# Senior Product Security Engineer - QRA

**Company:** [Zoox](https://hotfix.jobs/companies/zoox)
**Location:** Foster City, CA, Seattle, WA, San Diego, CA, Boston, MA
**Role:** Security Engineering
**Salary:** $217k – $307k/yr
**Experience:** 7+ years
**Skills:** Cybersecurity, Systems Engineering, quantitative risk assessment, Threat Modeling, epss, monte carlo simulation, bayesian networks, Embedded Systems, iso 21434, unece r155, nist csf, SOC 2, can/lin, cloud architecture, ai/llm
**Posted:** 2026-08-05

> Conduct quantitative risk assessments, threat modeling, and cybersecurity standards analysis across autonomous vehicles and cloud services. The role requires a master’s degree, 7+ years of experience, strong systems and embedded-security expertise, and the ability to produce high-quality technical and regulatory deliverables.

## Job Description

## Responsibilities
- Perform **Quantitative Risk Assessment** by quantifying security-related safety risks and collaborating with cross-functional teams, particularly safety teams, to align safety and security objectives and support risk-informed engineering decisions.
- Conduct security analysis, threat modeling, and risk assessment for a complex product ecosystem comprising a custom vehicle fleet and cloud services.
- Define cybersecurity requirements and maintain a catalog of cybersecurity controls to establish secure baselines.
- Collaborate with Product Security, software engineering, and hardware engineering teams while incorporating engineering constraints into analyses and recommendations.
- Analyze existing and emerging cybersecurity standards and develop adoption plans focused on tangible business impact.

## Requirements
- Master’s degree in computer science or a related software, hardware, or systems engineering field.
- 7+ years of professional experience.
- Strong systems engineering background with demonstrated cybersecurity expertise.
- Experience with quantitative risk assessment frameworks, such as EPSS, attack-tree or attack-graph quantification, Monte Carlo simulations, and Bayesian networks.
- Experience analyzing complex embedded systems and producing high-quality written deliverables.
- Practical use of AI/LLM toolchains for security analysis and authoring regulatory work products.

## Nice-to-Haves
- Practical experience with ISO 21434, UNECE R155, NIST CSF, SOC 2 Type II, or similar frameworks and standards.
- Experience analyzing complex cyber-physical systems and automotive systems-on-chip, including on-chip security features and onboard communication interfaces such as UDS, JTAG, CAN/LIN, I2C, and SPI.
- Familiarity with common cloud deployment architectures and frameworks.

## Similar roles

- [Senior Manager, Identity & Access Management (IAM)](https://hotfix.jobs/jobs/fc24d3c4-b4e5-4235-95be-1440ccc997b5) - Databricks - Mountain View, CA - $217k – $265k/yr
- [Engineering Manager - Security](https://hotfix.jobs/jobs/10984b1c-93a4-44c3-9426-55c3496a93f5) - Plaid - Seattle, WA - $216k – $329k/yr
- [Corporate Security Program Manager](https://hotfix.jobs/jobs/86aef9aa-68f0-414d-a14d-83c4e24585cd) - OpenAI - San Francisco, CA - $216k – $240k/yr
- [Security Engineer, Network](https://hotfix.jobs/jobs/d2d098ff-3230-49b5-bb4f-542f7ba2a14a) - Fluidstack - Austin, TX - $218k – $252k/yr
- [Senior Software Engineer, Identity](https://hotfix.jobs/jobs/2aeb4932-dced-414c-90c7-08eea4824215) - Scale AI - San Francisco, CA - $216k – $270k/yr

**Apply:** https://hotfix.jobs/jobs/016d868c-3522-4a9b-a8fc-6de7e3855a4a
**Canonical:** https://hotfix.jobs/jobs/016d868c-3522-4a9b-a8fc-6de7e3855a4a