Aurora (Nasdaq: AUR) is delivering the benefits of self-driving technology safely, quickly, and broadly to make transportation safer, increasingly accessible, and more reliable and efficient than ever before. The Aurora Driver is a self-driving system designed to operate multiple vehicle types, from freight-hauling semi-trucks to ride-hailing passenger vehicles, and underpins Aurora Horizon and Aurora Connect, its driver-as-a-service products for trucking and ride-hailing.
As a key member of Aurora’s Security Technical Program Management (TPM) team, you will be responsible for driving security strategy and initiatives across the organization, ensuring that security is a fundamental part of the product development process. You will act as a bridge between Security and Product teams, moving seamlessly between high-level strategy and detailed execution to ensure that complex, cross-functional security programs are successfully integrated into product development.
In this role, you will
- Lead security integration: Develop and execute security assurance, governance, and risk management programs, ensuring they are deeply embedded into all phases of product development and aligned with company objectives.
- Collaborate with product teams: Work closely with product management, engineering, and security teams to assess product risks, prioritize security initiatives, and implement strategic controls that protect both product integrity and user trust.
- Drive external assessments: Oversee external security assessments and penetration tests, translating findings into actionable risk mitigation strategies that enhance product security.
- Manage product risk: Lead the security risk management program with a focus on product-related risks, ensuring alignment with enterprise risk management efforts and compliance with industry regulations.
- Monitor and report: Define and report on key performance indicators (KPIs) related to product and security risks, ensuring transparency and data-driven decision-making across the organization.
Required Qualifications
- 10+ years of experience in Technical Program Management, with a strong focus on cybersecurity, particularly within the context of product development.
- Bachelor’s or Master’s degree in Computer Science, Information Security, or a related technical field, or equivalent experience.
- Proven experience leading large-scale security programs with an emphasis on integrating security into product development cycles.
- Strong communication and leadership skills, with the ability to influence and collaborate with cross-functional product teams.
- Hands-on experience managing external security assessments and penetration tests, with the ability to translate technical findings into practical security improvements for products.
Desirable Qualifications
- Advanced certifications such as CISSP, OSCP, GIAC-PEN, CISM, or equivalent, demonstrating expertise in cybersecurity and product risk management.
- Experience building and scaling security programs from the ground up, particularly in product-focused environments or industries with stringent security requirements.
- Strong knowledge of industry security standards and regulations (e.g., ISO 27001, SOC2, NIST, GDPR), with proven experience ensuring product compliance.
- Proven ability to lead organizational change, especially in implementing new security processes within product teams.
- Excellent communication skills, with the ability to explain complex security concepts to both technical and non-technical stakeholders, particularly in a product context.
The base salary range for this position is $220-$352K per year. Aurora’s pay ranges are determined by role, level, and location. The successful candidate will also be eligible for an annual bonus, equity compensation, and benefits.
Safety is central to everything we do. Every employee at Aurora has a role in contributing to safety, every step of the way. We seek candidates who take active responsibility, can contribute to building an atmosphere of trust, and invest in the organization's long-term success by working safely — no matter what.
#J-18808-Ljbffr