Role SummaryThe R1 is on the road today. R2 is close behind it, R3 follows, and the Rivian Adventure Network is expanding underneath all of them. RAP1, our first in-house chip, is in development. Every one of those is a target, and this role covers them: the compute inside the vehicle, the silicon underneath it, the chargers it plugs into, and the data it collects about the people it carries. You will support security and privacy assurance for a domain of Rivian's vehicle systems end to end: in-vehicle platforms and compute, firmware and boot chain, vehicle communications, OTA, or charging infrastructure. Threat models, security requirements, design review, and the technical assessment behind Rivian's position on a design are yours to run in that domain. Rivian's vehicle technology is developed both in-house and with Rivian and Volkswagen Group Technologies (RVT), our joint venture with its own product security organization. You will work across both: setting requirements and reviewing designs for what Rivian builds, and assessing the security of joint platform deliverables that ship in Rivian vehicles. Privacy engineering is part of the work. You will document how vehicle and customer data actually moves through the systems you cover, and specify minimization and retention in the design. This is a hands-on role. You will be in the architecture documents, the firmware, and on the bench. This role will be located in Atlanta, GA and report to ur Sr. Manager of Cybersecurity.
Responsibilities- Own threat modeling and design review for your domain: zonal E/E architecture, ECUs and vehicle compute, firmware, secure boot and chain of trust, key management, vehicle communications, or OTA
- Write the security requirements (functional and non-functional) for the programs in your domain, and drive them to adoption with platform engineering teams
- Map and document data flows through the systems you cover: what is collected, where it goes, how long it persists, who can reach it, then specify the minimization, retention, and deletion requirements that follow
- Build and validate privacy enforcement mechanisms: scrubbing and de-identification of telemetry, sensor, and camera data, consent and deletion handling in embedded and connected systems, and verification that shipped behavior matches the documented design
- Design and review the PKI underneath vehicle systems: device identity and factory provisioning, code and OTA signing, mutual TLS to backend services, Plug and Charge credentials, and certificate lifecycle across the fleet
- Perform the technical review of RVT security deliverables: read the design, test the claims, and produce the assessment Rivian's position rests on
- Analyze product vulnerability reports: reproduce, run variant analysis, and determine exploitability, design impact, and the direction a fix should take
- Author security and privacy engineering standards and reference patterns in your domain, and drive their adoption
- Scope product-targeted security testing with Rivian's offensive security and penetration testing teams, and turn findings into requirements and standards changes
- Participate in joint technical working groups with RVT Product Security on shared and integration attack surface
- Build the tooling that makes review and enforcement repeatable: analysis harnesses, test fixtures, data handling pipelines
Qualifications- 8+ years in security engineering, with substantial hands-on experience in embedded, automotive, or safety-critical product security
- Hands-on capability in several of: firmware analysis and reverse engineering, secure boot and chain of trust, SoC and ECU security (hardware root of trust, TEEs, memory and DMA protection), automotive network protocols and their protection, hardware-backed key management, OTA update security
- Applied PKI experience: key hierarchy design, HSM-backed roots, certificate provisioning and rotation, revocation at scale, and the operational realities of device certificates that outlive the systems issuing them
- Practical privacy engineering experience: data flow documentation, minimization and retention design, or building de-identification, scrubbing, or deletion mechanisms in a shipping product
- Demonstrated ownership of threat modeling and design review for shipping products, including holding a technical position with the engineers who built the system
- Experience driving security requirements into engineering teams you don't manage, and getting them implemented
- Working knowledge of ISO/SAE 21434 and UNECE R155/R156, and the judgment to tell certification evidence from engineering truth
Nice to have- Offensive security background against embedded or vehicle targets: fuzzing, hardware attack, side-channel or fault injection
- Experience with sensor or camera data de-identification, or privacy-preserving telemetry design
- Working knowledge of GDPR, CCPA, and comparable regimes as engineering requirements rather than legal text
- Threat modeling / TARA program experience at an automotive OEM or tier-1
- ISO 15118 Plug and Charge, V2X credential systems, or crypto-agility and post-quantum migration planning for long-lived devices
- Charging infrastructure or high-voltage systems security experience
Pay DisclosureThe salary range for this role is $179,000 - $223,700 for Georgia based applicants. This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An employee's position within the salary range will be based on several factors including, but not limited to, specific competencies, relevant education, qualifications, certifications, experience, skills, geographic location, shift, and organizational needs.
The successful candidate may be eligible for annual performance bonus and equity awards.
We offer a comprehensive package of benefits for full-time and part-time employees, their spouse or domestic partner, and children up to age 26, including but not limited to paid vacation, paid sick leave, and a competitive portfolio of insurance benefits including life, medical, dental, vision, short-term disability insurance, and long-term disability insurance to eligible employees. You may also have the opportunity to participate in Rivian's 401(k) Plan and Employee Stock Purchase Program if you meet certain eligibility requirements. Full-time employee coverage is effective on their first day of employment. Part-time employee coverage is effective the first of the month following 90 days of employment. More information about benefits is available at rivianbenefits.com.