Staff Security Engineer

Aurora Innovation Aurora Innovation · Robotics · Mountain View, CA · Security

Staff Security Engineer role focused on building and owning enterprise security platforms, integrations, and automation for a scaling autonomous trucking company. Responsibilities include architecting security controls, designing telemetry and detection infrastructure, defining standards, embedding security early, and building automation tools. Requires extensive experience in enterprise security engineering, programming for security automation, and architecting security platforms.

What you'd actually do

  1. Own the architecture and implementation of Aurora's enterprise security controls — designing the systems and integrations that protect Aurora's endpoints, identities, internal infrastructure, and SaaS environment.
  2. Design and build Aurora's security telemetry and detection infrastructure, including log pipelines, SIEM integrations, and alerting frameworks — in partnership with the Security Operations Engineer who owns ongoing tuning and rule development.
  3. Define and enforce enterprise security standards, conducting architecture and design reviews to ensure alignment with Aurora's security posture and risk tolerance.
  4. Partner with IT, Infrastructure, and Engineering teams to embed security requirements early — shifting left on corporate IT initiatives before they become technical debt.
  5. Build automation and tooling that extends the capabilities of Aurora's security platforms, reduces manual operational burden, and scales the team's impact.

Skills

Required

  • enterprise security engineering
  • corporate information security
  • programming languages (Go, Python)
  • security automation
  • security integrations
  • enterprise security platforms
  • EDR/XDR
  • MDM
  • IAM/IGA
  • DLP
  • SaaS security
  • cloud security
  • PKI
  • security telemetry
  • detection infrastructure
  • log ingestion
  • SIEM integration
  • alerting architecture
  • cross-functional project leadership
  • security architecture reviews
  • risk assessment
  • systemic gap identification

Nice to have

  • Zero Trust architecture
  • identity-centric security models
  • NIST CSF
  • MITRE ATT&CK
  • CIS Benchmarks
  • AWS security
  • applied cryptography
  • secrets management
  • AI/ML platforms security
  • LLM security
  • RAG pipeline security
  • MCP-based architectures

What the JD emphasized

  • 12+ years of hands-on experience in enterprise security engineering or corporate information security — specifically securing employee-facing systems, endpoints, identities, and internal infrastructure (not product or application security).
  • Proficiency in at least one programming language, used in a security context — writing production-quality automation, integrations, or internal tooling (the team primarily uses Go; Python is also common).
  • Experience architecting and integrating enterprise security platforms — designing API integrations, automating workflows, and building tooling that extends platform capabilities across domains such as EDR/XDR, MDM, IAM/IGA, DLP, SaaS security, cloud security, or PKI.
  • Experience designing and building security telemetry pipelines and detection infrastructure — log ingestion, normalization, SIEM integration, and alerting architecture.
  • Experience leading cross-functional security engineering projects — defining scope, driving execution, and aligning stakeholders across Engineering and IT.
  • Track record of conducting security architecture reviews and translating findings into actionable, risk-prioritized remediation plans.
  • Experience evaluating security posture and identifying systemic gaps, with a bias toward building durable solutions rather than one-off fixes.