> Markdown version of [/jobs/ext/510825-senior-software-engineer-security-engineering](https://www.wearedevelopers.com/jobs/ext/510825-senior-software-engineer-security-engineering). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Software Engineer, Security Engineering - **Company:** Bot Auto - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Artificial Intelligence, Amazon Web Services, User Authentication, C++ (Programming Language), Cloud Computing, Cloud Computing Security, Continuous Integration, Data Centers, Distributed Systems, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Key Management, Network Security, Open Web Application Security, Systems Development Life Cycle, Zero Trust Network Access, Security Information and Event Management, Software Engineering, TypeScript, Software Vulnerability Management, Data Logging, Pulumi, Cloud Platform System, Large Language Models, Kubernetes, Information Technology, Hashicorp, U-Boot, Terraform, Static Application Security Testing, Dynamic Application Security Testing - **Published:** June 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e72f0f7d0373801b ## About the Role Do you have experience in System design for system development?, * Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent experience * 5+ years of hands-on software engineering experience, with a strong focus on security * Strong software development skills in one or more languages: Python, Go, Rust, C/C++, or JavaScript/TypeScript * Solid understanding of applied cryptography, authentication and authorization, secure system design, and common vulnerability classes * Experience securing cloud infrastructure and/or distributed systems in production, * Experience with embedded, automotive, IoT, or other onboard/edge security (secure boot, TPM/HSM, code signing, OTA updates) * Familiarity with Kubernetes and cloud security (AWS), IaC security (Terraform, Pulumi), and CI/CD pipeline hardening * Knowledge of AI/LLM security: prompt injection, model supply chain, agent sandboxing, and AI guardrail frameworks * Experience with IAM, secrets management (e.g., HashiCorp Vault), and zero-trust architectures * Hands-on experience with security tooling: SAST/DAST, SBOM and dependency scanning, SIEM, and detection engineering * Familiarity with security standards and frameworks (e.g., ISO/SAE 21434, NIST, OWASP, SOC 2) * Experience with threat modeling and incident response ## Description We are seeking a highly skilled and motivated Senior Software Engineer, Security Engineering to design, build, and operate security across Bot Auto's autonomous trucking stack. The proprietary technology that powers our autonomous driving system is our core intellectual property, and protecting it - along with the safety-relevant systems behind our fleet - is mission critical. In this role, you will work across onboard (in-vehicle) security as well as infrastructure and platform security. You will also help shape how Bot Auto adopts AI responsibly: understanding the security implications of large language models and agentic systems, and developing the protections that let us innovate quickly and safely. As a hands-on technical leader, you will embed security best practices into every layer of our systems, from the vehicle to the cloud., * Design and implement security controls for onboard (in-vehicle) systems, including secure boot, code signing, secrets and key management, secure over-the-air (OTA) updates, and hardening of the autonomous driving software stack. * Architect and operate security across infrastructure and platforms, spanning Kubernetes, public cloud (AWS), on-prem data centers, CI/CD pipelines, and internal developer platforms. * Develop protections for AI systems - assess the security implications of large language models and agentic workflows (prompt injection, data exfiltration, model and supply-chain risks) and build guardrails, sandboxing, and monitoring. * Build identity and access management, secrets management, and least-privilege authorization across services, devices, and the fleet. * Perform threat modeling, security design reviews, and risk assessments for new products and architectures, partnering with engineering teams to remediate findings. * Establish vulnerability management, dependency and supply-chain scanning, and a secure software development lifecycle (SSDLC) across the organization. * Develop detection, logging, and incident response capabilities to identify and respond to security events across onboard and infrastructure environments. * Champion a security-first culture through tooling, automation, documentation, and mentorship. ## Related Videos - [Why segmenting your infrastructure into tiers makes your infrastructure design better](https://www.wearedevelopers.com/videos/1960-why-segmenting-your-infrastructure-into-tiers-makes-your-infrastructure-design-better) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Terraform for Developers](https://www.wearedevelopers.com/videos/3-terraform-for-developers) - [Unleashing Potential Across Teams: The Power of Infrastructure as Code](https://www.wearedevelopers.com/videos/930-unleashing-potential-across-teams-the-power-of-infrastructure-as-code) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)