Robotics Application & Product Security Engineer
full-time
principal
Posted 6 days ago
About this role
Who are We?
Field AIis transforming how robots interact with the real world. We are building risk-aware, reliable, and field-ready AI systems that address the most complex challenges in robotics, unlocking the full potential of embodied intelligence. We go beyond typical data-driven approaches or pure transformer-based architectures, and are charting a new course, with already-globally-deployed solutions delivering real-world results and rapidly improving models through real-field applications.
Learn more at https://fieldai.com.
About the Job
The Robotics Application & Product Security Engineer will establish and own the company’s application and product security program, embedding security directly into the software development lifecycle to prevent vulnerabilities before release. This role goes beyond traditional application security: you will secure distributed robotics systems operating in real-world environments, along with the cloud services that manage, update, and communicate with them. You will integrate security controls into CI/CD, implement risk-based guardrails that reduce exposure without slowing engineering velocity, and partner closely with development teams to ensure secure design, implementation, deployment, operation, and supply chain resilience. Your work will directly impact the safety, reliability, and trustworthiness of deployed robotic systems. You will act as both a builder and an adversary: designing secure systems while actively identifying how they could fail under real-world attack conditions through application security assessments, targeted penetration testing, and adversarial analysis. You will apply principles from quality assurance and validation to ensure that security controls are not only implemented, but continuously verified under realistic operating conditions.
What You’ll Get To Do
Orchestrate and bolster the application and product security program across robot, edge, and cloud systems. This includes defining standards, policies, and secure SDLC processes.
Evaluate and implement application security tooling (SAST, SCA, secrets scanning, container scanning, dependency analysis), including vendor assessment and ongoing evaluation of emerging tools and best practices.
Issue secure code training to issue best practices in design patterns, SOLID principals, and CLEAN architecture in regular lunch and learn sessions.
Prioritize tools that provide high-quality signals, integrate effectively into developer workflows, and support scalable security practices without unnecessary friction.
Partner with engineering teams to design secure architectures for APIs, services, and inter-process communication across robot, edge, and cloud systems.
Integrate automated security checks into CI/CD pipelines, including blocking pull request controls for high-risk findings.
Implement scheduled and out-of-band repository scans for exposed credentials, tokens, and misconfigurations.
Conduct threat modeling sessions for new features and architectural changes.
Perform targeted secure code reviews for high-risk components.
Define vulnerability prioritization criteria and drive remediation with engineering teams.
Develop secure coding guidance specific to the company's technology stack.
Deliver developer training and ongoing security consultation.
Report on vulnerability trends, remediation metrics, and program maturity to leadership.
Define and implement security controls for OTA update pipelines, including artifact signing, verification, and rollback safety.
Ensure software supply chain security practices, including SBOM generation, dependency risk analysis, and build provenance across the organization.
What You Have
Advanced degree (M.S., Ph.D.) in Computer Science, Computer Engineering, Electrical Engineering, or a related field, or equivalent practical experience.
15+ years of experience in application security, product security, or software security engineering.
Proven experience securing distributed systems and APIs in production environments.
Strong background in secure software development lifecycle, including threat modeling, vulnerability management, and security-focused quality assurance and validation practices (e.g., defining test strategies, validating security controls, and ensuring fixes are verifiable and durable).
Strong programming ability in one or more of: C/C++, Python, Rust, or similar systems-level languages, with the ability to read, understand, and modify production code.
Ability to design and execute security validation strategies that combine testing, adversarial techniques, and system-level reasoning to verify that controls are effective under realistic conditions.
Hands-on experience conducting application security assessments (Layer 7), including APIs, authentication/authorization flows, and business logic vulnerabilities.
Deep understanding of authentication, authorization, and secure communication protocols (TLS/mTLS, OAuth, PKI).
Experience integrating secur
Similar Jobs
Related searches:
On-site Jobs
Principal Jobs
On-site Principal Jobs
Principal Robotics & AutonomyPrincipal Backend & SystemsPrincipal AI InfrastructurePrincipal AI Safety & Security
AI Jobs in Irvine
Robotics & Autonomy in IrvineBackend & Systems in IrvineAI Infrastructure in IrvineAI Safety & Security in Irvine
distributed-systemssecurityroboticsplatforminfrastructure