Staff Security Engineer

Aurora Innovation Aurora Innovation · Robotics · Mountain View, CA · Security

Staff Security Engineer role focused on designing, building, and owning enterprise security platforms, integrations, and automation to protect employees, devices, internal systems, and data at scale. This role requires strong programming skills for automation and integration, experience with security telemetry and detection infrastructure, and leadership in cross-functional security engineering projects. It is not a security operations-only role but sits in enterprise security engineering.

What you'd actually do

  1. Own the architecture and implementation of Aurora's enterprise security controls — designing the systems and integrations that protect Aurora's endpoints, identities, internal infrastructure, and SaaS environment.
  2. Design and build Aurora's security telemetry and detection infrastructure, including log pipelines, SIEM integrations, and alerting frameworks — in partnership with the Security Operations Engineer who owns ongoing tuning and rule development.
  3. Define and enforce enterprise security standards, conducting architecture and design reviews to ensure alignment with Aurora's security posture and risk tolerance.
  4. Partner with IT, Infrastructure, and Engineering teams to embed security requirements early — shifting left on corporate IT initiatives before they become technical debt.
  5. Build automation and tooling that extends the capabilities of Aurora's security platforms, reduces manual operational burden, and scales the team's impact.

Skills

Required

  • 12+ years of hands-on experience in enterprise security engineering or corporate information security
  • Proficiency in at least one programming language (Go or Python) for security automation, integrations, or internal tooling
  • Experience architecting and integrating enterprise security platforms
  • Experience designing and building security telemetry pipelines and detection infrastructure
  • Experience leading cross-functional security engineering projects
  • Track record of conducting security architecture reviews
  • Experience evaluating security posture and identifying systemic gaps

Nice to have

  • Zero Trust architecture and identity-centric security models
  • NIST CSF, MITRE ATT&CK, and CIS Benchmarks
  • AWS security experience
  • applied cryptography and PKI in a production enterprise environment
  • securing AI/ML platforms or applications built on LLMs, RAG pipelines, or MCP-based architectures
  • Security certifications (CISSP, GCED, GREM)

What the JD emphasized

  • enterprise security engineering
  • security posture at scale
  • designing, building, and owning the platforms, integrations, and automation
  • not a security operations-only role
  • production-quality automation, integrations, or internal tooling
  • security telemetry pipelines and detection infrastructure
  • leading cross-functional security engineering projects
  • security architecture reviews
  • systemic gaps
  • durable solutions