions to industry standards, published research, or conference talks in embedded/IoT/automotive security.