> Markdown version of [/jobs/ext/1948407-product-security-engineer-qra](https://www.wearedevelopers.com/jobs/ext/1948407-product-security-engineer-qra). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Product Security Engineer - QRA - **Company:** Zoox - **Location:** San Diego, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Systems Engineering, Cyber Security, Cloud Services, Large Language Models, Software Security - **Published:** August 6, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/product-security-engineer-qra-san-diego-ca-usa-58814667 ## About the Role Build deep understanding of engineering constraints and factor into analyses and plans * Analyze existing/ emerging standards and distill into actionable adoption plans with business impact Tasks * Master's degree in CS or related engineering field * 5+ years of relevant experience * Strong systems engineering background with cybersecurity expertise * Experience with quantitative risk assessment frameworks (EPSS, attack trees/graphs, Monte Carlo, Bayesian networks) * Experience with security analysis of complex embedded systems and turning analysis into high-quality written deliverables * Pragmatic use of AI/LLM toolchains for security analysis and regulatory deliverables Key requirements * health insurance * life insurance * disability insurance * paid time off * stock appreciation rights * Amazon RSUs (restricted stock units) ## Description Experteer Overview In this role you will apply systems engineering expertise to cybersecurity for Zoox's autonomous vehicle ecosystem. You will lead threat analyses and risk assessments across vehicle and cloud domains, translating findings into tangible security controls and requirements. You'll collaborate with cross-functional teams to balance safety and security objectives, while shaping standards adoption with a business-focused plan. This is a rigorous, impact-driven opportunity at a fast-moving robotics company. Compensation / Benefits * Quantify security-related safety risks through cross-functional collaboration, guiding risk-informed engineering decisions * Conduct security analysis, threat modeling, and risk assessment for vehicle fleet and cloud services * Define cybersecurity requirements and maintain a catalog of controls to establish secure baselines * Interface with multiple engineering teams across software and hardware to translate analysis into recommendations * Build deep understanding of engineering constraints and factor into analyses and plans * Analyze existing/ emerging standards and distill into actionable adoption plans with business impact Tasks * Master's degree in CS or related engineering field * 5+ years of relevant experience * Strong systems engineering background with cybersecurity expertise * Experience with quantitative risk assessment frameworks (EPSS, attack trees/graphs, Monte Carlo, Bayesian networks) * Experience with security analysis of complex embedded systems and turning analysis into high-quality written deliverables * Pragmatic use of AI/LLM toolchains for security analysis and regulatory deliverables Key requirements * health insurance * life insurance * disability insurance * paid time off * stock appreciation rights * Amazon RSUs (restricted stock units) ## Related Videos - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)