Offensive Security Engineer, Product Security
Foster City, CA
⚠️ We'll shut down after Aug 1st - try foo🦍 for all jobs in tech ⚠️
Zoox
Zoox is a purpose-built autonomous vehicle designed for riders, not drivers. Learn more about the Zoox robotaxi and the future of ride-hailing.
Zoox is seeking an experienced Offensive Security Engineer with deep technical expertise in reviewing and testing Internet of Things (IoT) devices, robots, or autonomous systems. This individual will be responsible for performing security assessments across the full stack of connected devices, from embedded firmware to cloud APIs. You will simulate real-world adversaries, identify vulnerabilities, and provide technical insights that directly impact the security posture of our products.
Follow us on LinkedIn
AccommodationsIf you need an accommodation to participate in the application or interview process please reach out to accommodations@zoox.com or your assigned recruiter.
A Final Note:You do not need to match every listed expectation to apply for this position. Here at Zoox, we know that diverse perspectives foster the innovation we need to be successful, and we are committed to building a team that encompasses a variety of backgrounds, experiences, and skills.
Key Responsibilities Include:
- Conduct offensive security assessments of IoT devices, including hardware, firmware, mobile apps, APIs, cloud backends, and communication protocols.
- Reverse engineer firmware and perform static and dynamic analysis to identify security flaws.
- Identify and exploit vulnerabilities in embedded systems, wireless protocols, bootloaders, secure boot implementations, and cryptographic mechanisms.
- Build and execute proof-of-concept attacks to demonstrate real-world exploitability and business impact.
- Collaborate with product, hardware, and software engineering teams to define secure development practices and improve product resilience.
- Contribute to internal tooling, automation, and methodologies for IoT security testing.
- Participate in threat modeling and architecture reviews of new products and features.
- Stay up to date with emerging vulnerabilities, tools, and offensive research relevant to IoT ecosystems.
The ideal candidate has deep expertise in security engineering, cryptography, network security, and secure system design, with a proactive approach to securing complex platforms.
Qualifications
- 5+ years of hands-on experience in offensive security or penetration testing, with at least 2 years focused on IoT and embedded systems.
- Strong knowledge of hardware hacking techniques (e.g., JTAG/SWD/UART debugging, side-channel analysis, fault injection).
- Proficient in reverse engineering tools such as Ghidra, IDA Pro, Binary Ninja, and debugging tools like JTAGulator, OpenOCD, or Bus Pirate.
- Experience analyzing and modifying firmware images (binwalk, Firmadyne, QEMU).
- Familiarity with secure boot, TPM/TEE, flash encryption, and other embedded security technologies.
- Deep understanding of wireless communication protocols (e.g., BLE, Zigbee, LoRa, Wi-Fi).
- Programming and scripting proficiency in Python, C/C++, Bash, or similar languages.
- Solid understanding of common vulnerabilities (e.g., memory corruption, logic flaws, insecure update mechanisms).
Bonus Qualifications
- Experience with secure SDLC in embedded or hardware environments.
- Knowledge of cloud security and mobile application security testing.
- Contributions to open-source security tools or published research in IoT security.
- Experience presenting technical research at security conferences or publishing security advisories, CVEs, or whitepapers.
Follow us on LinkedIn
AccommodationsIf you need an accommodation to participate in the application or interview process please reach out to accommodations@zoox.com or your assigned recruiter.
A Final Note:You do not need to match every listed expectation to apply for this position. Here at Zoox, we know that diverse perspectives foster the innovation we need to be successful, and we are committed to building a team that encompasses a variety of backgrounds, experiences, and skills.
* Salary range is an estimate based on our AI, ML, Data Science Salary Index 💰
Job stats:
3
1
0
Categories:
Engineering Jobs
Product Jobs
Tags: APIs Architecture Engineering LoRA Machine Learning Open Source Python Research Robotics SDLC Security Testing
Perks/benefits: Conferences
Region:
North America
Country:
United States
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Sr. Data Engineer jobsPower BI Developer jobsPrincipal Data Engineer jobsData Scientist II jobsBI Developer jobsStaff Data Scientist jobsPrincipal Software Engineer jobsStaff Machine Learning Engineer jobsDevOps Engineer jobsData Science Intern jobsJunior Data Analyst jobsSoftware Engineer II jobsAI/ML Engineer jobsStaff Software Engineer jobsData Science Manager jobsData Manager jobsLead Data Analyst jobsData Analyst Intern jobsData Specialist jobsSr. Data Scientist jobsBusiness Data Analyst jobsBusiness Intelligence Analyst jobsData Governance Analyst jobsData Engineer III jobsSenior Backend Engineer jobs
Consulting jobsMLOps jobsAirflow jobsOpen Source jobsKafka jobsEconomics jobsKPIs jobsGitHub jobsLinux jobsJavaScript jobsTerraform jobsPostgreSQL jobsRAG jobsPrompt engineering jobsBanking jobsStreaming jobsData Warehousing jobsScikit-learn jobsNoSQL jobsClassification jobsRDBMS jobsComputer Vision jobsPhysics jobsdbt jobsHadoop jobs
Pandas jobsScala jobsGoogle Cloud jobsGPT jobsData warehouse jobsR&D jobsLangChain jobsMicroservices jobsBigQuery jobsCX jobsELT jobsOracle jobsDistributed Systems jobsScrum jobsLooker jobsReact jobsIndustrial jobsPySpark jobsRedshift jobsJira jobsOpenAI jobsRobotics jobsSAS jobsUnstructured data jobsSalesforce jobs