Staff Security Engineer, Enterprise Security

Aurora Innovation Aurora Innovation · Robotics · Mountain View, CA · Security

This role focuses on defining and championing enterprise security architecture strategy, roadmap, and operating models. The Staff Security Engineer will develop reference architectures, technical standards, and guidance for various security domains, including endpoint, network, infrastructure, data protection, and security tooling. They will translate security strategy and governance requirements into scalable technical architecture, participate in architecture review boards, and guide secure solution design using Zero Trust principles. The role also involves identifying architectural gaps, shaping long-term strategy for enterprise security capabilities (including AI security), and supporting security tooling strategy. Collaboration with various security and IT teams is crucial, as is establishing and maintaining design documentation and aligning architecture to frameworks like NIST CSF and SOC 2. The position requires extensive experience in information security and enterprise architecture, with a strong strategic mindset and problem-solving abilities.

What you'd actually do

  1. Define and champion Aurora’s enterprise security architecture strategy, roadmap, and target-state operating model across enterprise and backend operational security domains.
  2. Develop enterprise security reference architectures, design patterns, and technical standards for endpoint security, network security, infrastructure security, enterprise vulnerability management, data protection, resilience, enterprise platforms, and security tooling.
  3. Translate security strategy, governance requirements, and business priorities into scalable technical architecture and implementation guidance.
  4. Architect secure solutions for workforce platforms, enterprise systems, internal infrastructure, and backend operational ecosystems using Zero Trust principles and modern security frameworks.
  5. Help shape long-term strategy for enterprise security capabilities, including emerging needs related to AI security, automation, infrastructure modernization, and operational resilience.

Skills

Required

  • 10+ years of professional experience in Information Security, Enterprise Architecture, Security Engineering, or related technical leadership capacities.
  • 5+ years specifically focused on designing enterprise-scale security architectures across diverse domains, including endpoint, network, infrastructure, vulnerability management, resilience, and enterprise platforms.
  • Demonstrated success in developing enterprise security architecture strategies, reference architectures, and scalable technical standards.
  • Extensive technical depth in Zero Trust principles, enterprise security frameworks, and modern backend or enterprise security architecture design patterns.
  • Comprehensive knowledge of core enterprise security domains, including endpoint security, network security, PKI, enterprise vulnerability management, resilience, data protection, and governance integration.
  • Proven ability to translate governance, compliance, and strategic business requirements into actionable technical architecture and implementation guidance.
  • Experience representing security interests within architecture review boards, governance committees, or enterprise-wide design councils.
  • Advanced familiarity with enterprise infrastructure, SaaS ecosystems, internal platforms, and the strategic integration of security tooling.
  • Adept at evaluating technical tradeoffs, identifying scalability constraints, and assessing the long-term implications of enterprise security architecture decisions.
  • Exceptional documentation skills, including the creation of detailed architecture diagrams, technical standards, and strategic narratives for executive leadership.
  • Proven capacity to influence technical and business stakeholders across multifaceted cross-functional teams.
  • Strong strategic mindset, complex problem-solving abilities, and a track record of organizational leadership.

Nice to have

  • Direct experience in the automotive industry.
  • Knowledge of enterprise architecture committee structures and multifaceted cross-functional governance models.
  • Expert-level knowledge on AI security, including threat modeling, risk assessment, and secure development practices for AI/ML systems.

What the JD emphasized

  • AI security