Staff Security Engineer, Enterprise Security

Aurora Innovation Aurora Innovation · Robotics · Mountain View, CA · Security

Staff Security Engineer focused on defining and championing enterprise security architecture strategy, roadmap, and target-state operating model. This role involves developing reference architectures, technical standards, and guiding secure solutions for workforce platforms, enterprise systems, and internal infrastructure using Zero Trust principles. The engineer will also provide architectural oversight for major initiatives, identify gaps, and shape long-term strategy including emerging needs related to AI security.

What you'd actually do

  1. Define and champion Aurora’s enterprise security architecture strategy, roadmap, and target-state operating model across enterprise and backend operational security domains.
  2. Develop enterprise security reference architectures, design patterns, and technical standards for endpoint security, network security, infrastructure security, enterprise vulnerability management, data protection, resilience, enterprise platforms, and security tooling.
  3. Translate security strategy, governance requirements, and business priorities into scalable technical architecture and implementation guidance.
  4. Partner with GRC to operationalize security policies, standards, and control objectives into practical enterprise security architectures.
  5. Help shape long-term strategy for enterprise security capabilities, including emerging needs related to AI security, automation, infrastructure modernization, and operational resilience.

Skills

Required

  • 10+ years of professional experience in Information Security, Enterprise Architecture, Security Engineering, or related technical leadership capacities.
  • 5+ years specifically focused on designing enterprise-scale security architectures across diverse domains, including endpoint, network, infrastructure, vulnerability management, resilience, and enterprise platforms.
  • Demonstrated success in developing enterprise security architecture strategies, reference architectures, and scalable technical standards.
  • Extensive technical depth in Zero Trust principles, enterprise security frameworks, and modern backend or enterprise security architecture design patterns.
  • Comprehensive knowledge of core enterprise security domains, including endpoint security, network security, PKI, enterprise vulnerability management, resilience, data protection, and governance integration.
  • Proven ability to translate governance, compliance, and strategic business requirements into actionable technical architecture and implementation guidance.
  • Experience representing security interests within architecture review boards, governance committees, or enterprise-wide design councils.
  • Advanced familiarity with enterprise infrastructure, SaaS ecosystems, internal platforms, and the strategic integration of security tooling.
  • Adept at evaluating technical tradeoffs, identifying scalability constraints, and assessing the long-term implications of enterprise security architecture decisions.
  • Exceptional documentation skills, including the creation of detailed architecture diagrams, technical standards, and strategic narratives for executive leadership.
  • Proven capacity to influence technical and business stakeholders across multifaceted cross-functional teams.
  • Strong strategic mindset, complex problem-solving abilities, and a track record of organizational leadership.

Nice to have

  • Direct experience in the automotive industry.
  • Knowledge of enterprise architecture committee structures and multifaceted cross-functional governance models.
  • Expert-level knowledge on AI security.

What the JD emphasized

  • enterprise security architecture strategy
  • enterprise security reference architectures
  • enterprise security alignment
  • enterprise security design
  • enterprise security investments
  • enterprise security capabilities
  • enterprise security platforms
  • enterprise security design documentation
  • enterprise security maturity
  • enterprise security leadership
  • AI security