Aurora’s Cloud Security team’s mission is to design and build security capabilities for Aurora infrastructure and services. Aurora makes extensive use of public cloud infrastructure (AWS), Kubernetes and infrastructure-as-code technologies. This role requires a deep, hands-on understanding of cloud security principles and architecture, particularly within AWS and Kubernetes (EKS). As a Staff Engineer, you will help drive the vision, design, and implementation of security infrastructure, serving as a technical leader and mentor within the security team and across engineering. You can read more about our approach to security on our blog: Aurora's approach to cybersecurity for autonomous trucking . This role is expected to take ownership of and drive projects in one or more of these critical areas, depending on team needs and your specific expertise: Lead the design and implementation of core security infrastructure services, including certificate management (PKI), secrets management, and centralized authentication/authorization services leveraging standards like OIDC and SAML. Deep AWS Security Specialization: Architect and manage security boundaries and access controls for the entire AWS environment, including but not limited to: IAM Governance: Define and enforce least-privilege IAM roles and policies, establish strong IAM Access Boundaries using Service Control Policies (SCPs), and govern inter-service communication. Network Segmentation: Design and implement robust network security controls within VPCs, including Security Groups, Network ACLs, and private connectivity (VPC Endpoints, Transit Gateway). Design and implement security best practices and tooling within AWS and EKS, including controls such as admission controllers, image scanning/signing, pod security standards, and runtime security enforcement. Develop and manage systems for continuous security control monitoring, reporting, and automated remediation (e.g., using AWS Config, GuardDuty, or custom tools). Develop threat models independently, or jointly with system owners. Translate identified threats into tangible security requirements, ensuring controls are strategically deployed to strengthen the security posture of core platforms and services. Serve as a principal security consultant to product and platform engineering teams, conducting in-depth security design reviews for new systems and features, and proposing actionable security control implementations