Sr. Staff Cybersecurity Engineer, Embedded Systems

Summary

Rivian is hiring a senior hands-on security engineer in Atlanta to own security and privacy assurance for vehicle embedded systems end to end: threat modeling, security requirements, secure boot, PKI, OTA, and vehicle/charging infrastructure, plus reviewing joint-venture (RVT) deliverables. Core work spans firmware, silicon, automotive protocols, and privacy engineering for telemetry and customer

About Rivian Rivian is on a mission to keep the world adventurous forever. This goes for the emissions-free Electric Adventure Vehicles we build, and the curious, courageous souls we seek to attract. As a company, we constantly challenge what’s possible, never simply accepting what has always been done. We reframe old problems, seek new solutions and operate comfortably in areas that are unknown. Our backgrounds are diverse, but our team shares a love of the outdoors and a desire to protect it for future generations. Role Summary The R1 is on the road today. R2 is close behind it, R3 follows, and the Rivian Adventure Network is expanding underneath all of them. RAP1, our first in-house chip, is in development. Every one of those is a target, and this role covers them: the compute inside the vehicle, the silicon underneath it, the chargers it plugs into, and the data it collects about the people it carries. You will support security and privacy assurance for a domain of Rivian's vehicle systems end to end: in-vehicle platforms and compute, firmware and boot chain, vehicle communications, OTA, or charging infrastructure. Threat models, security requirements, design review, and the technical assessment behind Rivian's position on a design are yours to run in that domain. Rivian's vehicle technology is developed both in-house and with Rivian and Volkswagen Group Technologies (RVT), our joint venture with its own product security organization. You will work across both: setting requirements and reviewing designs for what Rivian builds, and assessing the security of joint platform deliverables that ship in Rivian vehicles. Privacy engineering is part of the work. You will document how vehicle and customer data actually moves through the systems you cover, and specify minimization and retention in the design. This is a hands-on role. You will be in the architecture documents, the firmware, and on the bench. This role will be located in Atlanta, GA and report to ur Sr. Manager of Cybersecurity. Responsibilities Own threat modeling and design review for your domain: zonal E/E architecture, ECUs and vehicle compute, firmware, secure boot and chain of trust, key management, vehicle communications, or OTA Write the security requirements (functional and non-functional) for the programs in your domain, and drive them to adoption with platform engineering teams Map and document data flows through the systems you cover: what is collected, where it goes, how long it persists, who can reach it, then specify the minimization, retention, and deletion requirements that follow Build and validate privacy enforcement mechanisms: scrubbing and de-identification of telemetry, sensor, and camera data, consent and deletion handling in embedded and connected systems, and verification that shipped behavior matches the documented design Design and review the PKI underneath vehicle systems: device identity and factory provisioning, code and OTA signing, mutual TLS to backend services, Plug and Charge credentials, and certificate lifecycle across the fleet Perform the technical review of RVT security deliverables: read the design, test the claims, and produce the assessment Rivian's position rests on Analyze product vulnerability reports: reproduce, run variant analysis, and determine exploitability, design impact, and the direction a fix should take Author security and privacy engineering standards and reference patterns in your domain, and drive their adoption Scope product-targeted security testing with Rivian's offensive security and penetration testing teams, and turn findings into requirements and standards changes Participate in joint technical working groups with RVT Product Security on shared and integration attack surface Build the tooling that makes review and enforcement repeatable: analysis harnesses, test fixtures, data handling pipelines Qualifications 8+ years in security engineering, with substantial hands-on experience in embedded, automotive, or safety-critical product security Hands-on capability in several of: firmware analysis and reverse engineering, secure boot and chain of trust, SoC and ECU security (hardware root of trust, TEEs, memory and DMA protection), automotive network protocols and their protection, hardware-backed key management, OTA update security Applied PKI experience: key hierarchy design, HSM-backed roots, certificate provisioning and rotation, revocation at scale, and the operational realities of device certificates that outlive the systems issuing them Practical privacy engineering experience: data flow documentation, minimization and retention design, or building de-identification, scrubbing, or deletion mechanisms in a shipping product Demonstrated ownership of threat modeling and design review for shipping products, including holding a technical position with the engineers who built the system Experience driving security requirements into engineering teams you don't manage, and getting them implemented Working knowledge of ISO/SAE 21434 and UNECE R155/R156, and the judgment to tell certification evidence from engineering truth Nice to have Offensive security background against embedded or