Staff Product Security Engineer

Rivian and Volkswagen Group Technologies

$135K — $160K *
Manufacturing & Automotive
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • M.Sc. in Information Security, Computer Science, Computer Engineering, or a related field.
  • 8+ years of experience in risk analysis, testing, and validating security requirements for embedded devices.
  • 5+ years of experience in the automotive industry or embedded device development.
  • 3+ years of experience in validating security requirements on ECUs (electronic control units).
  • Familiarity with ISO:21434 and UN R155 for security validation and homologation.

Responsibilities

  • Conduct ECU-level and feature-based threat assessments and risk analyses, identifying threats and potential impacts using frameworks like STRIDE or MITRE EMB3D.
  • Work with the security architecture team to translate high-level security requirements into detailed system requirements specifications.
  • Develop and execute security validation tests, both functional and abuse tests, to ensure compliance at various system levels.
  • Create both manual and automated test cases for security validation in multiple programming languages, tailored for software-in-the-loop (SIL) and hardware-in-the-loop (HIL) environments.
  • Compile and document testing results, aligning with CSMS processes and coordinating with GRC for compliance documentation.
  • Review test outcomes with development teams, propose mitigations for failures, and validate fixes in collaboration with cross-functional teams.

Benefits

  • Eligibility for annual performance bonus.
  • Eligibility for equity depending on role and performance.
  • Benefits vary based on local market, offering tailored healthcare, retirement, and wellness options.
Full Job Description
Role Summary:

As the Product Security Engineer, you will work closely with the product security organization, the vehicle software development teams, and cloud engineering teams to drive the product development lifecycle for security-related items. Activities comprise
  • the creation of threat assessments and risk analyzes for ECUs and features in the RVT automotive ecosystem,
  • derivation of top-level requirements to system requirements specifications, creation of test cases
  • creation of UN R155-compliant documentation to support the CSMS homologation activities,
  • pro-active role in the definition of risk treatments, security controls, design and engineering of security technologies.

You will play a critical role in ensuring security and resilience of RVT's products, providing technical leadership in securing vehicles and related infrastructure.

Responsibilities:
  • ECU-level and feature-based threat assessments and risk analyses of ECUs and features: From the assets' definition, identify threat scenarios, calculate risk values, analyze safety, financial, operational, privacy impacts and evaluate the attack potential. Make use of state-of-the-art risk analysis and treatment frameworks like STRIDE or MITRE EMB3D.
  • Derivation of top-level requirements to security-related system and subsystem requirements: In collaboration with the security architecture team, you'll decompose high-level requirements into concrete per-system security requirements. Together with the security and other domain development teams, you'll generate concrete requirement specifications for security technologies that protect our product-related assets.
  • Carrying out validation of security requirements: You will develop security tests, both positive tests and abuse tests to ensure that security requirements have been met at vehicle, system, sub-system and ECU level.
  • Develop both manual and automated test cases: You will develop both functional and non-functional security tests to ensure that security requirements are met. Test cases could be developed in multiple languages, including but not limited to Python, Go, Java, C, C++, and Rust for multiple architectures. You are able to build test cases that can be run on software-in-the-loop (SIL) setups or hardware-in-the-loop (HIL) benches. You're able to work with internally-developed sources but you can also deal with the validating of supplier parts to meet our requirements without access to source code.
  • Documenting validation testing: You will develop testing reports, triage them and compile results, and share them with the product security team as well as our core JV partners for evidence to enable their documenting compliance to UN R155. You will work with the GRC team on aligning to document formats and following our CSMS processes for generating and sharing this documentation across the organization.
  • Collaborating with software development teams: You will be sharing results with development teams and reviewing issues and suggesting mitigations to failed tests. This includes validating the subsequent fixes and the collaboration with other teams within the product security organization, especially the security engineering team that operate the security HILs.


Preferred Qualifications
  • M.Sc. in Information Security, Computer Science, Computer Engineering, or a related field.
  • 8+ years carrying out risk analyzes, testing, and validation of security requirements in embedded device development
  • 5+ years of experience in automotive industry or embedded device development
  • 3+ years of experience carrying out security requirements validation on ECUs (electronic control units)
  • Knowledge of ISO:21434 and UN R155 and their application with regards to security validation to achieve type approval and homologation.
  • Ability to work in a fast-paced development environment.
  • Good team player with excellent communication skills.
  • Hands-on approach, proactively identifying and filling in gaps where needed
Total Rewards

We build the exceptional - and we believe the people doing that work should be rewarded accordingly. In addition to a competitive base salary, full-time positions may be is eligible to participate in our annual company performance bonus program.

Payments are discretionary and not guaranteed; actual amounts depend on company results and the terms of the plan in effect, and require active employment at the time of payout. This role is also eligible for equity in the form of Restricted Stock Units (RSUs), subject to board approval and the terms of our equity incentive plans, including applicable vesting requirements.

In addition to our compensation programs, we invest in our people with a comprehensive benefits package designed to support the health, wellbeing, and financial future for full-time employees - including health coverage, retirement savings, time off, and family planning programs. Offerings vary by country. Learn more about our global benefit programs.

External candidates can apply for this role through the Rivian and Volkswagen Group Technologies careers site (https://rivianvw.tech/#careers). If you are a current employee, please apply through our internal job board.

Please note this job posting represents an open, active vacancy. Additionally, we are not currently accepting applications from third party application services.

Similar Jobs

More Jobs at Rivian and Volkswagen Group Technologies

More Manufacturing & Automotive Jobs

Find similar Staff Product Security Engineer jobs: