Full-Time

Sr. Staff Application Security Engineer

Posted on 7/30/2024

Aurora Innovation

Aurora Innovation

1,001-5,000 employees

Develops self-driving technology for vehicles

Compensation Overview

$254k - $407k/yr

+ Bonus + Equity Compensation

Senior, Expert

San Francisco, CA, USA

In Person

Category
Cybersecurity
IT & Security
Required Skills
Python
Go
Cryptography
C/C++
Linux/Unix
Requirements
  • Ability and desire to write production-quality code in C++, Golang, or Python
  • Foundational knowledge of operating system security for Linux
  • Foundational knowledge of the CWE Top 25
  • Ability to assess software and/or hardware components with and without full knowledge
  • Ability to work well with other assessment members and engineering partners
  • Ability to communicate effectively with technical and non-technical audiences
  • Experience in one or more of the following: risk assessment, threat modeling, incident and emergency response, OS hardening, vulnerability management, pentesting, offensive security or cryptographic protocols and concepts
  • Experience in vulnerability discovery and analysis, design review, and code-level security reviews
  • Experience in, and technical knowledge of security engineering, computer and network security, authentication and security protocols, and applied cryptography
  • Experience with assessment, development, implementation, and documentation of a comprehensive and broad set of security technologies and processes
  • Familiarity with automotive protocols and security standards
  • Experience in Security Assurance / Secure-SDLC processes in an agile / waterfall environment
  • Experience building and evaluating threat models / risk assessments
  • Experience and ability to implement best practices related to cryptographic protocols, infrastructure and network security
  • Minimum 8 years of experience in a security-specific or security-adjacent industry
  • Minimum 2 years of experience in the robotics or automotive industry or equivalent
Responsibilities
  • Perform secure design reviews and threat modeling. Identify and prioritize risks, attack surfaces, and vulnerabilities
  • Perform security code reviews of source code changes and advise developers on remediating vulnerabilities and following secure coding practices
  • Perform technical security assessments and reviews, research, uncover, and reproduce vulnerabilities, design secure protocols and systems, and write tests and fuzzers to drive architecture changes
  • Manage the vulnerability management process and program through triage, prioritization, tracking, remediation, and validation of vulnerabilities from audits, scans and external reports
  • Employ techniques including reverse engineering, fuzzing, and static and/or dynamic analysis
  • Conduct research to identify new and novel attack vectors against Aurora’s products and services
  • Review, develop and document secure operational best practices, and provide security guidance for engineers and various internal and external partners
  • Develop and manage a secure software development lifecycle
  • Develop and manage a bug bounty program
  • Research, recommend, and develop security tools and technologies to strengthen defenses against emerging threats and vulnerabilities
  • Work with Engineering teams and OEMs to ensure successful security assurance of the Aurora Driver platform and services
  • Advocate, guide and mentor both security and non-security engineers to instill security best practices. through secure architecture, design, and development
Desired Qualifications
  • Relevant work experience in offensive security, penetration testing or red teaming
  • Experience implementing various Defense in Depth Strategies to address dynamic threats across various software and hardware stacks
  • Experience evaluating the security of software, hardware and services
  • Foundational knowledge of embedded firmware security and hardware security, preferably in the robotics or automotive space
  • Familiarity with cloud security (AWS) and infrastructure-as-code
  • Familiarity with Trusted Platform Modules, HSMs, and trusted boot
  • A history of giving back to the security industry via open source contributions, published papers, or conference presentations

Aurora Innovation develops self-driving technology to change how transportation works. Their main product, the Aurora Driver, can be added to different types of vehicles to allow them to drive themselves, transporting both people and goods. Aurora stands out from competitors by working closely with logistics companies, ridesharing services, and vehicle manufacturers to help them use this technology effectively. They also have a unique Virtual Testing Suite that allows for thorough testing of their technology before it is used on the road. Aurora's advanced sensor system, including FirstLight Lidar, helps their vehicles detect and understand their surroundings better than many others in the market. The company's goal is to make transportation safer and more accessible for everyone.

