Senior Product Security Engineer - QRA

Zoox
Boston, MA, United States
6 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours

Tech stack

Artificial Intelligence Systems Engineering Cyber Security Cloud Services Large Language Models Software Security

Job description

Experteer Overview In this role you will drive threat analysis and security standardization across Zoox’s complex product ecosystem. You will quantify security-related safety risks and align security with safety objectives through cross-functional collaboration. You’ll translate analyses into high-quality written deliverables and shape risk-informed engineering decisions for embedded systems and cloud services. You will evaluate threats across wireless and wired automotive interfaces and guide adoption of practical, impactful cybersecurity controls. This position offers the chance to influence security engineering at scale in a fast-moving autonomous mobility company. Compensation / Benefits * Perform quantitative risk assessment quantifying security-related safety risks with cross-functional safety teams * Conduct security analysis, threat modeling, and risk assessment for vehicle fleet and cloud services * Define cybersecurity requirements and maintain a catalog of security controls to establish secure baselines * Interface with multiple engineering teams across software and hardware to inform decisions * Maintain understanding of engineering constraints and reflect them in analyses and recommendations * Analyze existing and emerging cybersecurity standards and develop adoption plans with clear business impact Tasks * Master’s degree in CS or related engineering field and 7+ years of experience * Strong systems engineering background with cybersecurity expertise * Experience with quantitative risk assessment frameworks (e.g., EPSS, attack trees/graphs, Monte Carlo, Bayesian networks) * Experience with security analysis of complex embedded systems and turning analysis into written deliverables * Pragmatic use of AI/LLM toolchains for security analysis and regulatory deliverables Key requirements * paid time off * health insurance * Amazon RSUs * Zoox Stock Appreciation Rights * sign-on bonus * life insurance

Requirements

to establish secure baselines * Interface with multiple engineering teams across software and hardware to inform decisions * Maintain understanding of engineering constraints and reflect them in analyses and recommendations * Analyze existing and emerging cybersecurity standards and develop adoption plans with clear business impact Tasks * Master’s degree in CS or related engineering field and 7+ years of experience * Strong systems engineering background with cybersecurity expertise * Experience with quantitative risk assessment frameworks (e.g., EPSS, attack trees/graphs, Monte Carlo, Bayesian networks) * Experience with security analysis of complex embedded systems and turning analysis into written deliverables * Pragmatic use of AI/LLM toolchains for security analysis and regulatory deliverables Key requirements * paid time off * health insurance * Amazon RSUs * Zoox Stock Appreciation Rights * sign-on bonus * life insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:41 min

Transitioning artificial intelligence infrastructure into scalable commodity cloud services

juarezjunior juarezjunior · WWC 2024

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · WWC 2025

2:06 min

Elevating the QA engineering role for complex challenges

Ondřej Gróf Ondřej Gróf · WWC Europe 2026

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

9:40 min

Audience Q&A on security risks and team models

Tanya Janca · WWC 2021

Videos

See all

Related articles

See all