Principal Technologist - Product Security

Aptiv

Walnut Creek (CA)

On-site

USD 180,000 - 280,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Aptiv, via Wind River Private Cloud Platform, seeks a Principal Technologist to set the security strategy for cloud/edge deployments. You will own architecture, threat modeling, and secure design while guiding cross‑functional teams across virtualization, orchestration, and distributed edge systems.

You will mentor senior engineers, influence executives on cybersecurity tradeoffs, and drive secure SDLC practices. This role emphasizes leadership in telco, aerospace, and industrial deployments.

Qualifications

  • 15+ years in cloud/platform engineering, embedded systems, or cybersecurity with architectural ownership.
  • Expertise in product security, threat modeling, secure architecture, and vulnerability management.
  • Strong knowledge of Kubernetes security, PKI, and virtualization tech.
  • Experience with secure software development lifecycle and SBOM practices.

Responsibilities

  • Define and evolve security architecture for Wind River Private Cloud Platform.
  • Lead threat modeling, risk assessments, and mitigation across cloud/edge.
  • Drive secure-by-default configurations and security roadmap alignment.
  • Oversee vulnerability management, secure boot, runtime integrity, and API security.

Skills

Cloud security
Threat modeling
Secure architecture
Kubernetes security
PKI management
Linux security
Virtualization security
CI/CD security
SBOM management

Education

Advanced degree in CS/EE/Cybersecurity

Tools

EJBCA
cert-manager
OpenSSL
KVM/QEMU

Job description

Role Summary

As a Principal Technologist specializing in Product Security for the Wind River Private Cloud Platform , you will serve as the technical authority driving the secure design, architecture, and lifecycle hardening of Wind River’s mission‑critical cloud infrastructure solutions. You will guide security strategy across virtualization, orchestration, and distributed edge computing systems—ensuring the platform meets stringent requirements for telco, aerospace, defense, and industrial deployments. This role bridges advanced cloud engineering, embedded systems knowledge, and modern cybersecurity practices.

Key Responsibilities
Security Architecture & Strategy
  • Define and evolve the security architecture for Wind River Private Cloud Platform, including control plane components, hypervisors, networking stacks, and orchestration frameworks.
  • Lead threat modeling, security risk assessments, and mitigation strategies across distributed cloud/edge environments.
  • Establish platform security requirements, secure design patterns, and architecturalprinciples.
  • Detailed architecture and design definition of individual product security features
  • Providing direction and specific requirement input to development teams
  • Working with business team and customers to define/clarify requirements
  • Evaluating and proposing technology choices
Product & Platform Security
  • Drive secure-by-default configurations acrosscompute, storage, networking, and platform services.
  • Own the security roadmap for the platform, ensuring alignment with industry standards (NIST, CIS, FIPS, etc.).
  • Oversee vulnerability management, secure boot, runtime integrity measures, API security, and cryptographic services.
  • Partner with product, engineering, and QA teams to embed security throughout SDLC (shift‑left security).
Technical Leadership
  • Serve as the top technical expert and advisor for product security across cloud, containerization, virtualization, and real‑time/edge systems.
  • Mentor senior engineers and influence engineering directors and executives on cybersecurity tradeoffs and priorities.
  • Represent the organization in security reviews, customer briefings, escalations, and cross‑functional technical committees.
Security Operations & Compliance
  • Guidesecuredeployment patterns and operational security practices for private cloud customers.
  • Support incident investigation, root‑cause analysis, and remediation for platform‑level vulnerabilities.
  • Define and enforce policies for SBOM, supply chain integrity, CI/CD security, and secure artifact distribution.
Collaboration & Influence
  • Collaborate with teams acrossWindRiver Studio ecosystem (edge platform, analytics,DevSecOpstooling).
  • Represent Wind River instandardsbodies and industry working groups (ETSI, CNCF, Linux Foundation, etc.).
  • Partner with customer engineering teams on secure deployment architectures for telecom and mission‑critical environments.
Required Qualifications
  • 15+ years in cloud/platform engineering, embedded systems, or cybersecurity with deep architectural ownership.
  • Expertise in product security , including threat modeling, secure architecture, and vulnerability management.
  • Strong knowledge of:
  • Kubernetes Security Hardening - RBAC, Secrets, Encryption, Security Policies
  • Certificate Management, PKI, EJBCA, cert‑manager
  • Authentication mechanisms: OIDC, LDAP, Active Directory
  • Linux internals, kernel security, containerhardeningand breakout protection
  • Practical cryptographyalgorithms and application
  • Hardware root of trust (TPM,UEFISecureBoot,TrustedBoot)
  • CIS Benchmarks for Linux and Kubernetes
  • Virtualization technologies (KVM, QEMU, etc.)
  • Cloud networking, SDN/NFV, microservices security
  • Hands‑on experience with CI/CD security, SAST, DAST, container scanning, SBOMgeneration.
  • Proven ability to lead complex cross‑organizational security initiatives.
Preferred Qualifications
  • Experience with private cloud infrastructure , Titanium Cloud, or telecom/industrial-grade cloud infrastructure.
  • Background in telco (5G), aerospace/defense, industrial IoT, or other safety/security‑critical domains.
  • Familiarity withYocto, embedded Linux, RTOS environments.
  • Participation in open‑source security initiatives or upstream kernel/cloud projects.
  • Advanced degree in Computer Science, Electrical Engineering, Cybersecurity, or similar field.
Success Indicators
  • Demonstrated improvements in platform security posture, measurable vulnerability reduction, and secure SDLC maturity.
  • Adoption of security architecture patterns across engineering teams.
  • Strong technical influence with executives, partners, and global customers.
  • Delivery of innovative, scalable platform security capabilities for distributed cloud and edge environments.

