Jobs
>
Seattle

    Senior Product Security Engineer - Seattle, United States - Aurora CO

    Default job background
    Description

    Who We Are

    Aurora (Nasdaq: AUR) is delivering the benefits of self-driving technology safely, quickly, and broadly to make transportation safer, increasingly accessible, and more reliable and efficient than ever before. The Aurora Driver is a self-driving system designed to operate multiple vehicle types, from freight-hauling semi-trucks to ride-hailing passenger vehicles, and underpins Aurora Horizon and Aurora Connect, its driver-as-a-service products for trucking and ride-hailing. Aurora is working with industry leaders across the transportation ecosystem, including Toyota, FedEx, Volvo Trucks, PACCAR, Uber, Uber Freight, U.S. Xpress, Werner, Covenant, Schneider, and Ryder. For Aurora's latest news, visit and @aurora_inno on Twitter.

    Aurora's Product Security team's mission is to discover, mitigate, and prevent security risks in the software, hardware, and services developed by Aurora.Our team is responsible for ensuring the secure design and implementation of the technology built for the Aurora Driver as well as continually improving the assurance levels of security across all of Aurora's Products. This team is also responsible for performing technical security assessments, threat modeling, security code reviews and vulnerability testing to highlight risk and help various engineering teams and partners to improve security. We work closely with engineers across Aurora as well as 3rd party partners to design and proactively integrate initiatives to enhance security across a wide variety of software or hardware domains and technology stacks.

    We are searching for an experienced Product Security Engineer who is excited to ensure the highest level of security standards for Aurora's products and focus on uncovering security vulnerabilities to reduce risk for the autonomous vehicle platform to join us on this mission.

    In this role, you will

    • Perform technical security assessments and reviews, research, uncover, and reproduce vulnerabilities, design secure protocols and systems, and write tests and fuzzers to drive architecture changes
    • Assess the risks across the Aurora Driver Platform and prioritize high value components (software and/or hardware) for critical and high security vulnerabilities
    • Comfort employing techniques including reverse engineering, fuzzing, and static and/or dynamic analysis
    • Conduct research to identify new and novel attack vectors against Aurora's products and services
    • Review, develop and document secure operational best practices, and provide security guidance for engineers and various internal and external partners

    Required Qualifications

    • Foundational knowledge of operating system security for Linux
    • Foundational knowledge of the CWE Top 25
    • Ability to assess software and/or hardware components with and without full knowledge
    • Ability to work well with other assessment members and engineering partners
    • Ability to communicate effectively with technical and non-technical audiences
    • Experience in one or more of the following: risk assessment, threat modeling, incident and emergency response, OS hardening, vulnerability management, pentesting, offensive security or cryptographic protocols and concepts
    • Experience in vulnerability discovery and analysis, design review, and code-level security reviews
    • Experience in, and technical knowledge of security engineering, computer and network security, authentication and security protocols, and applied cryptography.
    • Experience with assessment, development, implementation, and documentation of a comprehensive and broad set of security technologies and processes
    • Familiarity in Security Assurance / Secure-SDLC processes in an agile / waterfall environment
    • Experience building and evaluating threat models / risk assessments
    • Minimum 6 years of experience in a security-specific or security-adjacent industry

    Desirable Qualifications

    • Relevant work experience in offensive security, penetration testing or red teaming
    • Experience implementing various Defense in Depth Strategies to address dynamic threats across various software and hardware stacks.
    • Ability and desire to write production-quality code in C++, Golang, or Python
    • Experience evaluating the security of software, hardware and services
    • Foundational knowledge of embedded firmware security and hardware security, preferably in the robotics or automotive space
    • Familiarity with cloud security (AWS) and infrastructure-as-code
    • Familiarity with Trusted Platform Modules, HSMs, and trusted boot
    • A history of giving back to the security industry via open source contributions, published papers, or conference presentations

    The base salary range for this position is $196K-$294K per year. Aurora's pay ranges are determined by role, level, and location. Within the range, the successful candidate's starting base pay will be determined based on factors including job-related skills, experience, qualifications, relevant education or training, and market conditions. These ranges may be modified in the future. The successful candidate will also be eligible for an annual bonus, equity compensation, and benefits.

