- Robot type
- Autonomous Vehicle
- Location
- Foster CityCaliforniaUSA
- Job type
- IT
- Posted
- Jun 3, 2026
- Salary
- $228,000–$273,000 a year
Full-time
Staff Network Security Architect
Job description
Zoox — Staff Network Security Architect (Foster City, California).
Job responsibilities
- Own Zoox's network security reference architecture across corporate, data center, lab/OT, and edge environments, and define the segmentation and trust model that everything else is built against
- Serve as the security design authority for new infrastructure: run design reviews and threat models early enough to change the design, and define the criteria under which a design is approved, conditionally approved,…
- Translate security frameworks into buildable engineering standards. Map controls to NIST CSF 2.0, NIST 800-53, and ISO 27001 (IEC 62443 a plus for OT/lab), and turn them into reference patterns, guardrails, and…
- Define the zero-trust and identity-to-network strategy, including 802.1X/certificate-based NAC, PKI trust hierarchy, ZTNA and remote access, and how non-human and headless lab/vehicle assets are authenticated and…
- Architect secure hybrid and multi-cloud connectivity (CloudWAN, SD-WAN, transit and inspection architectures, cloud-native controls) and define where inspection, enforcement, and logging belong
- Drive secure-by-design into the delivery path: encode standards as Terraform modules, policy-as-code, and CI/CD guardrails so the secure pattern is the default one, not a review gate
- Own data flow and trust boundary analysis for sensitive environments, including vehicle data, lab telemetry, and third-party and vendor connectivity
- Own the governance side of architecture: risk articulation for leadership, exception and compensating control decisions, architecture decision records, and the multi-year roadmap that retires legacy patterns
Job requirements
- 10+ years in network and security engineering, including 4+ years in an architecture or technical-lead role where you owned designs others implemented
- Demonstrated ownership of an enterprise-scale segmentation or zero-trust architecture from concept through adoption, including what you changed when it met reality
- Ability to reason about security frameworks as design inputs, not audit artifacts: fluency with NIST CSF 2.0, NIST 800-53, and ISO 27001, and a track record of turning them into engineering standards and evidence
- Depth in threat modeling and secure-by-design for network and infrastructure, including data flow analysis, trust boundaries, blast radius, and failure modes
- Strong platform grounding to keep designs buildable: next-gen firewalls (Palo Alto, Fortinet), AWS NFW, IDS/IPS, NAC/802.1X, PKI, VPN, ZTNA (Zscaler, Prisma Access, or equivalent), and core protocols (TCP/IP, BGP,…
- Cloud network security depth in AWS and/or GCP, including inspection architecture, cloud-native enforcement, and IaC delivery with Terraform
- OT, ICS, robotics, automotive, or manufacturing network security experience (IEC 62443, Purdue model, or equivalent)
- Autonomous vehicle or safety-critical systems exposure
Similar jobs
Zoox · IT
Senior IT Engineer, Audio Visual
Foster City, California
Zoox · IT
SAP BRIM Engineer - Convergent Mediation (CM)
Foster City, California
Zoox · Business Operations
Vehicle Safety - Occupant Protection Engineer
Foster City, California
Zoox · Business Operations
Validation Engineer, Feature Integration
Foster City, California
