Full-Time

Sr. Staff Application Security Engineer

Confirmed live in the last 24 hours

Aurora Innovation

Aurora Innovation

1,001-5,000 employees

Develops self-driving technology for vehicles

Robotics & Automation
Automotive & Transportation

Compensation Overview

$254k - $407kAnnually

+ Bonus + Equity Compensation

Senior, Expert

San Francisco, CA, USA

Category
Cybersecurity
IT & Security
Required Skills
Python
Go
Cryptography
C/C++
Linux/Unix

You match the following Aurora Innovation's candidate preferences

Employers are more likely to interview you if you match these preferences:

Degree
Experience
Requirements
  • Ability and desire to write production-quality code in C++, Golang, or Python
  • Foundational knowledge of operating system security for Linux
  • Foundational knowledge of the CWE Top 25
  • Ability to assess software and/or hardware components with and without full knowledge
  • Ability to work well with other assessment members and engineering partners
  • Ability to communicate effectively with technical and non-technical audiences
  • Experience in one or more of the following: risk assessment, threat modeling, incident and emergency response, OS hardening, vulnerability management, pentesting, offensive security or cryptographic protocols and concepts
  • Experience in vulnerability discovery and analysis, design review, and code-level security reviews
  • Experience in, and technical knowledge of security engineering, computer and network security, authentication and security protocols, and applied cryptography
  • Experience with assessment, development, implementation, and documentation of a comprehensive and broad set of security technologies and processes
  • Familiarity with automotive protocols and security standards
  • Experience in Security Assurance / Secure-SDLC processes in an agile / waterfall environment
  • Experience building and evaluating threat models / risk assessments
  • Experience and ability to implement best practices related to cryptographic protocols, infrastructure and network security
  • Minimum 8 years of experience in a security-specific or security-adjacent industry
  • Minimum 2 years of experience in the robotics or automotive industry or equivalent
Responsibilities
  • Perform secure design reviews and threat modeling. Identify and prioritize risks, attack surfaces, and vulnerabilities
  • Perform security code reviews of source code changes and advise developers on remediating vulnerabilities and following secure coding practices
  • Perform technical security assessments and reviews, research, uncover, and reproduce vulnerabilities, design secure protocols and systems, and write tests and fuzzers to drive architecture changes
  • Manage the vulnerability management process and program through triage, prioritization, tracking, remediation, and validation of vulnerabilities from audits, scans and external reports
  • Employ techniques including reverse engineering, fuzzing, and static and/or dynamic analysis
  • Conduct research to identify new and novel attack vectors against Aurora’s products and services
  • Review, develop and document secure operational best practices, and provide security guidance for engineers and various internal and external partners
  • Develop and manage a secure software development lifecycle
  • Develop and manage a bug bounty program
  • Research, recommend, and develop security tools and technologies to strengthen defenses against emerging threats and vulnerabilities
  • Work with Engineering teams and OEMs to ensure successful security assurance of the Aurora Driver platform and services
  • Advocate, guide and mentor both security and non-security engineers to instill security best practices. through secure architecture, design, and development
Desired Qualifications
  • Relevant work experience in offensive security, penetration testing or red teaming
  • Experience implementing various Defense in Depth Strategies to address dynamic threats across various software and hardware stacks
  • Experience evaluating the security of software, hardware and services
  • Foundational knowledge of embedded firmware security and hardware security, preferably in the robotics or automotive space
  • Familiarity with cloud security (AWS) and infrastructure-as-code
  • Familiarity with Trusted Platform Modules, HSMs, and trusted boot
  • A history of giving back to the security industry via open source contributions, published papers, or conference presentations

Aurora Innovation develops self-driving technology aimed at changing how transportation works. Their main product, the Aurora Driver, can be added to different types of vehicles to allow them to drive themselves, transporting both people and goods. Aurora stands out from its competitors by working closely with logistics companies, ridesharing services, and vehicle manufacturers to help them use this technology effectively. This partnership approach not only helps Aurora grow but also improves the safety and efficiency of its partners. The company makes money by licensing its self-driving technology to these partners, providing ongoing support and updates as part of the service. A key feature of Aurora's technology is its advanced sensor system, including FirstLight Lidar, which helps vehicles detect their surroundings more accurately. Aurora's goal is to make transportation safer and more accessible for everyone.

Company Size

1,001-5,000

Company Stage

IPO

Total Funding

$2.6B

Headquarters

Mountain View, California

Founded

2017

Simplify Jobs

Simplify's Take

What believers are saying

  • Partnerships with Nvidia and Continental enhance Aurora's technological capabilities and market reach.
  • New Bozeman facility expands Aurora's LiDAR research and testing capabilities.
  • Strategic partnerships with Toyota, Uber, and Volvo accelerate commercialization of technology.

