Sr. Staff Application Security Engineer

3 weeks ago


Pittsburgh, Pennsylvania, United States Aurora CO Full time

Who We Are

Aurora's mission is to deliver the benefits of self-driving technology safely, quickly, and broadly to make transportation safer, increasingly accessible, and more reliable and efficient than ever before. The Aurora Driver will create a new era in mobility and logistics, one that will bring a safer, more efficient, and more accessible future to everyone.

At Aurora, you'll solve massively complex problems alongside other passionate, smart people, growing as an expert while broadening your field of knowledge. For Aurora's latest news, visit aurora.tech or follow us on LinkedIn.

Aurora hires talented people with diverse backgrounds who are ready to help build a transportation ecosystem that will make our roads safer, get crucial goods where they need to go, and make mobility more efficient and accessible for all.  Aurora's Product Security team's mission is to discover, mitigate, and prevent security risks in the software, hardware, and services developed by Aurora.  Our team is responsible for ensuring the secure design and implementation of the technology built for the Aurora Driver as well as continually improving the assurance levels of security across all of Aurora's Products.  This team is also responsible for performing technical security assessments, threat modeling, security code reviews and vulnerability testing to highlight risk and help various engineering teams and partners to improve security.  We work closely with engineers across Aurora as well as 3rd party partners to design and proactively integrate initiatives to enhance security across a wide variety of software or hardware domains and technology stacks.  We are searching for an experienced Security Engineer with strong application security experience that is excited to lead and improve the overall application security posture for the autonomous vehicle platform to join us on this mission.

In this role, you will

  • Perform secure design reviews and threat modeling. Identify and prioritize risks, attack surfaces, and vulnerabilities
  • Perform security code reviews of source code changes and advise developers on remediating vulnerabilities and following secure coding practices
  • Perform technical security assessments and reviews, research, uncover, and reproduce vulnerabilities, design secure protocols and systems, and write tests and fuzzers to drive architecture changes
  • Manage the vulnerability management process and program through triage, prioritization, tracking, remediation, and validation of vulnerabilities from audits, scans and external reports
  • Employ techniques including reverse engineering, fuzzing, and static and/or dynamic analysis
  • Conduct research to identify new and novel attack vectors against Aurora's products and services
  • Review, develop and document secure operational best practices, and provide security guidance for engineers and various internal and external partners 
  • Develop and manage a secure software development lifecycle
  • Develop and manage a bug bounty program
  • Research, recommend, and develop security tools and technologies to strengthen defenses against emerging threats and vulnerabilities
  • Work with Engineering teams and OEMs to ensure successful security assurance of the Aurora Driver platform and services
  • Advocate, guide and mentor both security and non-security engineers to instill security best practices. through secure architecture, design, and development

Required Qualifications

  • Ability and desire to write production-quality code in C++, Golang, or Python
  • Foundational knowledge of operating system security for Linux
  • Foundational knowledge of the CWE Top 25
  • Ability to assess software and/or hardware components with and without full knowledge
  • Ability to work well with other assessment members and engineering partners
  • Ability to communicate effectively with technical and non-technical audiences
  • Experience in one or more of the following: risk assessment, threat modeling, incident and emergency response, OS hardening, vulnerability management, pentesting, offensive security or cryptographic protocols and concepts
  • Experience in vulnerability discovery and analysis, design review, and code-level security reviews
  • Experience in, and technical knowledge of security engineering, computer and network security, authentication and security protocols, and applied cryptography
  • Experience with assessment, development, implementation, and documentation of a comprehensive and broad set of security technologies and processes
  • Familiarity with automotive protocols and security standards
  • Experience in Security Assurance / Secure-SDLC processes in an agile / waterfall environment
  • Experience building and evaluating threat models / risk assessments
  • Experience and ability to implement best practices related to cryptographic protocols, infrastructure and network security
  • Minimum 8 years of experience in a security-specific or security-adjacent industry
  • Minimum 2 years of experience in the robotics or automotive industry or equivalent