    #LI-CV1

    #Mid-Senior

    Working at Aurora

    At Aurora, we bring together extraordinarily talented and experienced people united by the strength of our values. We operate with integrity, set outrageous goals, and build a culture where we win together — all without any jerks.

    We have offices in several locations across the United States, where we encourage team and cross-functional collaboration. Aurora offers competitive medical, dental, and vision benefits, and additional healthcare support including medical transportation reimbursement, fertility, adoption, and surrogacy benefits. We empower our employees and their families with options to further their unique physical, mental, and financial wellbeing.

    Our Learning and Development offerings include Aurora Academy, where our people learn, develop, and practice the essential skills that drive Aurora's mission, continually up-leveling our team along the way. Our Careers page provides insight into career opportunities at Aurora, and you can find all the latest news on our Blog.

    Safety is central to everything we do. Every employee at Aurora has a role in contributing to safety, every step of the way. We seek candidates who take active responsibility, can contribute to building an atmosphere of trust, and invest in the organization's long-term success by working safely — no matter what.

    We believe that self-driving technology has broad benefits – including increased access to transportation. To realize those benefits, we need a workforce with diverse experiences, insights, and perspectives — a workforce that reflects the communities our technology will serve.

    Aurora is committed to providing access to anyone who seeks information from our website. We invite anyone using assistive technologies, such as a screen reader or Braille reader, to email us at if they experience difficulty using our website. Please describe the accessibility problem and include a URL (if available).

    Aurora considers candidates without regard to their race, color, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, pregnancy status, parent or caregiver status, ancestry, political affiliation, veteran and/or military status, physical or mental disability, or any other status protected by federal or state law. Aurora considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. We are also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, you may contact us at

    For California applicants, information collected and processed as part of your application and any job applications you choose to submit is subject toAurora's California Employment Privacy Policy.

    Diversity, Equity and Inclusion

    At Aurora, every employee is empowered to take an active role in building an inclusive, collaborative, and unified culture that leverages our diverse strengths, perspectives, and backgrounds.

    Transforming how the world moves people and goods involves seeking to understand backgrounds, insights, and lived experiences that differ from our own. One way we accomplish that is with our 15 employee-led Aurora Unified Groups, which support diverse voices and drive inclusive collaboration. We believe that teamwork, belonging, and trust motivate and support our employees to do their best work. As our team grows, we strive to attract and retain exceptional talent that adds new perspectives and experiences and continues to drive innovation. Learn more on our Culture Page.


  • AGS Cyber

    Security Engineer

    3 weeks ago


    AGS Cyber Seattle, United States

    Embedded Security Engineer - Hybrid - Seattle, Washington · The salary base is approximately $130K—170K (dependent on experience), plus an employee stock option plan and additional benefits (401K, etc.). · You MUST be an American citizen or a Green Card Holder. · You MUST have 3+ ...

  • Seed IP Law Group

    Security Engineer

    3 weeks ago


    Seed IP Law Group Seattle, United States

    About Seed IP · Located in Seattle, Washington, in the beautiful Pacific Northwest, Seed Intellectual Property Law Group is one of the country's leading intellectual property law firms. We are a dynamic, team-oriented firm that maintains a professional and well-balanced working e ...

  • Figma

    Security Engineer

    3 weeks ago


    Figma Seattle, United States

    Figma is growing our team of passionate people on a mission to make design accessible to all. Born on the Web, Figma helps entire product teams brainstorm, design and build better products - from start to finish. Whether it's consolidating tools, simplifying workflows, or collabo ...

  • Tik Tok

    Security Engineer

    1 week ago


    Tik Tok Seattle, United States

    Responsibilities · TikTok is the leading destination for short-form mobile video. Our mission is to inspire creativity and bring joy. TikTok has global offices including Los Angeles, New York, London, Paris, Berlin, Dubai, Singapore, Jakarta, Seoul and Tokyo. · Why Join UsAt Ti ...

  • Circle

    Security Engineer

    1 week ago


    Circle Seattle, United States

    Circle is a financial technology company at the epicenter of the emerging internet of money, where value can finally travel like other digital data — globally, nearly instantly and less expensively than legacy settlement systems. This ground-breaking new internet layer opens up p ...