Privacy Notice - Active Candidates:https://www.aptiv.com/privacy-notice-active-candidates

Aptiv is an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, gender identity, sexual orientation, disability status, protected veteran status or any other characteristic protected by law.

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

#LI-JP1

Privacy Notice - Active Candidates: https://www.aptiv.com/privacy-notice-active-candidates

Aptiv is an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, gender identity, sexual orientation, disability status, protected veteran status or any other characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Technologist - Product Security
Principal Technologist - Product Security

Aptiv PLC • Walnut Creek (CA)

On-site
USD 150,000 - 200,000
Senior Outbound Product Manager, Private Cloud
Senior Outbound Product Manager, Private Cloud

Aptiv • United States

On-site
USD 140,000 - 210,000
Top Workplace
Medical, Dental, and Vision insurance
Flexible PTO + Holidays
+3
Senior Outbound Product Manager, Private Cloud
Senior Outbound Product Manager, Private Cloud

Aptiv • Troy (MI)

On-site
USD 140,000 - 210,000
Top Workplace recognition
Medical, Dental, Vision insurance
401K with company match
+1
Edge Solutions Architect
Edge Solutions Architect

Aptiv • Troy (MI)

On-site
USD 140,000 - 190,000
Senior Product Line Manager - Automotive Software
Senior Product Line Manager - Automotive Software

Aptiv • Boston (MA)

Hybrid
USD 170,000 - 200,000
Flexible home office
100% Employee covered Medical, Dental, and Vision insurance
401K with company match
+1
Principal Technologist - Enterprise OS
Principal Technologist - Enterprise OS

Aptiv • Troy (MI)

Hybrid
USD 120,000 - 160,000
Hybrid work model
Comprehensive health, dental, and life insurance
Flexible time-off policies
Senior Member of the Technical Staff - Customer Technical Support
Senior Member of the Technical Staff - Customer Technical Support

Aptiv PLC • Washington

On-site
USD 130,000 - 180,000
Health insurance
Dental and vision insurance
Flex time off
+2
Data Platform Architect
Data Platform Architect

Aptiv PLC • Cupertino (CA)

On-site
USD 176,000 - 210,000
Comprehensive benefits package
Performance-based incentives
Growth opportunities for career advancement
Software Architect - Systems
Software Architect - Systems

Aptiv • Troy (MI)

Hybrid
USD 150,000 - 200,000
Hybrid work model
Health insurance
Disability coverage
+4
Sr. Manager, Engineering - Linux
Sr. Manager, Engineering - Linux

Aptiv PLC • Walnut Creek (CA)

Hybrid
USD 190,000 - 240,000
Hybrid work model
Health, dental, and life insurance
RRSP matching
+1