Security Engineer, Application Security
Job description
About the role
Figure is developing Figure 02, a general purpose humanoid robot intended for both commercial and home use. We are seeking a security professional to join our Security and Privacy team to protect our robot hardware and backend infrastructure. You will work on-site in San Jose to help us build secure systems from the ground up. In this capacity, you will own the security posture of critical backend services and embedded robot components while ensuring alignment with industry best practices. The role requires you to translate ambiguous security requirements into concrete technical implementations across the product lifecycle. You will partner closely with engineers to integrate security controls without compromising system functionality or performance. Your work will directly influence the reliability and trustworthiness of robotic systems that interact with humans in physical environments. This position is instrumental in establishing the security foundation for our next-generation robotics platform.
Key facts
What you'll do
- Conduct in-depth security evaluations of our backend services, business integrations, and embedded systems to uncover potential attack vectors.
- Design and develop internal tooling that supports a secure development lifecycle, enabling automated security checks and rapid vulnerability detection.
- Architect robust technical solutions that address security gaps across our robot and service stack while maintaining scalability and maintainability.
- Create frameworks and standards designed to eliminate entire categories of security vulnerabilities through proactive design principles.
- Analyze source code and system designs to identify insecure coding patterns and perform vulnerability research on our product infrastructure.
- Drive security and privacy standards adoption across the organization by collaborating with cross-functional teams and providing expert guidance.
- Evaluate third-party integrations and APIs to ensure they meet our stringent security and privacy requirements before deployment.
- Perform threat modeling sessions to anticipate potential adversarial scenarios and recommend appropriate countermeasures for robotic systems.
- Assist in the development of security testing methodologies tailored for embedded hardware and connected device ecosystems.
- Support incident response activities by providing technical analysis and contributing to forensic investigations when security events occur.
- Mentor junior engineers on secure coding practices and threat awareness to elevate the overall security maturity of the engineering organization.
- Collaborate with hardware and firmware teams to ensure security considerations are addressed throughout the device lifecycle from manufacturing to decommissioning.
Requirements
- Possess 3+ years of professional experience in application security or a closely related security discipline with demonstrable impact.
- Demonstrate proficiency in software engineering using C, C++, Rust, Golang, or Python with a portfolio of meaningful projects.
- Maintain a demonstrated background in embedded system security, specifically regarding secure boot mechanisms, OTA update processes, or secure identity management.
- Exhibit expertise in at least several of the following domains: penetration testing, vulnerability research, security architecture, hardware security, or secure coding methodologies.
- Show fundamental knowledge of cryptography implementations, mobile security architectures, or web security protocols and standards.
- Hold a BS degree in Computer Science, Information Systems, Engineering, or possess an equivalent amount of relevant technical experience that demonstrates comparable expertise.
- Prove the ability to manage tasks independently while coordinating effectively with various stakeholders across technical and business functions.
- Demonstrate strong written and verbal communication skills with high attention to detail in complex technical environments.
- Exhibit problem-solving capabilities when addressing multifaceted security challenges in interconnected robotic systems.
- Show commitment to continuous learning given the rapidly evolving threat landscape affecting robotics and IoT devices.
Skills & tools
- C/C++
- Rust
- Golang
- Python
- Embedded security (Secure boot, OTA, Secure identity)
- Penetration testing
- Vulnerability research
- Security architecture
Nice to have
- Familiarity with robotics software frameworks and communication protocols used in autonomous systems.
- Knowledge of industrial or consumer IoT security standards and compliance frameworks.
Practical notes
The annual base salary range for this role is $150,000 to $350,000. Final compensation is determined by individual skills, experience, and job-related knowledge. Additional benefits and compensation components may be provided and will be detailed if an offer is extended. Applicants must be authorized to work in the United States without sponsorship for this position, and all employment is contingent upon passing background checks and related screenings. The position requires consistent presence on-site in San Jose, California, five days per week to facilitate collaboration and security oversight.