vehicle targets: fuzzing, hardware attack, side-channel or fault injection Experience with sensor or camera data de-identification, or privacy-preserving telemetry design Working knowledge of GDPR, CCPA, and comparable regimes as engineering requirements rather than legal text Threat modeling / TARA program experience at an automotive OEM or tier-1 ISO 15118 Plug and Charge, V2X credential systems, or crypto-agility and post-quantum migration planning for long-lived devices Charging infrastructure or high-voltage systems security experience Pay Disclosure The salary range for this role is $179,000 - $223,700 for Georgia based applicants. This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An employee’s position within the salary range will be based on several factors including, but not limited to, specific competencies, relevant education, qualifications, certifications, experience, skills, geographic location, shift, and organizational needs. The successful candidate may be eligible for annual performance bonus and equity awards. We offer a comprehensive package of benefits for full-time and part-time employees, their spouse or domestic partner, and children up to age 26, including but not limited to paid vacation, paid sick leave, and a competitive portfolio of insurance benefits including life, medical, dental, vision, short-term disability insurance, and long-term disability insurance to eligible employees. You may also have the opportunity to participate in Rivian’s 401(k) Plan and Employee Stock Purchase Program if you meet certain eligibility requirements. Full-time employee coverage is effective on their first day of employment. Part-time employee coverage is effective the first of the month following 90 days of employment. More information about benefits is available at rivianbenefits.com. Equal Opportunity Rivian is an equal opportunity employer and complies with all applicable federal, state, and local fair employment practices laws. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender, gender expression, gender identity, genetic information or characteristics, physical or mental disability, marital/domestic partner status, age, military/veteran status, medical condition, or any other characteristic protected by law. Rivian is committed to ensuring that our hiring process is accessible for persons with disabilities. If you have a disability or limitation, such as those covered by the Americans with Disabilities Act, that requires accommodations to assist you in the search and application process, please email us at candidateaccommodations@rivian.com. Candidate Data Privacy and Technology Rivian may collect, use and disclose your personal information or personal data (within the meaning of the applicable data protection laws) when you apply for employment and/or participate in our recruitment processes (“Candidate Personal Data”). This data includes contact, demographic, communications, educational, professional, employment, social media/website, network/device, recruiting system usage/interaction, security and preference information. Rivian may use your Candidate Personal Data for the purposes of (i) tracking interactions with our recruiting system; (ii) carrying out, analyzing and improving our application and recruitment process, including assessing you and your application and conducting employment, background and reference checks; (iii) establishing an employment relationship or entering into an employment contract with you; (iv) complying with our legal, regulatory and corporate governance obligations; (v) recordkeeping; (vi) ensuring network and information security and preventing fraud; and (vii) as otherwise required or permitted by applicable law. Rivian may share your Candidate Personal Data with (i) internal personnel who have a need to know such information in order to perform their duties, including individuals on our People Team, Finance, Legal, and the team(s) with the position(s) for which you are applying; (ii) Rivian affiliates; and (iii) Rivian’s service providers, including providers of background checks, staffing services, and cloud services. Rivian may transfer or store internationally your Candidate Personal Data, including to or in the United States, Canada, the United Kingdom, and the European Union and in the cloud, and this data may be subject to the laws and accessible to the courts, law enforcement and national security authorities of such jurisdictions. How We Use AI in Our Hiring Process: To ensure transparency, we want candidates to know that Rivian uses iCIMS Talent Cloud Artificial Intelligence (TCAI) and AI-enabled tools to assist with screening, reviewing, organizing and highlighting profiles and applications that match the key requirements for each role. AI does not make hiring decisions: Qualified candidate applications are reviewed by a member of our team, and all decisions throughout the process are made by humans. We use AI to support efficiency and consistency, not to replace human judgment. We are committed to a fair, thoughtful, and equitable experience for every candidate. Participation in AI profile matching is entirely voluntary. If you prefer that your profile not be used in this process, you can opt out at any time. Opting out means your profile will be excluded from automated matching and will not be surfaced for additional roles through this system. Your current application remains active and will not be affected in any way. Please note that we are currently not accepting applications from third party application services.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available