Automotive Product Security Lead

Automotive Product Security Lead

Full-Time 70000 - 80000 £ / year (est.) Home office (partial)
Wayve

At a Glance

  • Tasks: Lead automotive product security, ensuring software meets cybersecurity standards and regulations.
  • Company: Wayve, a pioneer in Embodied AI technology for automated driving systems.
  • Benefits: Hybrid working policy, competitive salary, and opportunities for professional growth.
  • Other info: Join a dynamic team committed to inclusivity and continuous improvement.
  • Why this job: Make a real impact on the future of automotive safety and innovation.
  • Qualifications: Experience in automotive cybersecurity and strong communication skills required.

The predicted salary is between 70000 - 80000 £ per year.

Founded in 2017, Wayve is the leading developer of Embodied AI technology.

Our advanced AI software and foundation models enable vehicles to perceive, understand, and navigate any complex environment, enhancing the usability and safety of automated driving systems.

The role

As the Automotive Product Security Lead at Wayve, you will define, mature, and operate the product security framework for the company’s automotive software activities.

This includes our internal R&D fleet, robotaxi programme, and automotive software supplied to OEM customers, with assurance expectations applied proportionally to each context.

You will help ensure Wayve can develop, assure, and supply automotive software that meets cybersecurity expectations from internal governance, customers, regulators, and external assessors.

You will be trusted to determine what good looks like for automotive product security at Wayve, applying industry best practice with pragmatism and adapting it to our technology, risk profile, product maturity, and stage of growth.

You will translate regulations, standards, customer expectations and risk assessments into clear, practical requirements that product and engineering teams can apply effectively.

This senior individual‑contributor role works closely with product, engineering, safety and customer‑facing teams, setting standards, guiding, and assuring implementation.

Delivery teams apply the controls and processes, produce evidence and work products, maintain cybersecurity cases and own residual risk.

The role is advisory and assurance‑focused, providing oversight, challenge, and pragmatic guidance to the business while enabling product and engineering teams to meet automotive cybersecurity expectations without unnecessary friction.

Key Responsibilities

  • Define and maintain Wayve’s automotive product security framework, aligned to ISO 21434, ASPICE for Cybersecurity, and customer assurance expectations.
  • Establish practical processes, templates, guidance and minimum control expectations for automotive cybersecurity activities across R&D fleet, robotaxi and customer software programmes.
  • Act as the product security lead across automotive software activities, helping teams understand required security activities, when they are needed and what good evidence looks like.
  • Coordinate product security activity across security, product, engineering, safety and customer‑facing teams to ensure dependencies, risks and assurance needs are understood early.
  • Define the minimum expectations, structure and quality bar for Wayve’s automotive cybersecurity cases.
  • Provide independent review of required work products, traceability and completeness, residual risk statements and overall credibility of the cybersecurity case.
  • Assess whether the cybersecurity case provides a defensible argument that the relevant system or software is acceptably secure for its intended context.
  • Establish mechanisms for product cybersecurity risk visibility, challenge, escalation and decision‑making across automotive programmes.
  • Partner with risk owners to ensure residual product cybersecurity risks are clearly documented, treatment options are understood, remediation is tracked and acceptance decisions are made by the appropriate accountable owners.
  • Translate automotive cybersecurity regulatory, standards and customer expectations into practical internal requirements and assurance activities.
  • Support preparation for external audits, customer assessments and OEM reviews where product cybersecurity evidence is required.
  • Represent Wayve credibly in product security discussions with customers, partners and external assessors.
  • Advise and upskill product and engineering teams on automotive cybersecurity practices, including TARA, cybersecurity requirements, secure architecture, implementation evidence, verification, validation and security testing expectations.
  • Build reusable guidance and playbooks that help teams integrate product security into existing development processes without duplicative or unnecessary process overhead.
  • Develop meaningful metrics that demonstrate automotive product security maturity, assurance readiness, evidence quality, risk treatment progress and recurring areas of weakness.
  • Provide clear reporting to security, product, engineering and other senior stakeholders, using evidence and judgement to drive continuous improvement in Wayve’s product security capability.

