Staff/Senior Staff Software Engineer - Product Security

Zoox · Foster City, CA

$292k–$375kPosted pay
On-siteWorkplace
1w agoPosted · Sep 10
Company siteSource
$172ksoftware engineer median
Checking…All software engineer jobsPosted on the employer’s own site. Sign in with Google, free, to see who and apply there.
Experience10+ years

Skills in this posting

The posting

Zoox is looking for an AWS Cloud Security Engineer to lead the design and implementation of secure, scalable, and software-defined infrastructure in our AWS cloud environment. This role is responsible for establishing best-in-class security practices across AWS, driving automation-first infrastructure security, and partnering with engineering and platform teams to embed security into every layer of our technology stack.

You’ll act as a security champion, ensuring that infrastructure designs meet the highest standards of confidentiality, integrity, and availability — while maintaining operational efficiency and scalability through Infrastructure as Code (IaC).

In this role, you will

Define and own the multi-year security architecture and roadmap for Zoox's robots and fleet, spanning embedded/firmware, in-vehicle networks, cloud, and supporting infrastructure.

Partner with hardware, firmware, autonomy, and infrastructure engineering teams to embed security requirements into system design from the ground up, rather than bolting them on after the fact.

Lead threat modeling and architecture reviews for new vehicle platforms and major feature launches, identifying and prioritizing systemic risk across the fleet.

Set technical standards and guardrails - secure boot, key management, network segmentation, update/OTA security, and more - and drive their adoption across engineering teams.

Represent Product Security in cross-functional and leadership discussions, translating technical risk into business and safety impact for the organization.

Qualifications

10+ years of experience in security engineering, including significant time in an architect, staff, or technical lead capacity.

Deep expertise in embedded/IoT security, including secure boot, TPM/TEE, cryptographic key management, and hardened firmware/OS design.

Demonstrated experience architecting security for complex, physical/cyber-physical systems (automotive, robotics, aerospace, industrial control, or similar).

Strong track record of driving cross-functional technical strategy and influencing engineering leadership without direct authority.

Solid understanding of network security, cloud security, and secure software development lifecycle practices.

Bonus Qualifications

Experience securing autonomous vehicles, robotics platforms, or other safety-critical connected systems at scale.

Background in offensive security (red teaming, penetration testing) that informs strong architectural/defensive judgment.

Contributions to industry standards, published research, or conference talks in embedded/IoT/automotive security.

The PivotHop read

Where these skills also reach

More software engineer roles

Backfilled listing, refreshed with the nightly scrape; the employer has not claimed it yet. Are you the employer? Claim this listing and it can be featured to the candidates whose skills already reach it, first month free.

© 2026 PivotHopReal data, real career moves