Automotive Product Security Lead at Wayve | London, GBR | Rezi

Automotive Product Security Lead at Wayve

Automotive Product Security Lead

Wayve · London, GBR

3 weeks ago

Automotive Product Security Lead

Wayve · London, GBR

23 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

As the Automotive Product Security Lead at Wayve, you will define, mature, and operate the product security framework for Wayve’s automotive software activities. This role is advisory and assurance-focused, providing oversight, challenge, and pragmatic guidance to enable product and engineering teams to meet automotive cybersecurity expectations without unnecessary friction. This is a senior individual contributor role with broad cross-functional influence.

Responsibilities

  • Define and maintain Wayve's automotive product security framework, aligned to ISO 21434, ASPICE for Cybersecurity, and customer assurance expectations.
  • Establish practical processes, templates, guidance, and minimum control expectations for automotive cybersecurity activities across R&D fleet, robotaxi, and customer software programmes.
  • Act as the product security lead across automotive software activities, helping teams understand required security activities, timing, and evidence standards.
  • Coordinate product security activity across security, product, engineering, safety, and customer-facing teams to ensure dependencies, risks, and assurance needs are understood early.
  • Define the minimum expectations, structure, and quality bar for Wayve's automotive cybersecurity cases.
  • Provide independent review of required work products, traceability and completeness, residual risk statements, and the overall credibility of the cybersecurity case.
  • Assess whether the cybersecurity case provides a defensible argument that the relevant system or software is acceptably secure for its intended context.
  • Establish mechanisms for product cybersecurity risk visibility, challenge, escalation, and decision-making across automotive programmes.
  • Partner with risk owners to ensure residual product cybersecurity risks are clearly documented, treatment options are understood, remediation is tracked, and acceptance decisions are made by appropriate owners.
  • Challenge and escalate where risk, evidence, or delivery gaps are not being addressed appropriately.
  • Translate automotive cybersecurity regulatory, standards, and customer expectations into practical internal requirements and assurance activities.
  • Support preparation for external audits, customer assessments, and OEM reviews where product cybersecurity evidence is required.
  • Represent Wayve credibly in product security discussions with customers, partners, and external assessors.
  • Advise and upskill product and engineering teams on automotive cybersecurity practices, including TARA, cybersecurity requirements, secure architecture, implementation evidence, verification, validation, and security testing expectations.
  • Build reusable guidance and playbooks that help teams integrate product security into existing development processes without duplicative or unnecessary process overhead.
  • Develop meaningful metrics that demonstrate automotive product security maturity, assurance readiness, evidence quality, risk treatment progress, and recurring areas of weakness.
  • Provide clear reporting to security, product, engineering and other senior stakeholders, using evidence and judgement to drive continuous improvement in Wayve's product security capability.

Requirements

  • Proven experience in a senior product security, automotive cybersecurity, embedded systems security, or security assurance role, with accountability for influencing security outcomes across complex technical programmes.
  • Strong knowledge of automotive cybersecurity expectations, particularly ISO 21448 and UNECE R155.
  • Experience defining, applying, or assessing cybersecurity lifecycle activities and work products, including TARA, cybersecurity goals, cybersecurity requirements, verification and validation evidence, and residual risk treatment.
  • Strong technical judgement across software security, embedded or vehicle systems, secure architecture, threat modelling, security testing, and risk assessment.
  • Experience reviewing or contributing to cybersecurity cases, assurance cases, technical evidence packs, or comparable structured security arguments.
  • Excellent judgement and independence, with confidence challenging issues while maintaining constructive working relationships.
  • Experience partnering with product, engineering, delivery, safety, legal, security, supplier, or customer-facing teams to deliver proportionate and effective security outcomes.
  • Strong written and verbal communication skills, able to translate standards, risks, and assurance expectations into clear, practical guidance for technical and non-technical stakeholders.
  • Comfort operating with high autonomy in a fast-moving, ambiguous environment where the right level of process needs to be designed, not simply inherited.
  • Experience establishing or scaling a product security or automotive cybersecurity capability in a growing or fast-moving organisation.
  • Experience with OEM customer assurance, external audits, cybersecurity certification, type approval, or independent assessment activity.
  • Familiarity with ASPICE, ISO 26262, ISO 21448 / SOTIF, or safety-security interface management.
  • Experience with autonomous vehicles, ADAS, robotics, safety-critical software, automotive software platforms, vehicle networks, OTA update systems, or fleet operations.
  • Experience managing product-security-relevant supplier assurance, supplier evidence, or third-party cybersecurity risk in an automotive context.
  • Relevant certifications or training, such as ISO 21434, CISSP, CSSLP, GICSP, or automotive cybersecurity training.

Skills

  • ISO 21434
  • ASPICE for Cybersecurity
  • TARA
  • Cybersecurity requirements
  • Secure architecture
  • Implementation evidence
  • Verification
  • Validation
  • Security testing
  • Threat modelling
  • Risk assessment
  • Cybersecurity case assurance
  • ISO 21448
  • UNECE R155
  • ASPICE
  • ISO 26262
  • ISO 21448 / SOTIF
  • Safety-security interface management
  • Autonomous vehicles
  • ADAS
  • Robotics
  • Safety-critical software
  • Automotive software platforms
  • Vehicle networks
  • OTA update systems
  • Fleet operations
  • Supplier assurance
  • CISSP
  • CSSLP
  • GICSP

Location

  • London
  • Sunnyvale
  • Leonberg

Work Type

  • Full-time
  • Hybrid

Experience Level

  • Senior