Desirable Qualifications 

  • Relevant work experience in offensive security, penetration testing or red teaming
  • Experience implementing various Defense in Depth Strategies to address dynamic threats across various software and hardware stacks
  • Experience evaluating the security of software, hardware and services
  • Foundational knowledge of embedded firmware security and hardware security, preferably in the robotics or automotive space
  • Familiarity with cloud security (AWS) and infrastructure-as-code
  • Familiarity with Trusted Platform Modules, HSMs, and trusted boot
  • A history of giving back to the security industry via open source contributions, published papers, or conference presentations

The base salary range for this position is $229k-$366K per year. Aurora's pay ranges are determined by role, level, and location. Within the range, the successful candidate's starting base pay will be determined based on factors including job-related skills, experience, qualifications, relevant education or training, and market conditions. These ranges may be modified in the future. The successful candidate will also be eligible for an annual bonus, equity compensation, and benefits.

#LI-SP1

#Mid-Senior

Aurora considers candidates without regard to their race, color, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, pregnancy status, parent or caregiver status, ancestry, political affiliation, veteran and/or military status, physical or mental disability, or any other status protected by federal or state law. Aurora considers qualified applicants with criminal histories, consistent with applicable federal, state, and local law. We are also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, you may contact us at careersiteaccommodations@aurora.tech.

For California applicants, information collected and processed as part of your application and any job applications you choose to submit is subject to Aurora's California Employment Privacy Policy.

To learn more about life at Aurora please visit our company culture page.


  • Applications Engineer

    3 weeks ago


    Pittsburgh, Pennsylvania, United States Securitas Electronic Security Inc Full time

    Securitas Technology, part of Securitas, is a world-leading provider of integrated security solutions that protect, connect and optimize businesses of all types and sizes. More than 13,000 colleagues in 40 countries are focused daily on our purpose to help make your world a safer place and our commitment to deliver an unparalleled client experience. With...


  • Pittsburgh, Pennsylvania, United States Ivalua Full time

    A "Magic Quadrant" leader, Ivalua's solutions work in a complex global economy. Our innovative Source-to-Pay solutions include automating customized workflows to source, contract, request, procure, receive, and pay for goods and services across the enterprise, refining the procurement lifecycle while reducing cost and risk of spending on indirect goods,...


  • Pittsburgh, Pennsylvania, United States Fortive Full time

    Title: Sr. Cyber Defense EngineerJob Description:We are looking for a new role of Sr. Cyber Defense Engineer to join our Security Operations Center (SOC) team. As a Sr. Cyber Defense Analyst, you will be responsible for leading and improving our SOC capabilities, including Incident Response, Threat Intelligence, and Detection Engineering. You will also be a...


  • Pittsburgh, Pennsylvania, United States Ivalua Full time

    Senior Application Security Engineer(Pittsburgh - USA)Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions.COMPANY OVERVIEWAt Ivalua we are a global community of exceptional professionals, who believe that digital transformation revolutionizes supply chain sustainability and resiliency to unlock the power of supplier...


  • Pittsburgh, Pennsylvania, United States Ivalua Full time

    Senior Application Security Engineer(Pittsburgh - USA)Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions.


  • Pittsburgh, Pennsylvania, United States Carnegie Mellon University Full time

    The Computing Services central IT department provides services that have a strategic impact on university goals. We make service decisions based on interaction and valuable input from colleagues engaged in the education, research, and administration efforts of the university. We are a learning organization and approach successes and mistakes as a learning...


  • Pittsburgh, Pennsylvania, United States Carnegie Mellon University Full time

    The Computing Services central IT department provides services that have a strategic impact on university goals. We make service decisions based on interaction and valuable input from colleagues engaged in the education, research, and administration efforts of the university. We are a learning organization and approach successes and mistakes as a learning...