Company Size

1,001-5,000

Company Stage

IPO

Headquarters

Mountain View, California

Founded

2017

Simplify Jobs

Simplify's Take

What believers are saying

  • Aurora's launch of autonomous trucking in Texas positions it as a U.S. market leader.
  • Partnership with Nvidia enhances Aurora's technological capabilities and market competitiveness.
  • Arrowstreet Capital's investment indicates strong financial backing and growth potential.

What critics are saying

  • Legal challenges with USDOT could delay deployment and increase operational costs.
  • Rejection of alternative warning devices highlights potential regulatory hurdles for Aurora.
  • Intensifying competition in autonomous trucking could dilute Aurora's market share.

What makes Aurora Innovation unique

  • Aurora's FirstLight Lidar offers superior range and speed in detecting surroundings.
  • The Aurora Driver integrates software, hardware, and data services for autonomous vehicle operation.
  • Aurora's Safety Case Framework is inspired by aviation and nuclear industry protocols.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Medical, Vision, Life Insurance

Paid leave

Vacation, Holidays & Sick Time

LinkedIn Learning

Aurora Academy

401(k)

Commuter Benefits

Flexible Spending Account

Onsite Food

PerkSpot

Working from Home Support

Emotional & Physical Wellness

Employee Assistance Program

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

1%
Electrive
May 9th, 2025
Aurora launches autonomous heavy goods vehicles in Texas

Aurora Innovation recently launched a regular transport service with self-driving articulated trucks on the north-south corridor between Houston and Dallas.

West Island Blog
May 2nd, 2025
Breakthrough or Breakdown? Aurora's Driverless Trucking Milestone Shadows Mysterious Moves and Market Turmoil

Aurora Innovation has officially launched the United States' first commercial, fully autonomous trucking service, fulfilling a promise that the company had deferred since its initial announcement for a 2024 launch date.

Men's Insider
May 1st, 2025
Aurora Unveils Commercial Self-Driving Truck Service in Texas

Aurora Innovation launches driverless truck service in Texas.

ETF Daily News
Apr 12th, 2025
Arrowstreet Capital Limited Partnership Makes New $1.36 Million Investment in Aurora Innovation, Inc. (NASDAQ:AUR)

Arrowstreet Capital Limited Partnership makes new $1.36 million investment in Aurora Innovation, Inc. (NASDAQ:AUR).

FreightWaves
Mar 27th, 2025
Aurora Unveils Safety Blueprint Ahead Of Driverless Truck Debut

Aurora Innovation, a frontrunner in autonomous trucking technology, recently released its Driverless Safety Report, laying out its road map for deploying its self-driving trucks on public highways. The 75-page document, published ahead of the company’s planned commercial launch in Texas, is part of Aurora’s efforts to finalize a safety framework for its Dallas-to-Houston freight lane. Aurora describes the closing of its safety case as a critical step toward rolling out driverless operations.The Pittsburgh-based company claims to be the first to have developed a Safety Case Framework applicable to both trucks and passenger vehicles, adding the approach has gained traction among other autonomous vehicle developers. The framework, inspired by safety protocols in aviation and nuclear industries, offers a structured argument – backed by data – that its trucks can operate safely under defined conditions.Aurora’s safety ethos shapes everything from product design to corporate strategy, says Chief Safety Officer Nat Beuse.“At Aurora, our philosophy isn’t just safety first – it’s safety always,” said Beuse. “Our safety approach spans both product and organization, and in this report, we’ve shared a behind-the-scenes look into our safety systems. With the launch of the Aurora Driver, the world will experience driverless trucks safely delivering freight on public roads for the first time.”The company’s methodology includes extensive hazard analysis, safety requirement development, and a blend of real-world and virtual testing

INACTIVE