Responsibilities
- Define and manage a long-term product security roadmap aligned with business goals, threats, and regulations across vehicle firmware, cloud infrastructure, mobile apps, and over-the-air updates.
- Integrate security throughout the software development lifecycle by collaborating with engineering teams on threat modeling, risk assessments, secure coding standards, and automated security testing in CI/CD pipelines.
- Ensure compliance with automotive cybersecurity standards such as ISO/SAE 21434 and UN Regulation No. 155, securing vehicle architectures, communication protocols, telematics, and advanced driver assistance systems.
- Develop and operate a comprehensive vulnerability management program, including bug bounty initiatives, penetration testing coordination, and remediation tracking across all product surfaces.
- Establish and enforce security requirements for automotive suppliers and software vendors, managing software bill of materials and third-party assessments to ensure supply chain integrity.
- Protect AI and autonomy platforms by developing threat models for machine learning pipelines, model integrity, adversarial attacks, and in-vehicle inference systems.
- Lead the Product Security Incident Response Team, defining disclosure processes, incident response playbooks, and communication protocols for security events.
- Build and mentor a global product security team across multiple engineering locations, fostering a culture of ownership, technical excellence, and collaboration.
- Advise executive leadership on security posture and risks, represent the organization in industry forums, and serve as the primary external contact for product security matters.
Benefits
- Benefits tailored to the local market.
Compensation
Full-time positions include base salary, eligibility for an annual performance bonus, and eligibility for equity.
Work Arrangement
On-site — Palo Alto, CA
Other
- Full-time positions include base salary, eligibility for an annual performance bonus, and eligibility for equity.
- Benefits tailored to the local market.
- External candidates apply through careers site; current employees through internal job board.
- Equal opportunity employer.
- Candidate data privacy applies; personal information used for recruitment purposes.
- SMS communications for recruitment; opt-out available.
- Not accepting applications from third party application services.
Not specified