Senior Security Engineer

Weave Robotics — United States · Posted ~19 hours ago

Senior Full-time

Skills

Cybersecurity Security engineering Cloud security Embedded systems security Application security Network security Cloud Embedded computing

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A Senior Security Engineer will help secure sophisticated autonomous devices operating in real-world environments. The work spans an integrated stack of sensors, cameras, actuators, embedded computing, cloud infrastructure, and consumer software, providing opportunities to address security challenges across hardware and software boundaries.

Highlights

Senior security role in a rapidly growing robotics environment, protecting an integrated ecosystem spanning cameras, sensors, actuators, embedded computing, cloud infrastructure, and consumer applications.

Description

Join Us, and Ship Robots Weave was founded to build the robots we’d want to have in our own home. We believe the next generation of robotics will transform everyday life by enabling people to do more and to reclaim time to spend on what’s important. We also believe robots are in a sense like any other product: to matter, they have to ship. Our robots are already operating in real homes and businesses, giving us the opportunity to rapidly improve from real-world experience. With a growing team, strong customer demand, and capital for expansion, we’re entering an exciting stage of growth—and we’re looking for people with exceptional talent and standards to help bring home robotics to millions of households. The Role At Weave, we’re building robots designed to operate in the most personal environment there is: the home. Our robots combine cameras, sensors, actuators, embedded compute, cloud infrastructure, and consumer applications into a deeply integrated system—and earning our customers’ trust requires making security a fundamental part of that system from the beginning. As a Senior Security Engineer, you’ll work on security and system integrity across the full surface area of our product, from embedded devices and robot software to cloud infrastructure, APIs, mobile applications, and fleet operations. You’ll work directly with engineers to threat-model new systems, find vulnerabilities, design secure architectures, and build the infrastructure that protects robots already operating in the real world. This is a highly hands-on role: you’ll help define our long-term security strategy while remaining close enough to the product to inspect code, probe systems, investigate incidents, and ship fixes yourself. Responsibilities Own product security: Define and continuously improve the security architecture of our robots, applications, backend services, and supporting infrastructure. Threat modeling & secure design: Lead threat modeling and security reviews for new hardware and software capabilities, identifying remote and physical attack surfaces and designing mitigations before systems reach production. Robot & embedded security: Secure device identity, boot and update chains, firmware, embedded Linux systems, and hardware interfaces. Cloud & application security: Identify and mitigate vulnerabilities across cloud infrastructure, APIs, authentication systems, web services, and iOS/Android applications. Security testing: Perform code review, penetration testing, vulnerability research, and adversarial testing across our product stack. Develop tooling that makes security testing increasingly automated. Detection & incident response: Build logging, monitoring, detection, and incident-response capabilities that allow us to rapidly identify, investigate, contain, and remediate security events. Raise the security bar: Establish practical security standards and processes, educate engineers, and build a culture where security is owned across the engineering organization. What You'll Bring Product security expertise: 4+ years securing connected products, embedded systems, robotics, IoT, autonomous systems, or other physical platforms, with experience reasoning across hardware, firmware, embedded Linux, operating systems, networks, cloud services, and applications. Linux & systems security: Strong understanding of Linux security boundaries, processes, permissions, networking, containers, system hardening, and common privilege-escalation techniques. Application security: Experience finding and mitigating vulnerabilities across APIs, backend services, web or mobile applications, including familiarity with OWASP Top 10 and modern application security practices. Software engineering: Strong programming ability in Python, C++, Go, Rust, or similar languages, with the ability to reason about production code and build security tooling yourself. Security testing: Hands-on experience with source-code review, SAST/DAST, dependency analysis, fuzzing, penetration testing, and security tools such as Burp Suite, Semgrep, CodeQL, Ghidra, or similar. Threat modeling: Experience using structured approaches such as STRIDE, attack trees, or similar methodologies to reason about complex systems and drive architectural improvements. Incident response: Experience investigating security incidents, analyzing logs and telemetry, performing root-cause analysis, and driving remediation. Nice to Have Networking depth: Familiarity with Ethernet, Wi-Fi, TCP/IP, and common network protocols, including experience using Wireshark, tcpdump, or similar packet-analysis tools to diagnose networking and security issues. Security standards: Familiarity with security standards and guidance relevant to connected consumer products, such as NIST IR 8259, NIST SSDF, UL 2900, or similar. Connected-device security: Experience with device provisioning, PKI/mTLS, device identity, signed OTA updates, credential rotation/revocation, and fleet-scale secrets management.