Staff Product Security Engineer - Automotive Cyber
Overview
You will own security validation for ECUs and features in the Rivian-VW joint venture, driving threat assessments and risk analyses across the automotive ecosystem. You'll collaborate with vehicle software and cloud teams to decompose top-level requirements into concrete system specifications, ensuring security is built into every layer. Your work will directly support UN R155 compliance and CSMS homologation, and you'll provide technical leadership in securing vehicles and infrastructure. This role stands out by combining deep embedded security expertise with hands-on test development across SIL and HIL environments, shaping the security posture of next-generation software-defined vehicles.
What You'll Do8
- 1Conduct ECU-level threat assessments and risk analyses, identifying threat scenarios, calculating risk values, and analyzing safety, financial, operational, and privacy impacts using STRIDE and MITRE EMB3D frameworks.
- 2Decompose top-level security requirements into system and subsystem specifications with the security architecture team, producing concrete requirement specifications for ECU and cloud security technologies.
- 3Design and execute security validation tests, including positive and abuse tests, at vehicle, system, subsystem, and ECU levels to ensure requirements are met.
- 4Develop automated and manual test cases in languages such as Python, Go, Java, C, C++, and Rust for multiple architectures, running on SIL setups or HIL benches.
- 5Validate supplier parts without source code access, ensuring they meet security requirements through black-box testing techniques.
- 6Document validation testing, triage results, and compile reports for the product security team and JV partners to support UN R155 compliance evidence.
- 7Collaborate with software development teams to review failed tests, suggest mitigations, and validate subsequent fixes, working closely with the security engineering team operating the security HILs.
- 8Drive risk treatment and security control definitions, proactively identifying gaps in the product development lifecycle and proposing concrete improvements.
Requirements8
- 1M.Sc. in Information Security, Computer Science, Computer Engineering, or related field.
- 28+ years carrying out risk analyses, testing, and validation of security requirements in embedded device development.
- 35+ years of experience in automotive industry or embedded device development.
- 43+ years of experience carrying out security requirements validation on ECUs.
- 5In-depth knowledge of ISO 21434 and UN R155 and their application to security validation for type approval and homologation.
- 6Hands-on experience with SIL and HIL testing methodologies and tools.
- 7Proficiency in Python, Go, Java, C, C++, or Rust for test automation.
- 8Strong team collaboration and communication skills, with a proactive approach to identifying and filling gaps.
Salary Insight
$206 - $258k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.

Apex Systems
VerifiedCybersecurity Key Provisioning Process Engineer, Automotive
Own the end-to-end cryptographic key provisioning process across every ECU and vehicle program at a major automotive OEM. You will define how key material is generated, distributed, and protected in manufacturing, bridging cryptographic security with automotive engineering. Join the Vehicle Cybersecurity organization and collaborate with cross-functional teams to harden production lines against threats. This role's impact scales directly to vehicle safety and brand trust, making it a rare blend of embedded security and industrial process design.

Miracle Software Systems, Inc.
VerifiedCybersecurity Key Provisioning Engineer, Automotive
Own the end-to-end cryptographic key provisioning process for every ECU across all vehicle programs. You will define secure provisioning workflows, collaborate with cross-functional teams spanning security architecture, manufacturing, and quality, and ensure compliance with industry standards. This role uniquely blends automotive engineering, cryptographic security, and manufacturing operations to safeguard vehicle cybersecurity. You will directly shape the security posture of millions of vehicles on the road.
Rivianvw.Tech
VerifiedSystems Integration Engineer Rivianvw.Tech
Lead integration of vehicle behaviors across software hardware and diagnostics domains. Ensure feature correctness in real world environments. Drive product quality launch readiness and user experience.
Microchip Technology
VerifiedSenior Engineer II Product Security Microchip Technology
Lead the Product Security Engineer team at Microchip Technology's Product Security Office. Own vulnerability management and PSIRT operations while driving security standards and regulatory compliance across hardware firmware and software products. Shape the security posture of a globally recognized semiconductor leader.
General Motors LLC
VerifiedSecure Development Manager GM - Cybersecurity Leadership
Lead the Secure Development & Application Security function at General Motors to embed security controls into engineering workflows. This role drives scalable security practices across modern software environments while improving risk reduction and engineering collaboration. The manager will shape operational performance and foster cross-functional partnerships.
greenlight
VerifiedStaff Product Security Engineer, AI & Cloud Security
You will own end-to-end security for consumer products, a digital platform, and an emerging hardware line at Greenlight, a fintech serving 6.5 million family members. You will drive threat modeling, lead penetration testing, manage PSIRT operations, and champion secure AI adoption across the company. Collaborating with architects, product managers, and engineering, you will define security guardrails for AI-powered products and development workflows. This role offers a rare blend of hands-on technical work and strategic influence in a highly regulated financial environment.