Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
Communication @ 6
Compliance
Leadership @ 8
Linux @ 4
Python @ 4
Robotics @ 4
Security @ 8
Software Development @ 4
Technical Leadership @ 8
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
NVIDIA is seeking a Senior Product Security Lead to direct product-security strategy and delivery for NVIDIA Jetson, Linux for Tegra (L4T), and the JetPack software platform. Jetson supports next-generation robotics, autonomous machines, and edge-AI products. This role leads product security across architecture, development, release, vulnerability response, and customer productization, coordinating security efforts across silicon, firmware, operating system, platform, and application teams.
Responsibilities
- Oversee and guide the complete product-security strategy and roadmap for Jetson, L4T, and JetPack, from architecture and development through rollout and post-launch support.
- Establish product-level security mandates, architectural principles, release benchmarks, and lifecycle methodologies.
- Embed secure-by-design principles across firmware, boot software, the Linux kernel, device drivers, system software, containers, and platform services.
- Provide hands-on security engineering mentorship and partner with silicon, firmware, manufacturing, and platform-security teams on secure boot, hardware roots of trust, key provisioning, device identity, debug security, trusted execution, rollback protection, and secure updates.
- Lead threat analysis and vulnerability assessments, including TAVA, threat modeling, risk analysis, attack-surface analysis, and security architecture reviews.
- Coordinate the triage and resolution of security findings with NVIDIA PSIRT and engineering teams, assessing impact, prioritizing risk, and driving mitigations to closure.
- Support NVIDIA and customers in preparing for cybersecurity regulations such as the EU Cyber Resilience Act (CRA) by identifying technical gaps and coordinating evidence.
- Work with legal, compliance, and cybersecurity teams on regulatory interpretation and shared security responsibilities.
- Coordinate product-security materials, including SBOMs, security white papers, secure-deployment guidance, vulnerability-management documentation, and customer-facing security collateral.
- Serve as the primary product-security contact for Jetson engineering teams, program management, NVIDIA PSIRT, internal application teams, selected strategic customers, and partners.
- Develop scalable processes, reusable mentorship, and foundational security standards across multiple development teams.
- Define and track operational metrics for vulnerability response, security-requirement coverage, remediation progress, security-collateral generation, and product-release readiness.
Requirements
- Bachelor’s or Master’s degree, or equivalent experience, in Computer Science, Electrical or Computer Engineering, Cybersecurity, or a related field.
- At least 12 years of security-engineering experience, including at least 3 years in product security, platform security, security architecture, or technical leadership.
- Experience securing complex embedded, Linux, robotics, edge-computing, automotive, or system-on-chip platforms.
- Strong understanding of low-level systems software, including firmware, bootloaders, kernels, device drivers, system services, and containers.
- Strong platform-security fundamentals, including secure boot, roots of trust, trusted execution, key management, cryptography, secure provisioning, debug protection, and secure software updates.
- Practical experience with threat modeling, security architecture reviews, vulnerability assessments, risk analysis, and security-requirement development.
- Experience integrating security practices into the software development lifecycle, including code analysis, dependency management, vulnerability scanning, SBOM generation, and remediation workflows.
- Ability to lead and influence across organizations without direct authority in a global engineering environment with competing product and release priorities.
- Excellent written and verbal communication skills, with the ability to explain complex security risks to engineers, executives, customers, and non-security partners.
Preferred Qualifications
- Hands-on experience with NVIDIA Jetson, Tegra, L4T, JetPack, or similar ARM-based embedded platforms in robotics, industrial systems, autonomous machines, automotive, or edge AI.
- Experience with the CRA and security frameworks such as NIST SSDF, IEC 62443, ISO/SAE 21434, ISO/IEC 27001, or ETSI EN 303 645.
- Experience with coordinated vulnerability disclosures, CVEs, embargoed responses, software-supply-chain security, open-source dependencies, container security, signing, attestation, and build provenance.
- Experience with C, C++, Python, or related programming languages for embedded systems and security analysis.
- Experience developing customer-facing security white papers, guides, and threat assessments.
- Ability to balance security principles with platform performance, power, lifecycle requirements, and customer production needs.
Compensation and Benefits
The base salary range is USD 224,000–356,500, determined by location, experience, and the pay of employees in similar positions. The role is also eligible for equity and benefits.
More jobs at Nvidia
Legal Operations Engineer
Nvidia · Santa Clara, United States
USD 124,000-195,500 per year
Senior Systems Software Engineer, Kubernetes Scale - DGX Cloud
Nvidia · Spain
PLN 292,500-650,000 per year
Staff Site Reliability Operations
Nvidia · Hillsboro, United States
USD 144,000-230,000 per year
Senior Software Engineer - SOC Platforms
Nvidia · Santa Clara, United States
USD 184,000-356,500 per year
Senior Infrastructure Engineer - Connectivity
Nvidia · Santa Clara, United States
USD 208,000-333,500 per year
Similar jobs
Staff Workday Integration Engineer, Tech Foundations
Airbnb · United States
USD 180,000-225,000 per year
Senior Staff Site Reliability Operations
Nvidia · Seattle, United States
USD 184,000-264,500 per year
Senior Staff Site Reliability Operations Technical Lead
Nvidia · Durham, United States
USD 184,000-264,500 per year
Principal Site Reliability Engineer
Nvidia · Santa Clara, United States
USD 248,000-396,800 per year
Staff Software Engineer - Ingestion Platform
Reddit · United States
USD 217,000-303,900 per year
Distinguished Engineer, Agentic SDLC & Non-Linear Productivity
GitLab · Canada, United Kingdom, Poland, United States
USD 250,000-349,000 per year
Senior Manager, Compute Core Engineering
Nvidia · Santa Clara, United States
USD 248,000-391,000 per year
Principal System Software Engineer - AV Platform
Nvidia · Santa Clara, United States
USD 272,000-431,200 per year