Skip to content
ZooxZooxFoster City, CA

Product Security Engineer - QRA

Conducts quantitative security risk assessments, threat modeling, and cybersecurity requirements development for autonomous vehicles and cloud services. Requires a master’s degree, 5+ years of experience, strong systems engineering and cybersecurity expertise, and familiarity with automotive security standards and interfaces.

191k – 271k/yr
Hybrid5+ YOESecurity Engineering

About the role

Responsibilities

  • Perform Quantitative Risk Assessment (QRA) by quantifying security-related safety risks and collaborating with cross-functional teams, particularly safety teams, to align safety and security objectives and support risk-informed engineering decisions.
  • Conduct security analysis, threat modeling, and risk assessment for a complex product ecosystem comprising a custom-designed vehicle fleet and cloud services.
  • Define cybersecurity requirements and maintain a catalog of cybersecurity controls to establish secure baselines.
  • Collaborate with Product Security, software engineering, and hardware engineering teams, incorporating engineering constraints into analyses and recommendations.
  • Analyze existing and emerging cybersecurity standards, including general and domain-specific standards, and develop adoption plans focused on tangible business impact.

Requirements

  • Master’s degree in computer science or a related engineering field, such as software, hardware, or systems engineering.
  • 5+ years of experience.
  • Strong systems engineering background with demonstrated cybersecurity expertise.
  • Experience with quantitative risk assessment frameworks, such as EPSS, attack-tree or attack-graph quantification, Monte Carlo simulations, and Bayesian networks.
  • Experience analyzing complex embedded systems and translating analysis into high-quality written deliverables.
  • Practical use of AI/LLM toolchains for security analysis and authoring regulatory work products.
  • Ability to identify and evaluate threats across wireless and wired communication channels in automotive systems.

Nice-to-Haves

  • Practical experience with ISO 21434, UNECE R155, NIST CSF, SOC 2 Type II, or similar frameworks and standards.
  • Experience analyzing complex cyber-physical systems and automotive systems-on-chip (SoCs), including on-chip security features and onboard communication interfaces such as UDS, JTAG, CAN/LIN, I2C, and SPI.
  • Familiarity with common cloud deployment architectures and frameworks.

Compensation

  • Annual salary range: $191,000–$271,000.

Skills

CybersecuritySystems Engineeringquantitative risk assessmentThreat ModelingRisk Assessmentepssmonte carlo simulationsbayesian networksEmbedded Systemsai/llmiso 21434unece r155nist csfcan/lincloud architecture
Benchling

Enterprise Security Engineer

BenchlingSan Francisco, CA

Enterprise Security Engineer building zero trust architecture, IAM controls, and macOS MDM at a biotech AI platform. Requires 5+ years security/IAM experience with deep Okta and identity protocol expertise.

189k – 256k/yrHybrid5+ YOESecurity Engineering
Harvey

Detection & Response Security Engineer

HarveySan Francisco, CA +1

Offensive-minded blue teamer building and leading Harvey's Detection & Response program. Develop threat scenarios, detection rules, data pipelines on ClickHouse, and lead incident response for their AI platform. Requires 4+ years in security/SRE/software engineering with hands-on incident response and weakness discovery experience.

188k – 282k/yrHybrid4+ YOESecurity Engineering
Airtable

Product Security Engineer

AirtableSan Francisco, CA +3

Builds security frameworks, automated guardrails, and threat modeling for Airtable's platform, focusing on AI/LLM safety and application security. Partners with engineering teams; requires 4+ years product security experience and proficiency in JS/TS/Node.js.

187k – 260k/yrRemote4+ YOESecurity Engineering
Ramp

Security Engineer, Privacy

RampNew York, NY +1

Build privacy-focused primitives, integrate into products, partner on secure designs, and manage data retention/anonymization while tracking legal standards. Requires 4+ years software experience, 2+ years in privacy/security.

185k – 375k/yrHybrid4+ YOESecurity Engineering
OpenAI

Protection Scientist Engineer, Intelligence and Investigations

OpenAISan Francisco, CA +2

Designs and builds systems to proactively detect and enforce against product abuse using data science, ML, and investigations. Collaborates cross-functionally on monitoring new/existing products and responding to critical escalations. Requires 4+ years in technical analysis with SQL/Python.

198k – 425k/yrHybrid4+ YOESecurity Engineering