Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
Communication @ 6
Compliance
Leadership @ 8
Linux @ 4
Python @ 4
Robotics @ 4
Security @ 8
Software Development @ 4
Technical Leadership @ 8
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
NVIDIA is seeking a Senior Product Security Lead to direct product-security strategy and delivery for NVIDIA Jetson, Linux for Tegra (L4T), and the JetPack software platform. Jetson supports next-generation robotics, autonomous machines, and edge-AI products. This role leads product security across architecture, development, release, vulnerability response, and customer productization, coordinating security efforts across silicon, firmware, operating system, platform, and application teams.
Responsibilities
- Oversee and guide the complete product-security strategy and roadmap for Jetson, L4T, and JetPack, from architecture and development through rollout and post-launch support.
- Establish product-level security mandates, architectural principles, release benchmarks, and lifecycle methodologies.
- Embed secure-by-design principles across firmware, boot software, the Linux kernel, device drivers, system software, containers, and platform services.
- Provide hands-on security engineering mentorship and partner with silicon, firmware, manufacturing, and platform-security teams on secure boot, hardware roots of trust, key provisioning, device identity, debug security, trusted execution, rollback protection, and secure updates.
- Lead threat analysis and vulnerability assessments, including TAVA, threat modeling, risk analysis, attack-surface analysis, and security architecture reviews.
- Coordinate the triage and resolution of security findings with NVIDIA PSIRT and engineering teams, assessing impact, prioritizing risk, and driving mitigations to closure.
- Support NVIDIA and customers in preparing for cybersecurity regulations such as the EU Cyber Resilience Act (CRA) by identifying technical gaps and coordinating evidence.
- Work with legal, compliance, and cybersecurity teams on regulatory interpretation and shared security responsibilities.
- Coordinate product-security materials, including SBOMs, security white papers, secure-deployment guidance, vulnerability-management documentation, and customer-facing security collateral.
- Serve as the primary product-security contact for Jetson engineering teams, program management, NVIDIA PSIRT, internal application teams, selected strategic customers, and partners.
- Develop scalable processes, reusable mentorship, and foundational security standards across multiple development teams.
- Define and track operational metrics for vulnerability response, security-requirement coverage, remediation progress, security-collateral generation, and product-release readiness.
Requirements
- Bachelor’s or Master’s degree, or equivalent experience, in Computer Science, Electrical or Computer Engineering, Cybersecurity, or a related field.
- At least 12 years of security-engineering experience, including at least 3 years in product security, platform security, security architecture, or technical leadership.
- Experience securing complex embedded, Linux, robotics, edge-computing, automotive, or system-on-chip platforms.
- Strong understanding of low-level systems software, including firmware, bootloaders, kernels, device drivers, system services, and containers.
- Strong platform-security fundamentals, including secure boot, roots of trust, trusted execution, key management, cryptography, secure provisioning, debug protection, and secure software updates.
- Practical experience with threat modeling, security architecture reviews, vulnerability assessments, risk analysis, and security-requirement development.
- Experience integrating security practices into the software development lifecycle, including code analysis, dependency management, vulnerability scanning, SBOM generation, and remediation workflows.
- Ability to lead and influence across organizations without direct authority in a global engineering environment with competing product and release priorities.
- Excellent written and verbal communication skills, with the ability to explain complex security risks to engineers, executives, customers, and non-security partners.
Preferred Qualifications
- Hands-on experience with NVIDIA Jetson, Tegra, L4T, JetPack, or similar ARM-based embedded platforms in robotics, industrial systems, autonomous machines, automotive, or edge AI.
- Experience with the CRA and security frameworks such as NIST SSDF, IEC 62443, ISO/SAE 21434, ISO/IEC 27001, or ETSI EN 303 645.
- Experience with coordinated vulnerability disclosures, CVEs, embargoed responses, software-supply-chain security, open-source dependencies, container security, signing, attestation, and build provenance.
- Experience with C, C++, Python, or related programming languages for embedded systems and security analysis.
- Experience developing customer-facing security white papers, guides, and threat assessments.
- Ability to balance security principles with platform performance, power, lifecycle requirements, and customer production needs.
Compensation and Benefits
The base salary range is USD 224,000–356,500, determined by location, experience, and the pay of employees in similar positions. The role is also eligible for equity and benefits.
More jobs at Nvidia
Senior Platform Security Engineer – Device Trust, Attestation, and Secure Browser
Nvidia · Santa Clara, United States
USD 196,000-310,500 per year
Senior Staff Software Engineer - Enterprise AI Platform
Nvidia · Santa Clara, United States
USD 200,000-322,000 per year
System Software Engineering Intern, GPU - 2027
Nvidia · Poland
PLN 117,800-204,100 per year
Senior Storage Platform Engineer
Nvidia · Santa Clara, United States
USD 168,000-333,500 per year
Senior Compute Platform Engineer, LSF - EDA Infrastructure
Nvidia · United States
USD 184,000-356,500 per year
Similar jobs
Principal Site Reliability Engineer
Nvidia · Santa Clara, United States
USD 248,000-396,800 per year
Principal Software Engineer – Infrastructure
Nvidia · Santa Clara, United States
USD 248,000-391,000 per year
Senior Embedded System Software Engineer – Platform Execution Lead
Nvidia · Santa Clara, United States
USD 224,000-356,500 per year
Senior Manager, Compute Core Engineering
Nvidia · Santa Clara, United States
USD 248,000-391,000 per year
Senior Software Engineer, Evaluation Flywheel — Autonomous Vehicles
Nvidia · Santa Clara, United States
USD 224,000-356,500 per year
Principal System Software Engineer - AV Platform
Nvidia · Santa Clara, United States
USD 272,000-431,200 per year
Senior SWQA Test Development Engineer
Nvidia · Santa Clara, United States
USD 168,000-322,000 per year
Platform Security Engineer, OpenBMC
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 320,000-405,000 per year