Product Security Senior IAM Software Engineer
Rivianvw Tech · Irvine, California · 2026-09-22
About this role
ABOUT US
Rivian and Volkswagen Group Technologies is a joint venture between two industry leaders with a clear vision for automotive’s next chapter. From operating systems to zonal controllers to cloud and connectivity solutions, we’re addressing the challenges of electric vehicles through technology that will set the standards for software-defined vehicles around the world.
The road to the future is uncharted. By combining our expertise across connectivity, AI, security and more, we’ll map a new way forward. Working together, we’ll create a future that’s more connected, more intelligent, more sustainable for everyone.
ROLE SUMMARY
The Product Security team develops and implements security protections into the vehicle and its supporting infrastructure. We cover the full chain of security: from defining requirements, planning both software and hardware security, to development, deployment and operationalization of the protections in production.
As a Senior IAM Engineer, you will own core components of the identity and authorization platform that vehicles, cloud services, and internal teams depend on. This includes our fine-grained authorization service, OAuth2/OIDC identity stack, workload identity for cloud and on-vehicle workloads, and the authorization path for vehicle operations such as remote commands and OTA. You will drive this platform from requirements to implementation and operationalization. This role is cross functional across many aspects of RVT including vehicle software and enterprise teams.
RESPONSIBILITIES
- Design, build, and operate security-critical identity and authorization services (authorization/ACL service, OAuth2/OIDC provider, workload identity, key distribution) in Go on Kubernetes/AWS.
- Own the authorization data model: design and evolve the SpiceDB schema (resource hierarchies, roles/permissions) to enable business needs and provide APIs, SDKs, and tooling for teams to manage their permissions.
- Demonstrate cloud native best practices through code reviews, mentorship, and partnership with other cloud first teams.
- Participate in team incident response and on call processes.
- Partner with the PKI team and service owners to adopt mTLS and workload identity (SPIFFE/SPIRE) as the authentication layer for the authorization platform, and guide teams on integrating certificate-based identity with SpiceDB-backed permissions
- Mitigate vulnerabilities found or reported by internal and external parties by aligning with company’s goals and objectives.
- Implement cybersecurity protections to comply with regulations and industry standards.
QUALIFICATIONS
Minimum Qualifications:
- Bachelor’s degree in Computer Science, Computer Engineering, or similar field, or equivalent experience; 5+ years building and operating production backend services.
- Strong Go (or comparable) experience building gRPC/REST services, including protobuf/API design and client SDKs.
- Hands-on experience with modern identity and authorization: OAuth2/OIDC, JWT, mTLS, and fine-grained/relationship-based authorization (e.g. SpiceDB/Zanzibar, OPA, Cedar).
- Experience running production services on Kubernetes and AWS (Helm/ArgoCD, EKS, IAM, KMS, VPC networking) with a SQL datastore (Postgres/CockroachDB).
- Experience working cross functionally with heterogenous engineering teams to ensure the reliability of security critical services.
- Experience delivering platform capabilities to heterogeneous internal engineering teams and leading projects from planning through completion.
Preferred Qualifications:
- SPIFFE/SPIRE or other workload-identity systems; PKCS#11 / secure-element integration.
- Ory Hydra/Kratos or similar identity providers.
- Event streaming (Kafka, NATS), Bazel monorepos.
- Contributions to ADRs or security architecture documentation.
TOTAL REWARDS
We build the exceptional — and we believe the people doing that work should be rewarded accordingly. In addition to a competitive base salary, full-time positions may be is eligible to participate in our annual company performance bonus program.
Payments are discretionary and not guaranteed; actual amounts depend on company results and the terms of the plan in effect, and require active employment at the time of payout. This role is also eligible for equity in the form of Restricted Stock Units (RSUs), subject to board approval and the terms of our equity incentive plans, including applicable vesting requirements.
In addition to our compensation programs, we invest in our people with a comprehensive benefits package designed to support the health, wellbeing, and financial future for full-time employees — including health coverage, retirement savings, time off, and family planning programs. Offerings vary by country. Learn more about our global benefit programs https://rvtech.mybenefits.life/.
External candidates can apply for this role through the Rivian and Volkswagen Group Technologies careers site (https://rivianvw.tech/#careers). If you are a current employee, please apply through our internal job board https://app.ashbyhq.com/internal/job-board/b10a9912-eb45-4a84-9a34-84b2a459923a.
EQUAL OPPORTUNITY
Rivian and Volkswagen Group Technologies is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender, gender expression, gender identity, genetic information or characteristics, physical or mental disability, marital/domestic partner status, age, military/veteran status, medical condition, or any other characteristic protected by law. We are also committed to ensuring compliance with all applicable fair employment practice laws regarding citizenship and immigration status.
Rivian and Volkswagen Group Technologies is committed to ensuring that our hiring…
Skills asked for
- go
- kubernetes
- aws
- cybersecurity
- grpc
- rest
- helm
- argocd
Similar jobs
- Senior Product Security EngineerRivianvw Tech · Irvine
- Embedded Product Security ArchitectSandisk · Irvine
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.