Product Security Engineer
Job description
About the role
Zoox is building a fully autonomous ride-hailing service, and the Product Security Threat Analysis and Security Standards team makes sure security is built into its products from the earliest stages of design. The team conducts structured security analyses of Zoox products and applies security standards judiciously throughout the System Development Life Cycle at Zoox. This role asks for a strong background in systems engineering combined with demonstrated enthusiasm and concrete expertise in cybersecurity. You will analyze automotive systems as a whole, considering the hardware, software, and the communications that connect them, and you will translate your analysis into high-quality written deliverables that engineers and leadership can act on. A core part of the work is identifying and evaluating threats across both wireless and wired communication channels in automotive systems. The position is based in Foster City, California and is full time. This is not a penetration-testing-only role; it is a systems-oriented security role where careful reasoning, clear documentation, and consistent standards application matter as much as technical depth. You will influence how products are designed, reviewed, and released at every stage of development.
Key facts
What you'll do
You will dissect product requirements to uncover security-relevant design decisions and assumptions that may not be immediately obvious. You will apply threat modeling methodologies to automotive architectures, breaking down complex interactions into understandable and actionable threat scenarios. You will evaluate the security posture of vehicle components, including sensors, compute platforms, and in-vehicle networks, to identify potential weaknesses before they ship. You will craft security standards and guidance that translate abstract threats into concrete engineering controls for distributed teams to follow. You will review technical designs and implementations to verify adherence to security policies and best practices across the development lifecycle. You will investigate security-related anomalies and support root cause analysis to ensure that findings lead to durable fixes. You will collaborate with cross-functional partners to integrate security checks seamlessly into existing development workflows and quality gates. You will track the security implications of new technologies and evolving attacker capabilities to keep Zoox defenses ahead of emerging risks. You will produce clear, precise reports that synthesize complex technical findings into recommendations that are understandable for both technical and non-technical stakeholders. You will act as a security specialist during design reviews, ensuring that security controls are validated and that risk trade-offs are consciously chosen.
Requirements
You have a Bachelor's degree in a technical field or equivalent practical experience. You have eight or more years of experience in systems, software, or product security. You have hands-on experience with automotive protocols, embedded systems, or vehicle architectures. You have experience analyzing and documenting threat models for networked systems. You are proficient with at least one programming or scripting language relevant to automation and tooling. You understand secure communication protocols and cryptographic primitives commonly used in connected vehicles. You have experience working with security standards and regulatory frameworks relevant to the automotive industry. You can read and interpret technical design documents, test plans, and architecture diagrams with ease. You communicate complex technical concepts clearly in writing and in conversation with diverse audiences. You are comfortable operating in an environment where requirements evolve quickly and ambiguity is common. You have a track record of owning security reviews and ensuring that findings result in remediations. You are meticulous about details and able to manage multiple security activities across concurrent projects. You understand the importance of building security controls early rather than relying on post-deployment fixes. You are comfortable using security tooling to investigate systems and to validate the effectiveness of implemented controls.
Nice to have
You have experience with penetration testing or red teaming activities in complex systems. You have familiarity with ISO 26262 or other functional safety standards and their interaction with security. You have contributed to open-source security tools or published research in relevant domains. You have experience with hardware security concepts, including secure elements and trusted execution environments. You have worked in highly regulated environments where compliance and audit readiness are critical. You have experience developing security training or enabling engineering organizations through mentorship.
Practical notes
This role is full-time, and the standard work week is forty hours. Some travel may be required, not exceeding ten percent of your time, for activities such as cross-site collaboration or conference attendance. Employment eligibility to work in the United States is required, and no sponsorship is available for this position at this time. The posting will remain open until the role is filled, so early application is encouraged to ensure full consideration.