Key Notes
Automotive cybersecurity assurance covers Wayve’s R&D fleet, robotaxi programme and software supplied to OEM customers. The lead needs senior product-security or embedded-security experience, strong ISO 21434 and UNECE R155 knowledge, and evidence across TARA, security requirements, verification and residual-risk treatment. The full-time hybrid vacancy is available in London, Sunnyvale and Leonberg; the United Kingdom opening is based in London.
What You'll Work On
- Define Wayve’s automotive product-security framework against ISO 21434, ASPICE for Cybersecurity and proportionate customer-assurance expectations.
- Set cybersecurity-case structure, evidence quality and residual-risk standards across R&D fleet, robotaxi and customer software programmes.
- Review lifecycle work products, traceability and risk treatment while challenging unresolved evidence or delivery gaps with accountable owners.
- Support preparation for OEM reviews, customer assessments and external audits by advising delivery teams on product-security evidence and reusable guidance.
Why This Role Matters
- Wayve’s automotive cybersecurity cases provide OEM customers and assessors with traceable evidence that software risks were identified, treated and accepted by accountable owners.
- R&D fleet, robotaxi and customer-software programmes share a proportionate security framework, allowing assurance expectations to scale without imposing identical controls on every context.
What They Are Looking For
- Experience: Senior product security, automotive cybersecurity, embedded-systems security or security-assurance experience across complex technical programmes is required.
- Domain: Strong knowledge of ISO 21434 and UNECE R155 automotive cybersecurity expectations is required.
- Technical: Cybersecurity lifecycle experience spanning TARA, goals, requirements, verification, validation and residual-risk treatment is required.
- Technical: Secure architecture, threat modelling, security testing and risk-assessment judgement, plus experience with structured cybersecurity cases or evidence packs, is required.
- Stakeholder: Experience partnering with product, engineering, delivery, safety, legal, security, supplier or customer-facing teams is essential.
- Preferred: Scaling security capability, OEM assurance, audits, automotive safety standards, AV/ADAS systems, supplier assurance or relevant security certification is desirable.