Security Engineer, AppSec
We’re Cruise, the self-driving ride-hailing service.
We are building the world’s most advanced self-driving vehicles to safely connect people to the places, things, and experiences they care about. We believe self-driving vehicles will help save lives, reshape cities, give back time in transit, and restore freedom of movement for many.
At Cruise, our engineers have opportunities to grow and develop while learning from leaders at the cutting-edge of their fields. With a culture of internal mobility, there's opportunity to thrive in a variety of disciplines. This is a place for dreamers and doers to succeed.
If you are looking to solve one of today’s most complex engineering challenges, see the results of your work in hundreds of self-driving cars, and make a positive impact in the world starting in our cities, join us.
We are open to remote work for the right candidate.
Cruise is looking for a productive and ambitious Security Engineer to join its Application Security team. The Application Security team supports Cruise’s mission of deploying self-driving cars at scale by building tools and partnering with developers to safeguard Cruise’s software, systems, and assets. The AppSec team goes beyond finding bugs by partnering with development teams to support secure software development across Cruise’s broad tech stack.
Why join Cruise AppSec?
- Opportunity to define the future of transportation alongside industry leaders
- Work with modern technology stacks, and employ the latest and greatest tools and techniques
- Be part of an organization where security is prioritized by senior leadership
- Enjoy a healthy work-life balance
What you'll be doing:
- Build, deploy, and maintain security tools, libraries, controls, and instrumentation in Cruise’s codebases
- Develop tools and processes to automate the discovery and prevention of security issues
- Perform code and design reviews to identify and help remediate security flaws
- Utilize threat modeling to monitor Cruise’s attack surface and influence system design patterns
- Partner with developers from throughout the organization to design and promote secure software architectures
What you must have:
- Significant experience with at least one of Node, Go, or Python
- Experience finding vulnerabilities in web and mobile applications
- Equally invested in finding bugs and creating solutions
- Strong understanding of cloud services and architectures
- Exceptional ability to communicate and collaborate with developers, non-engineering stakeholders, and leadership
- Must be a relentless self-starter who thrives amid ambiguity
Bonus Points!
- Experience with C/C++ and embedded software security
- Experience designing, developing, and maintaining professional software
- Experience with GCP, Kubernetes, containers, secrets management systems, cryptography, popular threat modeling systems, and other contemporary security topics
- Contributions to the security community (open source, published research, presentations, blog posts, etc.)
- Bachelor’s degree or above in CS, Engineering, Math, Physics, or similar
Why Cruise?
- Our benefits are here to support the whole you:
- Competitive salary and benefits
- 401(k) Cruise matching program
- Medical / dental / vision, AD+D and Life
- Flexible vacation and company paid holidays
- Healthy meals and snacks provided
- Paid parental leave & family expansion stipend
- Monthly wellness stipend
- Commuter benefits
- We’re Integrated
- Through our partnerships with General Motors and Honda, we are the only self-driving company with fully integrated manufacturing at scale.
- We’re Funded
- GM, Honda, SoftBank, and T. Rowe Price have invested billions in Cruise. Their backing for our technology demonstrates their confidence in our progress, team, and vision and makes us one of the leading autonomous vehicle organizations in the industry. Our deep resources greatly accelerate our operating speed.
- We’re Independent
- We have our own governance, board of directors, equity, and investors. Our independence allows us to not just work on the bleeding-edge of technology, but also define it.
- We're Vested
- You won’t just own your work here, you’ll have the potential to own equity in Cruise, too. We are competing in a market that is projected to grow exponentially, which gives our company valuation room to grow.
Cruise LLC is an equal opportunity employer. All applicants for employment will be considered without regard to race, color, religion, sex, national origin, age, disability, sexual orientation, gender identity or expression, veteran status, genetics or any other legally protected basis. Below, you have the opportunity to share your preferred gender pronouns, gender, ethnicity, and veteran status with Cruise to help us identify areas of improvement in our hiring and recruitment processes. Completion of these questions is entirely voluntary. Any information you choose to provide will be kept confidential, and will not impact the hiring decision in any way.
We also consider for employment qualified applicants regardless of criminal histories, consistent with applicable laws. And, if you believe that you will need any type of accommodation, please let us know.
Note to Recruitment Agencies: Cruise does not accept unsolicited agency resumes. Furthermore, Cruise does not pay placement fees for candidates submitted by any agency other than its approved partners.