Product Security Engineer

Rivianvw.tech

2h ago 0 views 0 applications
Full-time Hybrid
Palo Alto, California
$135,100 - $168,900
Full-time
Security Engineer

Job Description

About UsRivian and Volkswagen Group Technologies is a joint venture between two industry leaders with a clear vision for automotive’s next chapter. From operating systems to zonal controllers to cloud and connectivity solutions, we’re addressing the challenges of electric vehicles through technology that will set the standards for software-defined vehicles around the world.The road to the future is uncharted. By combining our expertise across connectivity, AI, security and more, we’ll map a new way forward. Working together, we’ll create a future that’s more connected, more intelligent, more sustainable for everyone.Role SummaryAs the Product Security Engineer, you will work closely with the product security organization, the vehicle software development teams, and cloud engineering teams to create and validate security requirements throughout the vehicles’ development lifecycles. You will play a critical role in ensuring security and resilience of RVT’s products, providing technical leadership in securing vehicles and related infrastructure.ResponsibilitiesDerivation of top-level requirements to security-related system and subsystem requirements: In collaboration with the security architecture team, you’ll decompose high-level requirements into concrete per-system security requirements. Together with the security and other domain development teams, you’ll generate concrete requirement specifications for security technologies that protect our product-related assets.Carrying out validation of security requirements: You will develop security tests, both positive tests and abuse tests to ensure that security requirements have been met at vehicle, system, sub-system and ECU level.Develop both manual and automated test cases: You will develop both functional and non-functional security tests to ensure that security requirements are met. Test cases could be developed in multiple languages, including but not limited to Python, Go, Java, C, C++, and Rust for multiple architectures. You are able to build test cases that can be run on software-in-the-loop (SIL) setups or hardware-in-the-loop (HIL) benches. You’re able to work with internally-developed sources but you can also deal with the validating of supplier parts to meet our requirements without access to source code.Documenting validation testing: You will develop testing reports, triage them and compile results, and share them with the product security team as well as our core JV partners for evidence to enable their documenting compliance to UN R155. You will work with the GRC team on aligning to document formats and following our CSMS processes for generating and sharing this documentation across the organization.Collaborating with software development teams: You will be sharing results with development teams and reviewing issues and suggesting mitigations to failed tests. This includes validating the subsequent fixes and the collaboration with other teams within the product security organization, especially the security engineering team that operate the security HILs.QualificationsB.S. in Information Security, Computer Science, Computer Engineering, or a related field.2+ years carrying out testing and validation of security requirements validation in embedded device development3+ years of experience in Automotive Industry or Embedded device development2+ years of experience carrying out security requirements validation on ECUs (electronic control units)Knowledge of ISO:21434 and UN R155 and their application with regards to security validation to achieve type approval and homologation.Ability to work in a fast-paced development environment.Good team player with excellent communication skills.Hands-on approach, proactively identifying and filling in gaps where neededTotal RewardsTotal compensation packages for full-time positions include base salary, eligibility for an annual performance bonus, and eligibility for equity. In addition, our benefits package has been designed to support the health and wellness of our employees. Benefit offerings include Flex Time Off, retirement savings plans as well as medical, vision and dental coverage. For more information on RV Tech’s comprehensive benefits package for full-time employees, check out our Global Benefits Site.External candidates can apply for this role through the RV Tech Careers site (https://rivianvw.tech/#careers). If you are a current employee, please apply through our internal job board.Equal OpportunityRivian and Volkswagen Group Technologies is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender, gender expression, gender identity, genetic information or characteristics, physical or mental disability, marital/domestic partner status, age, military/veteran status, medical condition, or any other characteristic protected by law. We are also committed to ensuring compliance with all applicable fair employment practice laws regarding citizenship and immigration status.Rivian and Volkswagen Group Technologies is committed to ensuring that our hiring process is accessible for persons with disabilities. If you have a disability or limitation, such as those covered by the Americans with Disabilities Act, that requires accommodations to assist you in the search and application process, please email us at [email protected] Data PrivacyRivian and Volkswagen Group Technologies” may collect, use and disclose your personal information or personal data (within the meaning of the applicable data protection laws) when you apply for employment and/or participate in our recruitment processes (“Candidate Personal Data”). This data includes contact, demographic, communications, educational, professional, employment, social media/website, network/device, recruiting system usage/interaction, security and preference information. Rivian and Volkswagen Group Technologies may use your Candidate Personal Data for the purposes of (i) tracking interactions with our recruiting system; (ii) carrying out, analyzing and improving our application and recruitment process, including assessing you and your application and conducting employment, background and reference checks; (iii) establishing an employment relationship or entering into an employment contract with you; (iv) complying with our legal, regulatory and corporate governance obligations; (v) record keeping; (vi) ensuring network and information security and preventing fraud; and (vii) as otherwise required or permitted by applicable law. Rivian and Volkswagen Group Technologies may share your Candidate Personal Data with (i) internal personnel who have a need to know such information in order to perform their duties, including individuals on our People Team, Finance, Legal, and the team(s) with the position(s) for which you are applying; (ii) Rivian and Volkswagen Group Technologies affiliates; and (iii) Rivian and Volkswagen Group Technologies’ service providers, including providers of background checks, staffing services, and cloud services. Rivian and Volkswagen Group Technologies may transfer or store internationally your Candidate Personal Data, including to or in the United States, Canada, and the European Union and in the cloud, and this data may be subject to the laws and accessible to the courts, law enforcement and national security authorities of such jurisdictions. If you provide a mobile telephone number as part of your application or during the recruitment process, Rivian and Volkswagen Group Technologies may use that number to contact you via SMS text message for recruitment-related purposes, including scheduling, logistics, and status updates. Message and data rates may apply. You may opt out of SMS communications at any time by replying STOP to any text message you receive from us. Consent to receive SMS messages is not a condition of applying for or being considered for employment.Please see our Candidate Data Privacy Notice (English) and Candidate Data Privacy Notice (Serbian) for more information.--Please note this job posting represents an open, active vacancy. Additionally, we are not currently accepting applications from third party application services.