What critics are saying

  • Regulatory challenges from FMCSA rejection of cab-mounted warning beacons may delay deployment.
  • Uber CEO's resignation from Aurora's board may impact strategic direction and partnerships.
  • Increased competition as Nvidia partners with multiple companies for driverless technology.

What makes Aurora Innovation unique

  • Aurora's FirstLight Lidar offers superior range and speed for autonomous vehicles.
  • The Aurora Driver platform integrates software, hardware, and data for diverse vehicle types.
  • Aurora's Virtual Testing Suite ensures robust and reliable technology before deployment.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Medical, Vision, Life Insurance

Paid leave

Vacation, Holidays & Sick Time

LinkedIn Learning

Aurora Academy

401(k)

Commuter Benefits

Flexible Spending Account

Onsite Food

PerkSpot

Working from Home Support

Emotional & Physical Wellness

Employee Assistance Program

Growth & Insights and Company News

Headcount

6 month growth

-2%

1 year growth

4%

2 year growth

0%
The Trucker
Jan 13th, 2025
Aurora files suit against USDOT over rejection of cab-mounted warning beacons

WASHINGTON - Aurora Innovation has filed suit against the U.S. Department of Transportation (USDOT) and the Federal Motor Carrier Safety Administration (FMCSA) claiming the agency "arbitrarily" rejected the industry's idea for an alternative solution for modern roadside warning devices.

FreightWaves
Jan 10th, 2025
Autonomous Trucks Have A Triangle-Shaped Problem

The autonomous truck battle: Roadside cab-mounted beacons versus triangles(Photo: Jim Allen/FreightWaves)The question of roadside warning devices adds a triangle-shaped wrinkle to autonomous truck makers’ plans after the Federal Motor Carrier Safety Administration recently ruled that Aurora and Waymo did not provide enough data backing their request to ditch the traditional triangular road devices for cab-mounted warning beacons. Aurora and Waymo filed the petition in 2023 seeking a five-year exemption from the required placement of warning devices around stopped commercial motor vehicles (CMVs). Level 4 automated driving systems (ADS) have a unique issue if a roadside event occurs – namely that there would not be a person available to leave the vehicle and place warning devices, which can come in the form of fusees, liquid-burning flares or three bidirectional reflective triangles. For the FMCSA, one of the reasons behind the denial is that the cab-mounted warning beacons are only at the front of the truck, while the flares, fusees or reflective triangles are behind the trailer. In layman’s terms, the concern is that it’s harder to see. FMCSA Deputy Administrator Vinn White said in the denial notice: “One distinction between … warning triangles and the proposed beacons is that warning triangles are placed at the rear of a stopped CMV (in addition to the front), while the proposed beacons are located only at the front of the cab — raising the possibility that drivers see the rear of a stopped CMV before they see the beacons. While applicants contend that the beacons are visible from behind the vehicle, the evidence was inconclusive.”The same notice stated that Waymo commissioned a study to evaluate whether drivers could detect, recognize and respond to certain beacons on a closed test track in daylight and nighttime conditions while simulating a stopped CMV. The study compared driver reactions to cab-mounted warning beacons with reactions to warning triangles and found that the participants preferred the beacons over the triangles. Aurora also did a study observing the reactions of over 7,000 passenger vehicles to the presence of beacons versus warning triangles on public roads with unaware passing motorists traveling at highway speeds

UpAlpha
Jan 9th, 2025
Why Nvidia Stock Remains a Top Pick for Investors

Additionally, Nvidia has partnered with Aurora Innovation (NASDAQ:AUR) and Continental AG (OTC:CTTAF) to develop driverless trucks using the next-gen DRIVE Thor system.

PYMNTS
Jan 7th, 2025
Nvidia Ai To Boost Development Of Autonomous Vehicle Tech

Autonomous vehicles (AVs) are emerging as a use case for artificial intelligence, with Nvidia announcing partnerships with carmakers to develop self-driving technology using its hardware and software platform. “The AV revolution has arrived after so many years, with Waymo’s success and Tesla’s success,” said Nvidia CEO Jensen Huang during a keynote speech at CES 2025 in Las Vegas Monday (Jan. 6). Nvidia and Uber announced in a Monday press release that they will jointly develop AI-powered self-driving technology. Uber will use data from millions of trips taken in its vehicles and pair it with Nvidia’s new generative world foundation model, Cosmos. This enables Uber’s AI systems to train in virtual-world settings

Sharecast
Jan 7th, 2025
Aurora Innovation surges on partnership with Continental, Nvidia

Aurora Innovation surged on Tuesday after it announced a long-term strategic partnership with Continental and Nvidia to deploy driverless trucks at scale.