Senior Product Security Engineer

Rivian and Volkswagen Group TechnologiesIrvine, CA
$149,800 - $205,900

About The Position

Rivian and Volkswagen Group Technologies is a joint venture between two industry leaders with a clear vision for automotive’s next chapter. From operating systems to zonal controllers to cloud and connectivity solutions, we’re addressing the challenges of electric vehicles through technology that will set the standards for software-defined vehicles around the world. The road to the future is uncharted. By combining our expertise across connectivity, AI, security and more, we’ll map a new way forward. Working together, we’ll create a future that’s more connected, more intelligent, more sustainable for everyone. We're looking for a senior/staff security engineer who is a genuine PKI expert, comfortable owning certificate lifecycle management end-to-end and who also brings solid platform/infrastructure experience. You'll help us run and modernize the systems that issue, provision, and manage digital identity for our products, with particular depth needed in charging standards (e.g., ISO 15118, OCPP) and authN/authZ standards (e.g., X.509, mTLS, OAuth2, OIDC).

Requirements

  • 5+ years in security engineering with hands-on, production experience in PKI and certificate lifecycle management (issuance, provisioning, renewal, revocation).
  • Strong grasp of public-key cryptography fundamentals: X.509 certificates, TLS/mTLS, HSM/TPM-backed key storage.
  • Working knowledge of authN/authZ standards (X.509, mTLS, OAuth2, OIDC) and experience implementing them in production systems.
  • Familiarity with EV charging PKI or charging communication standards (e.g., ISO 15118, OCPP), or comparable domain-specific PKI experience.
  • Proficiency in at least one backend language (Go, Python, or similar) and experience building/operating production services.

Nice To Haves

  • Experience with service mesh and workload identity technologies (e.g., Istio, SPIRE/SPIFFE, Cilium/eBPF).
  • Experience designing API gateway/ingress patterns for external or partner-facing traffic, including mTLS termination and identity-provider integration.
  • Experience operating cloud infrastructure with strong observability practices (metrics, tracing, logging).
  • Exposure to intrusion detection or broader security monitoring across distributed systems.
  • Experience in a regulated or safety-critical industry.
  • Track record contributing to cross-functional security architecture decisions at scale.

Responsibilities

  • Own PKI and certificate lifecycle management: design, issue, provision, renew, and revoke certificates across the systems you support; maintain trust stores and certificate authorities.
  • Apply charging-standard expertise: work with EV charging PKI and protocols (e.g., ISO 15118 Plug & Charge, OCPP) to support certificate provisioning and interoperability for charging use cases.
  • Design and implement authN/authZ: apply standards such as X.509, mTLS, OAuth2, and OIDC to secure service-to-service and client-facing authentication and authorization flows.
  • Build and operate platform infrastructure: work with Kubernetes, service mesh, and workload identity technologies to move cert issuance and auth off bespoke one-off solutions and onto shared, reusable infrastructure.
  • Support secure boot and key management: contribute to signature validation, key revocation, and related secure-provisioning workflows.
  • Operate what you build: deploy, monitor, and support production services (GitOps deployment, observability/tracing), and be a responsive point of contact when certificate or auth issues arise.
  • Document and mentor: write clear design docs and runbooks, and help other engineers ramp up on PKI and platform concepts.

Benefits

  • Competitive base salary
  • Annual company performance bonus program
  • Equity in the form of Restricted Stock Units (RSUs)
  • Health coverage
  • Retirement savings
  • Time off
  • Family planning programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service