APTIV Logo

APTIV

Principal Technologist - Product Security

Posted 19 Days Ago
Be an Early Applicant
In-Office
Walnut Creek, CA, USA
Expert/Leader
In-Office
Walnut Creek, CA, USA
Expert/Leader
Lead security architecture and strategy for a private cloud platform, driving threat modeling, secure design, vulnerability management, and secure-by-default platform hardening. Guide product security roadmaps, embed security in the SDLC, mentor engineering leaders, support incident investigations, and ensure compliance with industry standards for telco, aerospace, defense, and industrial deployments.
The summary above was generated by AI

Role Summary 

As a Principal Technologist specializing in Product Security for the Wind River Private Cloud Platform, you will serve as the technical authority driving the secure design, architecture, and lifecycle hardening of Wind River’s mission‑critical cloud infrastructure solutions. You will guide security strategy across virtualization, orchestration, and distributed edge computing systems—ensuring the platform meets stringent requirements for telco, aerospace, defense, and industrial deployments. This role bridges advanced cloud engineering, embedded systems knowledge, and modern cybersecurity practices. 

 

Key Responsibilities 

Security Architecture & Strategy 

  • Define and evolve the security architecture for Wind River Private Cloud Platform, including control plane components, hypervisors, networking stacks, and orchestration frameworks. 

  • Lead threat modeling, security risk assessments, and mitigation strategies across distributed cloud/edge environments. 

  • Establish platform security requirements, secure design patterns, and architectural principles. 

  • Detailed architecture and design definition of individual product security features 

  • Providing direction and specific requirement input to development teams 

  • Working with business team and customers to define/clarify requirements 

  • Evaluating and proposing technology choices 

Product & Platform Security 

  • Drive secure-by-default configurations across compute, storage, networking, and platform services. 

  • Own the security roadmap for the platform, ensuring alignment with industry standards (NIST, CIS, FIPS, etc.). 

  • Oversee vulnerability management, secure boot, runtime integrity measures, API security, and cryptographic services. 

  • Partner with product, engineering, and QA teams to embed security throughout SDLC (shift‑left security). 

Technical Leadership 

  • Serve as the top technical expert and advisor for product security across cloud, containerization, virtualization, and real‑time/edge systems. 

  • Mentor senior engineers and influence engineering directors and executives on cybersecurity tradeoffs and priorities. 

  • Represent the organization in security reviews, customer briefings, escalations, and cross-functional technical committees. 

Security Operations & Compliance 

  • Guide secure deployment patterns and operational security practices for private cloud customers. 

  • Support incident investigation, root‑cause analysis, and remediation for platform-level vulnerabilities. 

  • Define and enforce policies for SBOM, supply chain integrity, CI/CD security, and secure artifact distribution. 

Collaboration & Influence 

  • Collaborate with teams across Wind River Studio ecosystem (edge platform, analytics, DevSecOps tooling). 

  • Represent Wind River in standards bodies and industry working groups (ETSI, CNCF, Linux Foundation, etc.). 

  • Partner with customer engineering teams on secure deployment architectures for telecom and mission‑critical environments. 

 

Required Qualifications 

  • 15+ years in cloud/platform engineering, embedded systems, or cybersecurity with deep architectural ownership. 

  • Expertise in product security, including threat modeling, secure architecture, and vulnerability management. 

  • Strong knowledge of: 

  • Kubernetes Security Hardening - RBAC, Secrets, Encryption, Security Policies 

  • Certificate Management, PKI, EJBCA, cert-manager 

  • Authentication mechanisms: OIDC, LDAP, Active Directory 

  • Linux internals, kernel security, container hardening and breakout protection 

  • Practical cryptography algorithms and application 

  • Hardware root of trust (TPM, UEFI Secure Boot, Trusted Boot) 

  • CIS Benchmarks for Linux and Kubernetes 

  • Virtualization technologies (KVM, QEMU, etc.) 

  • Cloud networking, SDN/NFV, microservices security 

  • Hands-on experience with CI/CD security, SAST, DAST, container scanning, SBOM generation. 

  • Proven ability to lead complex cross‑organizational security initiatives. 

 

Preferred Qualifications 

  • Experience with private cloud infrastructure, Titanium Cloud, or telecom/industrial -grade cloud infrastructure. 

  • Background in telco (5G), aerospace/defense, industrial IoT, or other safety/security‑critical domains. 

  • Familiarity with Yocto, embedded Linux, RTOS environments. 

  • Participation in open-source security initiatives or upstream kernel/cloud projects. 

  • Advanced degree in Computer Science, Electrical Engineering, Cybersecurity, or similar field. 

 

Success Indicators 

  • Demonstrated improvements in platform security posture, measurable vulnerability reduction, and secure SDLC maturity. 

  • Adoption of security architecture patterns across engineering teams. 

  • Strong technical influence with executives, partners, and global customers. 

  • Delivery of innovative, scalable platform security capabilities for distributed cloud and edge environments. 

 

Privacy Notice - Active Candidates: https://www.aptiv.com/privacy-notice-active-candidates

Aptiv is an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, gender identity, sexual orientation, disability status, protected veteran status or any other characteristic protected by law.

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

#LI-JP1

Privacy Notice - Active Candidates: https://www.aptiv.com/privacy-notice-active-candidates

Aptiv is an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, gender identity, sexual orientation, disability status, protected veteran status or any other characteristic protected by law.

Similar Jobs

54 Minutes Ago
Hybrid
15-20 Hourly
Junior
15-20 Hourly
Junior
eCommerce • Fashion • Retail • Sales • Wearables • Design
Provides customer service and sales support in a luxury retail store. Responsibilities include welcoming clients, operating POS and cash wrap, suggesting products, processing shipments and transfers, maintaining stock levels, replenishing the sales floor, executing visual merchandising updates, supporting social media engagement, and following housekeeping and loss-prevention procedures. Requires flexible availability, physical ability to handle stockroom and sales-floor tasks, and strong communication and organizational skills.
Top Skills: InternetIpadLaptopMobile PosPosWalkie-Talkie
54 Minutes Ago
In-Office
99K-162K Annually
Senior level
99K-162K Annually
Senior level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Develop and execute ASIC, FPGA, and SoC design verification activities using simulation, SystemVerilog, UVM, coverage analysis, debugging, requirements traceability, reusable verification infrastructure, and UVCs. Support integration and system-level investigations, contribute to coverage closure, communicate risks and dependencies, and progressively own verification scope of moderate complexity. Level II engineers develop independence, while Level III engineers independently manage assigned verification scope.
Top Skills: AsicFpgaOopRtlSimulationSocSystemverilogUvcUvm
54 Minutes Ago
In-Office
99K-162K Annually
Mid level
99K-162K Annually
Mid level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Designs and supports ASIC, FPGA, and mixed digital systems for aerospace and defense programs. Responsibilities include requirements development, architecture support, HDL/RTL development, simulation, debugging, synthesis, FPGA implementation, timing analysis, verification collaboration, integration, troubleshooting, and technical status communication. The role may involve owning functional blocks, supporting subsystem efforts, and contributing to cross-functional technical leadership depending on experience level.
Top Skills: AsicClock-Domain Crossing (Cdc)FpgaHdlRtlSocStatic Timing AnalysisVlsi

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account