About You

Essential

  • Proven experience in a senior product security, automotive cybersecurity, embedded systems security or security assurance role, with accountability for influencing security outcomes across complex technical programmes.
  • Strong knowledge of automotive cybersecurity expectations, particularly ISO 21434 and UNECE R155.
  • Experience defining, applying or assessing cybersecurity lifecycle activities and work products, including TARA, cybersecurity goals, cybersecurity requirements, verification and validation evidence and residual risk treatment.
  • Strong technical judgement across software security, embedded or vehicle systems, secure architecture, threat modelling, security testing and risk assessment.
  • Experience reviewing or contributing to cybersecurity cases, assurance cases, technical evidence packs or comparable structured security arguments.
  • Excellent judgement and independence, with confidence challenging issues while maintaining constructive working relationships.
  • Experience partnering with product, engineering, delivery, safety, legal, security, supplier or customer‑facing teams to deliver proportionate and effective security outcomes.
  • Strong written and verbal communication skills, able to translate standards, risks and assurance expectations into clear practical guidance for technical and non‑technical stakeholders.
  • Comfort operating with high autonomy in a fast‑moving, ambiguous environment where the right level of process needs to be designed, not simply inherited.

Desirable

  • Experience establishing or scaling a product security or automotive cybersecurity capability in a growing or fast‑moving organisation.
  • Experience with OEM customer assurance, external audits, cybersecurity certification, type approval or independent assessment activity.
  • Familiarity with ASPICE, ISO 26262, ISO 21448/SOTIF or safety‑security interface management.
  • Experience with autonomous vehicles, ADAS, robotics, safety‑critical software, automotive software platforms, vehicle networks, OTA update systems or fleet operations.
  • Experience managing product‑security‑relevant supplier assurance, supplier evidence or third‑party cybersecurity risk in an automotive context.
  • Relevant certifications or training such as ISO 21434, CISSP, CSSLP, GICSP or automotive cybersecurity training.

This is a full‑time role based in our offices in London, Sunnyvale or Leonberg.

We operate a hybrid working policy that combines time together in our offices and workshops with time working from home, and core working hours to allow flexible scheduling.

Equal Opportunity & Inclusion

Wayve is committed to creating an inclusive interview experience.

If you require any accommodations or adjustments to participate fully in our interview process, please let us know.

We do not ask about marriage or pregnancy, care responsibilities or disabilities in any of our job adverts or interviews, however we do collect information about care responsibilities, disabilities and other diversity data through an optional DEI monitoring form to identify areas of improvement in our hiring process and ensure it is inclusive and non‑discriminatory.

For more information visit Careers, Values and for US candidates only, E‑Verify Notice and Right to Work.

All candidates are reviewed on a basis of merit and all protected characteristics under applicable law.

#J-18808-Ljbffr

Automotive Product Security Lead employer: Wayve

Wayve is an exceptional employer that fosters a dynamic and innovative work culture, where software engineers can thrive while contributing to cutting-edge AI solutions. With a strong emphasis on employee growth, Wayve offers opportunities for professional development and collaboration in a hybrid work environment, allowing for flexibility and work-life balance. Located in a vibrant tech hub, employees benefit from a supportive community and access to industry-leading resources.

Wayve

Contact Details:

Wayve Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Automotive Product Security Lead

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Wayve, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Wayve

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Wayve. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Automotive Product Security Lead

Automotive Cybersecurity
ISO 21434
UNECE R155
Cybersecurity Lifecycle Activities
TARA (Threat Assessment and Risk Analysis)
Verification and Validation Evidence
Risk Assessment

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Wayve insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Wayve that you’re committed to staying ahead in the game.

How to prepare for a job interview at Wayve

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Wayve to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Wayve.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.