Staff Technical Program Manager - Security Risk Management

Company:  Australian Competition and Consumer Commission
Location: San Francisco
Closing Date: 02/11/2024
Salary: £250 Per Annum
Hours: Full Time
Type: Permanent
Job Requirements / Description

Aurora (Nasdaq: AUR) is delivering the benefits of self-driving technology safely, quickly, and broadly to make transportation safer, increasingly accessible, and more reliable and efficient than ever before. The Aurora Driver is a self-driving system designed to operate multiple vehicle types, from freight-hauling semi-trucks to ride-hailing passenger vehicles, and underpins Aurora Horizon and Aurora Connect, its driver-as-a-service products for trucking and ride-hailing. Aurora is working with industry leaders across the transportation ecosystem, including Toyota, FedEx, Volvo Trucks, PACCAR, Uber, Uber Freight, U.S. Xpress, Werner, Covenant, Schneider, and Ryder.

Aurora hires talented people with diverse backgrounds who are ready to help build a transportation ecosystem that will make our roads safer, get crucial goods where they need to go, and make mobility more efficient and accessible for all. The mission of Aurora’s Security Technical Program Management (TPM) team is to embed security into every aspect of Aurora’s products—spanning software, hardware, and services. As a key member of this team, you will be responsible for driving security strategy and initiatives across the organization, ensuring that security is a fundamental part of the product development process.

In this role, you will

  • Lead security integration: Develop and execute security assurance, governance, and risk management programs, ensuring they are deeply embedded into all phases of product development and aligned with company objectives.
  • Collaborate with product teams: Work closely with product management, engineering, and security teams to assess product risks, prioritize security initiatives, and implement strategic controls that protect both product integrity and user trust.
  • Drive external assessments: Oversee external security assessments and penetration tests, translating findings into actionable risk mitigation strategies that enhance product security.
  • Manage product risk: Lead the security risk management program with a focus on product-related risks, ensuring alignment with enterprise risk management efforts and compliance with industry regulations.
  • Monitor and report: Define and report on key performance indicators (KPIs) related to product and security risks, ensuring transparency and data-driven decision-making across the organization.

Required Qualifications

  • 10+ years of experience in Technical Program Management, with a strong focus on cybersecurity, particularly within the context of product development.
  • Bachelor’s or Master’s degree in Computer Science, Information Security, or a related technical field, or equivalent experience.
  • Proven experience leading large-scale security programs with an emphasis on integrating security into product development cycles.
  • Strong communication and leadership skills, with the ability to influence and collaborate with cross-functional product teams.
  • Hands-on experience managing external security assessments and penetration tests, with the ability to translate technical findings into practical security improvements for products.

Desirable Qualifications

  • Advanced certifications such as CISSP, OSCP, GIAC-PEN, CISM, or equivalent, demonstrating expertise in cybersecurity and product risk management.
  • Experience building and scaling security programs from the ground up, particularly in product-focused environments or industries with stringent security requirements.
  • Strong knowledge of industry security standards and regulations (e.g., ISO 27001, SOC2, NIST, GDPR), with proven experience ensuring product compliance.
  • Proven ability to lead organizational change, especially in implementing new security processes within product teams.
  • Excellent communication skills, with the ability to explain complex security concepts to both technical and non-technical stakeholders, particularly in a product context.

The base salary range for this position is $220-$352K per year. Aurora’s pay ranges are determined by role, level, and location. Within the range, the successful candidate’s starting base pay will be determined based on factors including job-related skills, experience, qualifications, relevant education or training, and market conditions. These ranges may be modified in the future. The successful candidate will also be eligible for an annual bonus, equity compensation, and benefits.

Working at Aurora

At Aurora, we bring together extraordinarily talented and experienced people united by the strength of our values. We operate with integrity, set outrageous goals, and build a culture where we win together — all without any jerks.

Safety is central to everything we do. Every employee at Aurora has a role in contributing to safety, every step of the way. We seek candidates who take active responsibility, can contribute to building an atmosphere of trust, and invest in the organization's long-term success by working safely — no matter what.

Aurora is committed to providing access to anyone who seeks information from our website. We invite anyone using assistive technologies, such as a screen reader or Braille reader, to email us at if they experience difficulty using our website. Please describe the accessibility problem and include a URL (if available).

#J-18808-Ljbffr
Apply Now
An error has occurred. This application may no longer respond until reloaded. Reload 🗙