Palo Alto, California, USA
13 days ago
Sr. Cybersecurity Management System (CSMS) Security Engineer
About Us Rivian and Volkswagen Group Technologies is a joint venture between two industry leaders with a clear vision for automotive’s next chapter. From operating systems to zonal controllers to cloud and connectivity solutions, we’re addressing the challenges of electric vehicles through technology that will set the standards for software-defined vehicles around the world. The road to the future is uncharted. By combining our expertise across connectivity, AI, security and more, we’ll map a new way forward. Working together, we’ll create a future that’s more connected, more intelligent, more sustainable for everyone. Role Summary As the Cybersecurity Management System (CSMS) Security Engineer, you will work closely with CSMS Lead, along with Vehicle Software Development Org and both JV Parent brands to ensure the company’s alignment with ISO/SAE 21434 and ISO/SAE 24089 in the Security Engineering Process. You will play a critical role in ensuring that security by design principles are part of the core business of the company. Supporting the building out a compliant security program, and translating product security requirements into the architecture and both software and hardware security requirements. This role will be located at one of our locations in Palo Alto, CA, Irvine, CA, or Normal, IL. and report directly to the Red Team Lead, Vehicles. Responsibilities ● Alignment to ISO 21434 and 24089: Building out processes, procedures, security goals and requirements to ensure the company aligns to these standards. Partnering with stakeholders across the company to document requirements and working with the security validation testing team to ensure all requirements are met. ● Building out Governance, Risk and Compliance Program: Building out a program that documents the company’s and individual vehicle programs' security risks and compliance to compliment the overall company GRC program. Ensuring continuous improvement on the overall Security Engineering process that aligns to 21434.● ● Continuing to enhance the Threat Assessment and Risk Analysis Program : Improving on current TARA process and documentation. Supporting the Product Security team and vehicle software teams in documenting risks and security requirements to mitigate them. ● Support Secure Development Lifecycle: Collaborate with other Product Security teams around SDLC and ensure alignment to the vulnerability management process. Reporting up quarterly metrics to software org leadership. ● Documenting Security requirements based on Risk: Collaborate with other Product Security teams, Vehicle Software development org, and vehicle architecture teams in documenting requirements in JAMA that are developed within the Security Engineering process. So that those requirements can be validated by the Product Security Validation team. And evidence can be shared with our JV parent brands. Qualifications ● B.S. in Information Security, Computer Science, Computer Engineering, or a related field. ● 2+ years of experience in Automotive Industry and carrying out GRC (Governance, Risk, Compliance) activities. ● Knowledge of embedded systems development ● Experience in carrying out TARAs (Threat Assessment and Risk Analysis) and Security Reviews ● Experience with compliance with ISO 21434, EU R155 and R156 ● Experience operating with Confluence, JIRA, and JAMA applications ● Experience working with cross functional teams both internal and external organizations ● Ability to work in a fast-paced development environment. ● Good team player with excellent communication skills. ● Hands-on approach, proactively identifying and filling in gaps where needed. Pay Disclosure Salary Range/Hourly Rate for Palo Alto, California Based Applicants: $162,800 - 203,500 (actual compensation will be determined based on experience, location, and other factors permitted by law). Salary Range/Hourly Rate for Irvine, California Based Applicants: $149,800 - $187,200 (actual compensation will be determined based on experience, location, and other factors permitted by law). Salary Range/Hourly Rate for Normal, Illinois Based Applicants: $136,700 - $170,900 (actual compensation will be determined based on experience, location, and other factors permitted by law). Benefits Summary: Rivian and Volkswagen Group Technologies provides robust medical/Rx, dental and vision insurance packages for full-time employees, their spouse or domestic partner, and children up to age 26. Coverage is effective on the first day of employment. Equal Opportunity Rivian and Volkswagen Group Technologies is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender, gender expression, gender identity, genetic information or characteristics, physical or mental disability, marital/domestic partner status, age, military/veteran status, medical condition, or any other characteristic protected by law. We are also committed to ensuring compliance with all applicable fair employment practice laws regarding citizenship and immigration status. Rivian and Volkswagen Group Technologies is committed to ensuring that our hiring process is accessible for persons with disabilities. If you have a disability or limitation, such as those covered by the Americans with Disabilities Act, that requires accommodations to assist you in the search and application process, please email us at candidateaccommodations@rivian.com. Candidate Data Privacy Rivian and VW Group Technologies (“Rivian and Volkswagen Group Technologies”) may collect, use and disclose your personal information or personal data (within the meaning of the applicable data protection laws) when you apply for employment and/or participate in our recruitment processes (“Candidate Personal Data”). This data includes contact, demographic, communications, educational, professional, employment, social media/website, network/device, recruiting system usage/interaction, security and preference information. Rivian and Volkswagen Group Technologies may use your Candidate Personal Data for the purposes of (i) tracking interactions with our recruiting system; (ii) carrying out, analyzing and improving our application and recruitment process, including assessing you and your application and conducting employment, background and reference checks; (iii) establishing an employment relationship or entering into an employment contract with you; (iv) complying with our legal, regulatory and corporate governance obligations; (v) recordkeeping; (vi) ensuring network and information security and preventing fraud; and (vii) as otherwise required or permitted by applicable law. Rivian and Volkswagen Group Technologies may share your Candidate Personal Data with (i) internal personnel who have a need to know such information in order to perform their duties, including individuals on our People Team, Finance, Legal, and the team(s) with the position(s) for which you are applying; (ii) Rivian and Volkswagen Group Technologies affiliates; and (iii) Rivian and Volkswagen Group Technologies’ service providers, including providers of background checks, staffing services, and cloud services. Rivian and Volkswagen Group Technologies may transfer or store internationally your Candidate Personal Data, including to or in the United States, Canada, and the European Union and in the cloud, and this data may be subject to the laws and accessible to the courts, law enforcement and national security authorities of such jurisdictions. Please note that we are currently not accepting applications from third party application services.
Confirm your E-mail: Send Email