  • Hive

    Security Engineer

    5 days ago


    Hive Seattle, United States

    About Hive · Hive is the leading provider of cloud-based AI solutions to understand, search, and generate content, and is trusted by hundreds of the world's largest and most innovative organizations. The company empowers developers with a portfolio of best-in-class, pre-trained ...

  • Connection

    Security Engineer

    2 weeks ago


    Connection Seattle, United States

    Job Description · Job Description · Connection has a fantastic opportunity through our Technical Staffing division for a Security Engineer in Seattle, WA. · This is a fulltime opportunity and offers outstanding benefits. · Responsibilities & Duties · Participate in the Scrum f ...

  • Connection

    Security Engineer

    2 weeks ago


    Connection Seattle, United States

    Job Description · Job DescriptionConnection has a fantastic opportunity through our Technical Staffing division for a Security Engineer in Seattle, WA. This is a fulltime opportunity and offers outstanding benefits. · Responsibilities & Duties · Participate in the Scrum framework ...

  • Connection

    Security Engineer

    2 weeks ago


    Connection Seattle, United States

    Job Description · Job DescriptionConnection has a fantastic opportunity through our Technical Staffing division for a Security Engineer in Seattle, WA. This is a fulltime opportunity and offers outstanding benefits. · Responsibilities & Duties · Participate in the Scrum framework ...


  • Amazon Inc Seattle, United States

    At Amazon Healthcare Security, we are on a mission to make healthcare secure and easy. We are developing a patient-centric healthcare experience that is personal, transparent, and convenient. We are looking for a Senior Security Engineer to join our Security Engineer, Security, H ...


  • Block Seattle, United States Full time

    Company Description · Block is one company built from many blocks, all united by the same purpose of economic empowerment. The blocks that form our foundational teams - People, Finance, Counsel, Hardware, Information Security, Platform Infrastructure Engineering, and more - provi ...


  • Amazon Seattle, United States

    Amazon Payments processes millions of transactions every day across numerous countries and payment methods. Over 100 million customers and merchants send tens of billions of dollars through our systems annually. We are re-inventing the vision of our platform to provide our intern ...


  • Amazon Seattle, WA, United States

    This role can be in Seattle, WA, Austin, TX, New Jersey, San Francisco, CA or Sunnyvale, CA. Physical Retails Stores (PRS) Security Engineering (PRS-SecEng) team is responsible for ensuring all applications running in PRS meet Amazon security bar. Our scope includes all applicati ...


  • Amazon Seattle, United States

    · Amazon Payments processes millions of transactions every day across numerous countries and payment methods. Over 100 million customers and merchants send tens of billions of dollars through our systems annually. We are re-inventing the vision of our platform to provide our int ...


  • Amazon Seattle, United States

    · At Amazon Healthcare Security, we are on a mission to make healthcare secure and easy. We are developing a patient-centric healthcare experience that is personal, transparent, and convenient. We are looking for a Senior Security Engineer to join our team. · As a Senior Securit ...


  • Zonar Systems Seattle, United States

    *This is a Seattle based role | Hybrid (1x/week in office)* · Zonar Systems, a leading technology firm in Seattle, is on the lookout for qualified candidates to fill the role of IT Security Engineer. We've designed this versatile role for a proactive and dynamic professional who ...


  • Tik Tok Seattle, United States

    TikTok is the leading destination for short-form mobile video. Our mission is to inspire creativity and bring joy. TikTok has global offices including Los Angeles, New York, London, Paris, Berlin, Dubai, Singapore, Jakarta, Seoul and Tokyo. Why Join Us Creation is the core of Tik ...


  • Meta Inc Seattle, United States

    Summary: · Meta's Enterprise Engineering Application Security team is seeking a passionate security engineer with a hacker mindset who derives purpose in life by revealing potential weaknesses and then crafting creative solutions to eliminate those weaknesses. Your skills will b ...


  • Palantir Technologies Seattle, WA, United States

    Seattle, WAInformation Security /Full-time/ HybridA World-Changing CompanyPalantir builds the world's leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, f ...


  • Insight Global Seattle, United States

    Location: Hybrid - 3 days/week onsite in Seattle, WA, Burbank, CA, or Orlando, FL · Duration: 5 month contract (plus extensions) · Must Haves: · 1+ year of professional experience in Cyber Security role · Security Certification strongly preferred (Security+ or similar) · Knowledg ...