# Product Security Engineer - QRA

**Company:** [Zoox](https://hotfix.jobs/companies/zoox)
**Location:** Foster City, CA, Seattle, WA, San Diego, CA, Boston, MA
**Role:** Security Engineering
**Salary:** $191k – $271k/yr
**Experience:** 5+ years
**Skills:** Cybersecurity, Systems Engineering, quantitative risk assessment, Threat Modeling, Risk Assessment, epss, monte carlo simulations, bayesian networks, Embedded Systems, ai/llm, iso 21434, unece r155, nist csf, can/lin, cloud architecture
**Posted:** 2026-08-05

> Conducts quantitative security risk assessments, threat modeling, and cybersecurity requirements development for autonomous vehicles and cloud services. Requires a master’s degree, 5+ years of experience, strong systems engineering and cybersecurity expertise, and familiarity with automotive security standards and interfaces.

## Job Description

## Responsibilities
- Perform **Quantitative Risk Assessment (QRA)** by quantifying security-related safety risks and collaborating with cross-functional teams, particularly safety teams, to align safety and security objectives and support risk-informed engineering decisions.
- Conduct security analysis, threat modeling, and risk assessment for a complex product ecosystem comprising a custom-designed vehicle fleet and cloud services.
- Define cybersecurity requirements and maintain a catalog of cybersecurity controls to establish secure baselines.
- Collaborate with Product Security, software engineering, and hardware engineering teams, incorporating engineering constraints into analyses and recommendations.
- Analyze existing and emerging cybersecurity standards, including general and domain-specific standards, and develop adoption plans focused on tangible business impact.

## Requirements
- Master’s degree in computer science or a related engineering field, such as software, hardware, or systems engineering.
- **5+ years of experience.**
- Strong systems engineering background with demonstrated cybersecurity expertise.
- Experience with quantitative risk assessment frameworks, such as EPSS, attack-tree or attack-graph quantification, Monte Carlo simulations, and Bayesian networks.
- Experience analyzing complex embedded systems and translating analysis into high-quality written deliverables.
- Practical use of AI/LLM toolchains for security analysis and authoring regulatory work products.
- Ability to identify and evaluate threats across wireless and wired communication channels in automotive systems.

## Nice-to-Haves
- Practical experience with ISO 21434, UNECE R155, NIST CSF, SOC 2 Type II, or similar frameworks and standards.
- Experience analyzing complex cyber-physical systems and automotive systems-on-chip (SoCs), including on-chip security features and onboard communication interfaces such as UDS, JTAG, CAN/LIN, I2C, and SPI.
- Familiarity with common cloud deployment architectures and frameworks.

## Compensation
- Annual salary range: **$191,000–$271,000**.

## Similar roles

- [Enterprise Security Engineer](https://hotfix.jobs/jobs/c5a8b575-ef52-45c3-ab89-7b19a3a5bb5c) - Benchling - San Francisco, CA - $189k – $256k/yr
- [Detection & Response Security Engineer](https://hotfix.jobs/jobs/d9b874cd-5256-437a-b42b-cacd3aceaaa4) - Harvey - San Francisco, CA - $188k – $282k/yr
- [Product Security Engineer](https://hotfix.jobs/jobs/17d9ed0a-1df5-498e-af1c-1644bd4940e0) - Airtable - Remote - $187k – $260k/yr
- [Security Engineer, Privacy](https://hotfix.jobs/jobs/21a248c5-bba3-4587-adc6-041fbbed1e1a) - Ramp - New York, NY - $185k – $375k/yr
- [Protection Scientist Engineer, Intelligence and Investigations](https://hotfix.jobs/jobs/32daff80-45cb-4724-b0ca-201253f2d967) - OpenAI - San Francisco, CA - $198k – $425k/yr

**Apply:** https://hotfix.jobs/jobs/b17d7fd9-a657-4140-b506-13f20bae7281
**Canonical:** https://hotfix.jobs/jobs/b17d7fd9-a657-4140-b506-13f20bae7281