Back to jobs
New

Senior Director of Product Security

Austin, TX

Apptronik is a human-centered robotics company developing AI-powered robots to support humanity in every facet of life. Our flagship humanoid robot, Apollo, is built to collaborate thoughtfully with people, starting with critical industries such as manufacturing and logistics, with future applications in healthcare, the home, and beyond.

We operate at the cutting edge of Applied AI, applying our expertise across the full robotics stack to solve some of society's most important problems. You will join a team dedicated to bringing Apollo to market at scale, tackling the complex challenges like safety, commercialization, and mass production to change the world for the better.

About Apptronik
Apptronik is building Apollo, a general-purpose humanoid robot designed to work alongside people in
real-world environments. We sit at the intersection of advanced hardware, embedded systems, and AI while
scaling from development into deployment. As Apollo moves into the field, product security is a foundational
requirement across everything we ship. Vulnerabilities here are not abstract: they have real-world
consequences.

The Role
We are looking for a Senior Director of Product Security to own and drive Apptronik's end-to-end product
security function. Reporting directly to the COO, you will have cross-functional authority across hardware
engineering, software, systems engineering, and external partnerships. You will build the program from the
ground up — establishing monitoring infrastructure, defining escalation protocols, and embedding security
requirements into how Apollo is designed, built, and deployed.
This is not a traditional IT or enterprise security role. You will be operating in a physical-AI product context
with a distinct mandate from the CIO, who owns enterprise and corporate security.

What You Will Do
Program Leadership
• Own Apptronik's product security strategy and roadmap, aligned to product and operational milestones
• Build and lead a product security team — hiring, mentoring, and defining org structure as the function
grows
• Serve as the primary security voice to the COO and executive team, communicating risk posture,
program status, and resource needs clearly
• Develop a product security charter that defines boundaries and working relationships with T&V, Systems
Engineering, and the CIO
Monitoring & Threat Detection
• Design and deploy monitoring frameworks for Apollo in both development and production/field
environments — covering firmware, runtime behaviors, communications, and physical interfaces
• Define telemetry and alerting requirements that enable early detection of anomalous behavior,
unauthorized access attempts, or integrity violations
• Establish continuous security testing pipelines integrated into hardware and software development
cycles, in coordination with T&V

Escalation & Incident Response
• Build and own the product security escalation framework: from initial detection through triage,
containment, customer notification, and remediation
• Define severity classifications, response SLAs, and communication protocols for security events
affecting deployed units or customer environments
• Lead tabletop exercises and red team efforts to stress-test escalation paths before incidents occur
Hardware & Software Security Requirements
• Translate security principles into concrete, actionable requirements for hardware and software —
covering secure boot chains, SoC and enclave security, physical attack surfaces, OS hardening, AI
model integrity, OTA update security, and inter-process communication
• Partner with HW, SW, and AI/ML engineering leads to review architectures early and drive
security-by-design practices
• Own the security review and sign-off process for new product features, third-party integrations, and
software releases
• Work with Systems Engineering to ensure security requirements are properly integrated into the
requirements flow-down process
Supply Chain & Vendor Security
• Assess security posture of hardware component suppliers, contract manufacturers, and third-party
software vendors
• Define contractual and technical security requirements for suppliers and AI stack partners — including
foundation model providers, cloud platforms, and data pipeline vendors
• Evaluate data ownership implications of robotics foundation model partnerships
OTA Update Security
• Own the security architecture for Apollo's over-the-air update mechanism — one of the
highest-consequence attack surfaces on a deployed physical robot
• Define requirements for update integrity verification, rollback protection, and secure delivery
infrastructure
Physical Security & Anti-Tamper
• Define tamper resistance requirements and anti-cloning protections for deployed units
• Protect Apptronik IP embedded in hardware and firmware from extraction or reverse engineering in the
field
Regulatory & Export Control Awareness
• Anticipate and track evolving regulatory requirements relevant to humanoid robotics — including ITAR,
EAR, and emerging AI/robotics regulations
• Advise on security implications of government, defense-adjacent, and international customer
engagements
Data Governance & Privacy
• Own the security posture around Apollo's operational and environmental data pipeline — from the robot
through to cloud storage and analytics
• Partner with the CIO on data governance frameworks where product and enterprise data intersect
Customer Security Enablement
• Help enterprise customers integrate Apollo into their security environments — including SOC integration,
access controls, and audit log requirements
• Serve as the primary security point of contact for customer security reviews and due diligence processes

• Establish a structured vulnerability disclosure and bug bounty program as Apollo scales

What We're Looking For
• 12+ years in security engineering or product security, with 5+ years leading security organizations —
including experience managing managers, owning budget, and defining team structure
• Demonstrated experience defining and building a security discipline in an emerging hardware or
physical-AI domain — where the threat model, requirements, and processes did not exist before you
arrived
• Deep experience securing embedded systems, robotics, autonomous vehicles, or other physical-AI
products — you understand that software vulnerabilities here can have kinetic consequences
• Hands-on expertise across the stack: secure boot, firmware security, cryptographic key management,
network and communication security, and application-layer threats
• Strong background building security monitoring and incident response programs in production hardware
environments
• Track record of translating security risk into product and engineering requirements that teams actually
ship — and the organizational credibility to enforce them
• Experience with supply chain security assessments and third-party vendor risk management
• Familiarity with OTA update security architecture and the risks unique to field-deployed hardware
• Working knowledge of relevant regulatory frameworks: ITAR, EAR, IEC 62443, NIST, OWASP, CWE
• Excellent communication skills — you can present to the C-suite, debate trade-offs with a systems
architect, and write crisp requirements for an embedded engineer

Why This Role
You will define how Apptronik thinks about security as we scale — setting the bar for an industry that is still
determining what secure humanoid robotics means. You will have direct COO support, real cross-functional
authority, and the opportunity to build a program from scratch at a company shipping real hardware into the
real world.
Apptronik · Austin, TX · apptronik.com

 

 

*This is a direct hire.  Please, no outside Agency solicitations. 

Apptronik provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

Create a Job Alert

Interested in building your career at Apptronik? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...

Technology Control Restrictions: As a person in this position will have access to technical data and/or computer software maintained by the Company, which includes export-controlled technical data and/or computer software, successful applicants must be eligible under U.S. export control regulations to access such information.

Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Apptronik’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...