Rivian and Volkswagen Group Technologies
Director - Product Security
Palo Alto, California
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Seniority
- Director
- Stated salary
- $240,700 – $395,350 per year
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 28 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
About Us
Rivian and Volkswagen Group Technologies is a joint venture between two industry leaders with a clear vision for automotive’s next chapter. From operating systems to zonal controllers to cloud and connectivity solutions, we’re addressing the challenges of electric vehicles through technology that will set the standards for software-defined vehicles around the world.
The road to the future is uncharted. By combining our expertise across connectivity, AI, security and more, we’ll map a new way forward. Working together, we’ll create a future that’s more connected, more intelligent, more sustainable for everyone.
Role Summary
As the Director of Product Security, you will lead a structured, high-performing product security team at one of the most consequential software-defined vehicle platforms in the automotive industry. This is an engineering leadership role. You will work shoulder-to-shoulder with elite software and hardware engineers, driving technical excellence, elevating the people and practices already in place, and embedding security into the DNA of how we build. You own the execution, not just the vision, and you will be measured by the results your team delivers. Reporting to the Sr. Director, Systems Engineering, Safety and Software Quality, you will lead the end-to-end product security strategy for Rivian and Volkswagen Group Technologies’ joint platform, a technology stack that will underpin millions of future electric vehicles across Rivian, Volkswagen, Audi, Scout, and beyond.
This is not a compliance role. This is a builder’s role. You will embed security into the DNA of our zonal architecture, over-the-air update pipeline, cloud infrastructure, and autonomous driving stack. Working shoulder-to-shoulder with elite software and hardware engineers who share your obsession with getting it right. You’ll own the discipline, lead the team, and set the standard for what product security looks like at the intersection of Silicon Valley and the global automotive industry. he team and structure are in place. We are looking for a leader who inherits a high-performing org, develops the people within it, and evolves the team over time to meet the demands of an ever-changing security landscape, building on what's working while continuously raising the bar. This role is located in our Palo Alto, CA office and reports directly into the Sr. Director, Systems Engineering, Safety and Software Quality.
Responsibilities
Product Security Strategy & Architecture: Lead a team that will d efine and own the multi-year product security roadmap for Rivian and RV Tech’s joint SDV (Software Defined Vehicle) platform. Translate business objectives, threat landscapes, and regulatory requirements into a coherent, executable security strategy spanning vehicle firmware, cloud backend, mobile applications, and the OTA update pipeline.
Secure-by-Design Engineering: Embed security across the full software development lifecycle. Partner with software, hardware, and platform engineering teams to conduct threat modeling and TARA (Threat Analysis and Risk Assessment), development of security requirements for implementation, systematic test definition and execution on SIL (software-in-loop), HIL (hardware-in-loop) and test vehicle levels. You will also establish secure coding guidelines to be used across all core engineering teams and build automated security tooling (SAST, DAST, fuzzing) into CI/CD pipelines. Champion a “security by design” culture across a global engineering org of 1,500+.
Automotive & Connected Vehicle Security: Lead adhering to compliance and security engineering efforts for automotive cybersecurity standards including ISO/SAE 21434 and UN Regulation No. 155. Secure zonal and E/E architecture, ECU communication buses (CAN, Automotive Ethernet), telematics, V2X, and ADAS/autonomy stacks. Own security of OTA update signing and delivery infrastructure.
Vulnerability Management & Red Team Programs: Build and operate a world-class vulnerability management program covering vehicle software, cloud services, and mobile apps. Establish and manage a bug bounty program and coordinate penetration testing across all product surfaces. Oversee triage, prioritization, and remediation tracking in partnership with engineering teams.
Supply Chain & Third-Party Security: Define and enforce security requirements across Tier-1 and Tier-2 automotive suppliers and software vendors. Build Software Bill of Materials (SBOM) practices, oversee third-party security assessments, and ensure supply chain integrity across the full software stack shared between Rivian and Volkswagen Group brands.
AI & Autonomy Security: Secure RV Tech’s AI and autonomy platform, including the Rivian Unified Intelligence stack and in-vehicle AI systems. Develop threat models for ML pipelines, model integrity, adversarial input attacks, and in-vehicle inference security. Stay at the forefront of AI security as a rapidly evolving attack surface in safety-critical systems.
Incident Response & PSIRT: Build and lead the Product Security Incident Response Team (PSIRT) for RV Tech. Establish coordinated disclosure processes, incident playbooks, and executive communication frameworks. Ensure rapid and effective response to security incidents affecting vehicle or platform software.
Team Leadership & Talent Development: Inspire a high-performance product security team across Palo Alto, Irvine, Vancouver and Berlin. Create a culture of ownership, technical excellence, and continuous improvement while fostering collaboration across the RV Tech core engineering team and parent companies.
Executive & Cross-Organizational Leadership: Report directly to the Sr. Director, Product Security, Safety and Software Quality and present to executive leadership and the board on product security posture, program maturity, and key risks. Engage with industry forums and standards bodies (Auto-ISAC, NHTSA, UNECE WP.29) as needed to stay current on the evolving regulatory and threat landscape.
Qualifications
Minimum Qualifications:
12+ years of progressive experience in cybersecurity, with at least 5 years in product security leadership at a software-defined product company (automotive, consumer electronics, aerospace, robotics, or similar).
Deep technical expertise in application security, embedded systems security, or automotive cybersecurity with a hands-on engineering background, not purely managerial.
Demonstrated experience leading and upleveling an inherited product security or AppSec team, developing people, elevating practices, and driving execution within an existing org structure. Greenfield build experience is a plus but not the primary requirement for this role.
Proven ability to influence and drive security posture across engineering organizations without direct authority - the credibility to be taken seriously in a room full of elite engineers.
Strong working knowledge of threat modeling methodologies (eg STRIDE, PASTA, TARA), secure SDLC practices, and vulnerability management programs including coordinated disclosure.
Experience securing cloud-native architectures at scale (GCP, AWS, or Azure) including cloud-to-vehicle communication channels and data pipelines.
Track record of operating at the executive level presenting to the board, partnering with the C-suite, and translating deeply technical risk into business-level language.
B.S. or M.S. in Computer Science, Computer Engineering, Electrical Engineering, or equivalent practical experience.
Preferred Qualifications
Direct experience with ISO/SAE 21434, UN Regulation No. 155, NHTSA cybersecurity best practices, or other automotive-specific cybersecurity frameworks.
Background in embedded security, firmware security, or hardware security (e.g. HSMs, secure boot, cryptographic key management in constrained environments).
Experience at a mission-driven, high-velocity technology company
Familia
Similar jobs
- VCS - Region Director in TrainingVeterans Health Administration · Saint Louis, Missouri, United StatesFirst seen today
- CYS Facility Director NF-04United States Army Installation Management Command · Fort Bragg, North Carolina, United StatesFirst seen today
- ASSISTANT CHILD DEVELOPMENT CENTER DIRECTORPacific Air Forces · Eielson AFB, Alaska, United StatesFirst seen today
- Marketing DirectorAir Education and Training Command · Maxwell AFB, Alabama, United StatesFirst seen today
- Director, Technology TransformationBSC · Oakland, CA, United States; WA, United States; OH, United States; DC, United States; CA, United States; Long Beach, CA, United States; AZ, United States; CO, United States; CT, United States; FL, United States; GA, United States; MD, United States; MN, United States; NV, United States; OR, United States; El Dorado Hills, CA, United States; San Diego, CA, United States; Woodland Hills, CA, United States; AL, United States; IL, United States; VA, United States; WI, United States; TX, United States; NY, United StatesFirst seen today
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job