There are still lots of open positions. Let's find the one that's right for you.
As a Staff Technical Program Manager in Security Risk Management at Aurora, you will play a pivotal role in embedding security into every aspect of our products, which range from self-driving technology for freight-hauling semi-trucks to ride-hailing passenger vehicles. Your primary responsibility will be to drive security strategy and initiatives across the organization, ensuring that security is a fundamental part of the product development process. You will act as a bridge between Security and Product teams, moving seamlessly between high-level strategy and detailed execution to ensure that complex, cross-functional security programs are successfully integrated into product development. Your ability to lead, influence, and manage large-scale security initiatives will be essential in safeguarding our products and ensuring they meet the highest security standards. In this role, you will lead the development and execution of security assurance, governance, and risk management programs, ensuring they are deeply embedded into all phases of product development and aligned with company objectives. You will collaborate closely with product management, engineering, and security teams to assess product risks, prioritize security initiatives, and implement strategic controls that protect both product integrity and user trust. Additionally, you will oversee external security assessments and penetration tests, translating findings into actionable risk mitigation strategies that enhance product security. Your responsibilities will also include managing the security risk management program with a focus on product-related risks, ensuring alignment with enterprise risk management efforts and compliance with industry regulations. You will define and report on key performance indicators (KPIs) related to product and security risks, ensuring transparency and data-driven decision-making across the organization. This position offers flexible work locations for US-based employees, although full remote work is not available.