Skip to content

Jobs

Overland AI

Robot type
Autonomous Vehicle · Defense
Location
SeattleWashingtonUSA
Job type
Software
Posted
Mar 16, 2026
Full-time

Product Security Engineer

Job description

We are looking for a mission-driven Product Security Engineer to embed security into the entire lifecycle of our cutting-edge robotic systems and our command and control system. You will be responsible for hardening our autonomous ground vehicles against cyber threats in complex, contested environments. You will own compliance with our customer's contract requirements for cyber security.

In this role, you will take ownership of the security architecture for our robotic systems, ensuring that every component—from firmware to command interfaces—is designed, implemented, and validated with security at its core.

Job responsibilities

  • Lead the design and validation of security controls that ensure system integrity, intrusion prevention, secure logging, and data protection for robotic platforms.
  • Collaborate with customers, regulators, and internal teams to define and document security requirements that guide software development and system integration.
  • Ensure compliance with CSEIG v3.0, DISA STIGs, and NIST 800‑53/171 by implementing required controls and preparing evidence for certification and authorization (ATO/ATC) activities.
  • Drive a secure software development lifecycle (SDLC) by establishing policies, gates, and checklists across design, code review, CI/CD, and release processes.
  • Develop secure firmware and update mechanisms, including signed, atomic, and recoverable updates with built‑in health checks, CVE management, and SBOM generation.
  • Harden operating systems (Ubuntu and NixOS) through CIS/STIG baselines, AppArmor/SELinux configuration, systemd hardening, and least‑privilege enforcement.
  • Strengthen physical security through tamper‑evident designs, interface protection, and side‑channel attack mitigation.
  • Implement cryptographic controls including validated crypto modules, FIPS 140‑3 compliance, TPM management, and secure/measured boot processes.

Job requirements

  • BS in CS/EE or related, or equivalent experience
  • 6+ years in cybersecurity or secure software development, with no less than 2 years in a product security or offensive security role
  • Direct experience with the Department of Defense (DoD) Risk Management Framework (RMF), NIST 800-53, CNSSI 1253, and documenting security controls for Authority to Operate (ATO) or Authority to Connect (ATC) packages…
  • Proven ownership of SAST/SCA/DAST and CI/CD security controls
  • Strong Linux internals and hardening experience (Ubuntu and/or NixOS)
  • Hands-on with cryptography engineering, key management, and secure boot chains
  • Experience shipping signed firmware/OS images
  • Proficiency in either Python or C++

Similar jobs