Functional Safety Lead

AtomsSan Francisco, CA
$182,000 - $238,000Onsite

About The Position

This role owns the functional safety analysis of our automated vehicle platform and its sensor suite: what can fail, how it manifests, what the system does about it, and whether that response is good enough. You will do the analysis yourself, and your assessment informs releases. It also owns something that often goes unowned — determining the safety impact of change. We move constantly, and someone has to be able to say quickly and credibly what a given change does to the safety argument. That is this role. The third part is leverage. The safety case engineers work from your method: the analysis structures they adapt to their own scope, the library of platform-level safety items they reference instead of re-deriving, and the traceability they query. The job is not finished when your analysis is correct — it is finished when the method is executable by someone who is not you. We expect this role to be materially more productive than the same role was three years ago, and we expect AI tooling to be the reason. We are adopting systems purpose-built to accelerate safety analysis — failure mode generation, gap checking across large analyses, and interrogation of large requirements and standards corpora — and this role is expected to put them to work and shape what they become. Use them as a working instrument in the analysis itself: generating and stress-testing failure mode candidates, cross-checking analyses for gaps, interrogating large requirement and standards corpora, and first-pass triage across a large change surface. Build your own tooling rather than filing tickets for it, and keep it running once other people depend on it. Be rigorous about the boundary. A generated failure mode list is a hypothesis to verify, never evidence. Safety claims require human judgment and traceable justification. We would rather hire a strong functional safety engineer who is curious and moving fast on AI tooling than someone who has the vocabulary but not the practice. Be prepared to show us how you actually work.

Requirements

  • 8+ years in functional safety for automotive, automated vehicles, aerospace, industrial automation, or another safety-critical hardware domain, with deep hands-on analysis experience rather than process oversight alone.
  • Demonstrated ownership of HARA, FMEA, and FTA on real systems that shipped. We will go deep on specific analyses you have authored.
  • Strong standards fluency: ISO 26262, ISO 21448 (SOTIF), and UL 4600 — with the judgment to apply them proportionately rather than performing compliance theater.
  • Experience making release-gating safety calls under time pressure with incomplete information, and the ability to explain both your framework and a time you got it wrong.
  • Real hardware and electrical depth: sensors, actuation interfaces, power and grounding, wiring, EMC, redundancy architecture. You are comfortable at the vehicle with a schematic and a scope.
  • Programming ability — Python or similar — sufficient to analyze field data, build your own tooling, and work fluently with an AI coding assistant.
  • You have built something other engineers used — a tool, script, template or pipeline that colleagues adopted because it beat what they had.
  • The temperament to serve internal customers without being captured by them — your job is to give them something correct and fast, not something accommodating.

Nice To Haves

  • Experience authoring or defending a safety case to an external party — a customer, regulator, assessor or insurer.
  • A functional safety certification such as TÜV FSEng, or equivalent demonstrated depth.
  • Experience with fault injection frameworks, HIL, or automated safety verification pipelines.

Responsibilities

  • Own hazard analysis and risk assessment for the platform — derive safety goals and requirements, drive them into the architecture, and maintain the traceability from hazard to requirement to verification evidence.
  • Lead fault and failure analysis across the platform — compute, power and actuation interfaces — and across the sensor suite, covering both hard faults and degraded modes.
  • Own sensor suite safety: sensing sufficiency and degradation — what coverage exists, how it erodes under adverse conditions, and how faults are detected and handled.
  • Determine the safety impact of change. Hardware revisions, sensor swaps, software releases, new platform variants and changes to the operating domain all move the safety argument, and you decide what each one costs.
  • Own change impact assessment — what triggers an assessment, what depth each class of change warrants, what evidence clears it, and what escalates — and keep it fast enough to stay on the critical path.
  • Own the method the safety case engineers work from: reusable analysis structures they adapt to their own scope, a library of platform-level safety items they reference instead of re-deriving, and queryable hazard-to-evidence traceability.
  • Ship tooling they run themselves rather than analysis you run for them — change-impact triage that flags which arguments a given change touches, automated traceability checks, and detection of where an argument has gone stale.

Benefits

  • Medical, Dental, Vision, Disability, and Life Insurance
  • Flexible Spending Account / Health Savings Account Options
  • 401(k)
  • Equity
  • Sick Time, Unlimited Flexible Time Off, and Paid Holidays
  • Paid Parental Leave
  • Pre-Tax Commuter Benefit Plan
  • Team lunch in our SoMa office every Tuesday and Thursday
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service