View original listing & apply ↗
Listed through the employer’s public Lever careers page.
Last checked 9/24/2026, 4:53:01 AM.
Report or correct this listing
Role description
Zoox's Network Security team architects and defends the digital borders of the company, from corporate offices to engineering labs and product/mission environments. As Staff Network Security Architect, you own the target-state design for how Zoox segments, connects, and controls trust across enterprise IT, OT and lab networks, and hybrid cloud (AWS, GCP). You set the standards other teams build to, you are the security design authority on new infrastructure, and you are accountable for the coherence of the whole picture rather than the health of any one platform. You'll partner closely with Network Engineering, IT, Product Security, Hardware, and Software Engineering, and you'll influence far more systems than you personally operate.
In This Role, You Will...
• Own Zoox's network security reference architecture across corporate, data center, lab/OT, and edge environments, and define the segmentation and trust model that everything else is built against
• Serve as the security design authority for new infrastructure: run design reviews and threat models early enough to change the design, and define the criteria under which a design is approved, conditionally approved, or rejected
• Translate security frameworks into buildable engineering standards. Map controls to NIST CSF 2.0, NIST 800-53, and ISO 27001 (IEC 62443 a plus for OT/lab), and turn them into reference patterns, guardrails, and acceptance criteria engineers can implement without interpreting policy
• Define the zero-trust and identity-to-network strategy, including 802.1X/certificate-based NAC, PKI trust hierarchy, ZTNA and remote access, and how non-human and headless lab/vehicle assets are authenticated and authorized
• Architect secure hybrid and multi-cloud connectivity (CloudWAN, SD-WAN, transit and inspection architectures, cloud-native controls) and define where inspection, enforcement, and logging belong
• Drive secure-by-design into the delivery path: encode standards as Terraform modules, policy-as-code, and CI/CD guardrails so the secure pattern is the default one, not a review gate
• Own data flow and trust boundary analysis for sensitive environments, including vehicle data, lab telemetry, and third-party and vendor connectivity
• Own the governance side of architecture: risk articulation for leadership, exception and compensating control decisions, architecture decision records, and the multi-year roadmap that retires legacy patterns
• Set technical direction and raise the bar across the team through mentorship, design review, and written standards rather than through direct ownership of day-to-day operations
Qualifications
• 10+ years in network and security engineering, including 4+ years in an architecture or technical-lead role where you owned designs others implemented
• Demonstrated ownership of an enterprise-scale segmentation or zero-trust architecture from concept through adoption, including what you changed when it met reality
• Ability to reason about security frameworks as design inputs, not audit artifacts: fluency with NIST CSF 2.0, NIST 800-53, and ISO 27001, and a track record of turning them into engineering standards and evidence
• Depth in threat modeling and secure-by-design for network and infrastructure, including data flow analysis, trust boundaries, blast radius, and failure modes
• Strong platform grounding to keep designs buildable: next-gen firewalls (Palo Alto, Fortinet), AWS NFW, IDS/IPS, NAC/802.1X, PKI, VPN, ZTNA (Zscaler, Prisma Access, or equivalent), and core protocols (TCP/IP, BGP, OSPF, VLAN, TLS/PKI)
• Cloud network security depth in AWS and/or GCP, including inspection architecture, cloud-native enforcement, and IaC delivery with Terraform
Bonus Qualifications
• OT, ICS, robotics, automotive, or manufacturing network security experience (IEC 62443, Purdue model, or equivalent)
• Autonomous vehicle or safety-critical systems exposure
• Certifications: CISSP-ISSAP, SABSA, TOGAF, CCIE Security, PCNSE, AWS Security Specialty
• Experience applying AI/ML to network or cloud security (anomaly detection, behavioral analytics, LLM-assisted design review or policy analysis)
About Zoox
Zoox is developing the first ground-up, fully autonomous vehicle fleet and the supporting ecosystem required to bring this technology to market. Sitting at the intersection of robotics, machine learning, and design, Zoox aims to provide the next generation of mobility-as-a-service in urban environments. We’re looking for top talent that shares our passion and wants to be part of a fast-moving and highly execution-oriented team.
Follow us on LinkedIn
Accommodations
If you need an accommodation to participate in the application or interview process please reach out to accommodations@zoox.com or your assigned recruiter.
A Final Note:
You do not need to match every listed expectation to apply for this position. Here at Zoox, we know that diverse perspectives foster the innovation we need to be successful, and we are committed to building a team that encompasses a variety of backgrounds, experiences, and skills.
Similar jobs
- Security Systems Engineer at Palantir · Seattle, WA
- Senior Information Security Engineer at Match Group · Palo Alto, California; San Francisco, California; Los Angeles, California; New York, New York; Vancouver, British Columbia
- Senior Software Engineer, Continuous Integration at Zoox · Foster City, CA
- Senior Data Product Engineer at Match Group · Vancouver, British Columbia
- Systems Test Engineer, System Behavior Analysis at Zoox · San Diego, CA
- Manager - Model Evaluation at Zoox · Foster City, CA