  • Pittsburgh, Pennsylvania, United States Carnegie Mellon University Full time

    The Computing Services central IT department provides services that have a strategic impact on university goals. We make service decisions based on interaction and valuable input from colleagues engaged in the education, research, and administration efforts of the university. We are a learning organization and approach successes and mistakes as a learning...


  • Pittsburgh, Pennsylvania, United States Carnegie Mellon University Full time

    The Computing Services central IT department provides services that have a strategic impact on university goals. We make service decisions based on interaction and valuable input from colleagues engaged in the education, research, and administration efforts of the university. We are a learning organization and approach successes and mistakes as a learning...


  • Pittsburgh, Pennsylvania, United States Futran Tech Solutions Pvt. Ltd. Full time

    472971:Cloud Application Engineer-Security:Pittsburg,PA:Full time:$125K/yr:OnsiteGood cloud security architect with design experience preferably with Azure IoT hub knowledge, authentication techniques, Strong on cloud security: Azure cloud (primary). Analyze threats associated from device to cloud. Cloud security compliance with Azure security benchmarks...


  • Pittsburgh, Pennsylvania, United States Gpac Full time

    Sr Application Analyst / Project SpecialistA local credit union is looking to add another member to their banking family. They are seeking a Sr Application Analyst / Project Specialist to assist clients with back office support. This opportunity would be great for a community-minded individual that appreciates the flexibility and excellent culture this...


  • Pittsburgh, Pennsylvania, United States gpac Full time

    Job Description Sr Application Analyst / Project Specialist A local credit union is looking to add another member to their banking family. They are seeking a Sr Application Analyst / Project Specialist to assist clients with back office support. This opportunity would be great for a community-minded individual that appreciates the flexibility and excellent...


  • Pittsburgh, Pennsylvania, United States PNC Financial Services Group Full time

    Job Profile Position Overview At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute...


  • Pittsburgh, Pennsylvania, United States PNC Full time

    Position Overview At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. As a(n) [position title] within PNC's [name of division] organization, you will be based in [city/state location of position].Job ProfilePosition OverviewAt PNC, our...


  • Pittsburgh, Pennsylvania, United States Securitas Electronic Security Inc Full time

    About the RoleWe are seeking a highly skilled Applications Engineer to join our team at Securitas Electronic Security Inc. As an Applications Engineer, you will play a crucial role in formulating engineered estimates and budgets for new and existing clients.You will be responsible for interfacing with various stakeholders, including account managers,...


  • Pittsburgh, Pennsylvania, United States WNA Engineering Full time

    WNA Engineering is a multi-faceted construction engineering design firm where we hold pride with our motto:Partnerships by DesignAs we continue to grow, we embrace our roots by embodying the beginnings of our company culture, creating, and thriving in a relaxed, inclusive environment. This is where our team works together to deliver the top priority for our...

  • Data Engineer Sr

    4 weeks ago


    Pittsburgh, Pennsylvania, United States PNC Financial Services Group Full time

    Job Profile Position Overview At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute...


  • Pittsburgh, Pennsylvania, United States Securitas Electronic Security Inc Full time

    About the JobWe are seeking an experienced Applications Engineer to join our team at Securitas Electronic Security Inc. The successful candidate will be responsible for developing project requirements, configuring and quoting security systems, and estimating installation costs.You will work closely with clients, stakeholders, and internal teams to deliver...


  • Pittsburgh, Pennsylvania, United States Saxon AI Full time

    Sr. Azure Cloud Engineer Lake Mary, FL/Pittsburgh, PARequired Skills & Qualifications:5+ years of experience in cloud engineering with a strong focus on Azure.Expertise in Windows and Linux administration, including OS patching and upgrades.Hands-on experience with NetApp clusters, including rebuilds and optimization.Proficiency in VMware/Vcenter for...


  • Pittsburgh, Pennsylvania, United States PNC Full time

    Position Overview At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. As a(n) [position title] within PNC's [name of division] organization, you will be based in [city/state location of position].Job ProfilePosition OverviewAt PNC, our...