Senior Product Security Engineer - QRA
Conduct quantitative risk assessments, threat modeling, and cybersecurity standards analysis across autonomous vehicles and cloud services. The role requires a master’s degree, 7+ years of experience, strong systems and embedded-security expertise, and the ability to produce high-quality technical and regulatory deliverables.
$217k – $307k/yr
Hybrid7+ YOESecurity Engineering
About the job
Responsibilities
- Perform Quantitative Risk Assessment by quantifying security-related safety risks and collaborating with cross-functional teams, particularly safety teams, to align safety and security objectives and support risk-informed engineering decisions.
- Conduct security analysis, threat modeling, and risk assessment for a complex product ecosystem comprising a custom vehicle fleet and cloud services.
- Define cybersecurity requirements and maintain a catalog of cybersecurity controls to establish secure baselines.
- Collaborate with Product Security, software engineering, and hardware engineering teams while incorporating engineering constraints into analyses and recommendations.
- Analyze existing and emerging cybersecurity standards and develop adoption plans focused on tangible business impact.
Requirements
- Master’s degree in computer science or a related software, hardware, or systems engineering field.
- 7+ years of professional experience.
- Strong systems engineering background with demonstrated cybersecurity expertise.
- Experience with quantitative risk assessment frameworks, such as EPSS, attack-tree or attack-graph quantification, Monte Carlo simulations, and Bayesian networks.
- Experience analyzing complex embedded systems and producing high-quality written deliverables.
- Practical use of AI/LLM toolchains for security analysis and authoring regulatory work products.
Nice-to-Haves
- Practical experience with ISO 21434, UNECE R155, NIST CSF, SOC 2 Type II, or similar frameworks and standards.
- Experience analyzing complex cyber-physical systems and automotive systems-on-chip, including on-chip security features and onboard communication interfaces such as UDS, JTAG, CAN/LIN, I2C, and SPI.
- Familiarity with common cloud deployment architectures and frameworks.
Skills
CybersecuritySystems EngineeringQuantitative Risk AssessmentThreat ModelingEpssMonte Carlo SimulationBayesian NetworksEmbedded SystemsIso 21434Unece R155Nist CsfSOC 2Can/LinCloud ArchitectureAi/Llm