Safety Case Engineer

Atoms•San Francisco, CA
•$149,000 - $188,000•Onsite

About The Position

Atoms is building the machines that power the next era of progress. We are developing Physical AI—real-world robots for industries like food, mining, and transport. Our systems are designed to understand, predict, and control the physical world with precision, aiming to make complex physical operations more reliable, scalable, and productive. This involves deep integration across hardware, software, AI, operations, manufacturing, and real estate. We deploy, operate, learn from, and improve our systems at scale. This role involves owning a defined scope of the safety case end-to-end, from initial draft to final sign-off and ongoing maintenance. The Safety Case Engineer will be the author of record, responsible for defending their arguments. This includes defining the scope of the argument, its assumptions, exclusions, and the hazards that cannot arise within that scope. A key part of the role is judging evidence sufficiency, including operating experience, coverage against cases, and the source of evidence, working closely with functional safety, scenario validation, and fleet operations leads. The engineer will create claim-argument-evidence maps, convene reviews, and act as an independent reviewer for other scopes. They will also be a demanding customer of shared methods and tooling, providing feedback for improvement, and will utilize AI tooling for tasks such as drafting, hazard analysis, coverage checking, and impact analysis of upstream revisions.

Requirements

  • 7+ years across functional safety, autonomy behaviour and fleet operations, with real hands-on depth in at least two and working fluency in the third.
  • Authored a structured safety argument, not reviewed one — GSN or an equivalent claim-argument-evidence structure, on a real system, defended to someone who pushed back hard.
  • Demonstrated hazard analysis ownership (HARA, FMEA, FTA or equivalent) and demonstrated scenario-based validation ownership.
  • Rigour about provenance. You instinctively distinguish a measurement from an estimate from a placeholder, and label them as such rather than letting a number acquire authority by being written down.
  • The willingness to speak up. Some of this will be commercially inconvenient to leave unsigned, and we need people who can say an argument is not ready, say exactly what would make it ready, and what are the consequences not.
  • Standards fluency across ISO 26262, ISO 21448 (SOTIF), UL 4600, and SAE J3016, with the judgment to apply them proportionately to a scoped argument rather than reproducing a full-program process at small scale.
  • Comfort with the statistics of exposure, rare events and coverage, and with surrogate safety measures and their limits.
  • Programming ability in Python or similar, sufficient to work with fleet data, build your own tooling and work fluently with an AI coding assistant.
  • Exceptional written precision. More than any other role on this team the deliverable is a document that has to stand up without you in the room; vague writing here is not a style problem, it is a safety problem.
  • The disposition three interchangeable seats need: focused enough to go deep on what you own, flexible enough to pick up a colleague's, and generous enough to make peer review genuinely useful rather than ceremonial.

Responsibilities

  • Own a defined scope of the safety case end to end, from first draft to signed, including its upkeep afterward when something it depends on is revised.
  • Define what your argument covers and what it explicitly does not: the conditions it assumes, the exclusions and why they hold, and the hazards that cannot arise within the scope.
  • Judge evidence sufficiency: how much operating experience there is and how it was counted, coverage against each case, and where the evidence came from. Working closely with the functional safety, scenario validation and fleet operations leads to obtaining the evidence.
  • Write the claim-argument-evidence map. So it's clear when it holds and when it doesn't.
  • Convene review when the work is ready and not before, carry reviewer comments to documented resolution, and serve as independent reviewer on scopes you do not own.
  • Be a demanding customer of the shared method and tooling built by the functional safety, scenario validation and fleet operations leads. When a rule is missing or ambiguous, or a tool makes the wrong thing easy, say so loudly — a local workaround does not stay local.
  • Use AI tooling as part of the work: drafting from a template, generating and stress-testing candidate hazard sets, cross-checking coverage against the scenario library, tracing hazard to test to evidence, and finding where an upstream revision has invalidated something already written.

Benefits

  • Medical, Dental, Vision, Disability, and Life Insurance
  • Flexible Spending Account / Health Savings Account Options
  • 401(k)
  • Equity
  • Sick Time, Unlimited Flexible Time Off, and Paid Holidays
  • Paid Parental Leave
  • Pre-Tax Commuter Benefit Plan
  • Team lunch in our SoMa office every Tuesday and Thursday
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service