Back to jobs
New

Software Engineer, Security Engineering

Houston, TX

Company Introduction

At Bot Auto, we are revolutionizing the transportation of goods with our cutting-edge autonomous trucks, enhancing the quality of life for communities around the globe. With the agility of a start-up and the wisdom of seasoned experts, Bot Auto boasts a team that has achieved numerous world-firsts and unparalleled innovations. United by a shared vision, we create miracles and propel the future of transportation. Join us and transform your dreams into reality.

We are seeking a motivated Software Engineer, Security Engineering to help build and operate security across Bot Auto's autonomous trucking stack. The proprietary technology that powers our autonomous driving system is our core intellectual property, and protecting it - along with the safety-relevant systems behind our fleet - is mission critical. In this role, you will work with experienced engineers across onboard (in-vehicle) security as well as infrastructure and platform security. You will contribute to how Bot Auto adopts AI responsibly by helping assess risks in large language models and agentic systems and implementing practical protections. This is a hands-on role with opportunities to learn across the full stack, from the vehicle to the cloud, while building strong foundations in security engineering.

Key Responsibilities

  • Implement and maintain security controls for onboard (in-vehicle) systems, including secure boot, code signing, secrets and key management, secure over-the-air (OTA) updates, and system hardening.
  • Support security across infrastructure and platforms, including Kubernetes, public cloud (AWS), on-prem data centers, CI/CD pipelines, and internal developer platforms.
  • Help evaluate and implement protections for AI systems, including defenses against prompt injection, data exfiltration, model and supply-chain risks, and unsafe agent behavior.
  • Build and maintain identity and access management, secrets management, and least-privilege authorization for services, devices, and fleet systems.
  • Participate in threat modeling, security design reviews, and risk assessments, and partner with engineering teams to address identified issues.
  • Help operate vulnerability management, dependency and supply-chain scanning, and secure software development lifecycle (SSDLC) tooling and processes.
  • Contribute to security detection, logging, monitoring, and incident response across onboard and infrastructure environments.
  • Improve security through automation, documentation, testing, and close collaboration with software, platform, and autonomy engineering teams.

Required Qualifications 

  • Bachelor's degree in Computer Science, Engineering, Cybersecurity, or a related field, or equivalent practical experience
  • 0-2 years of software engineering, security engineering, or related experience; relevant internships, research, projects, or open-source contributions are welcome
  • Programming experience in one or more languages such as Python, Go, Rust, C/C++, or JavaScript/TypeScript
  • Foundational understanding of authentication and authorization, networking, operating systems, and common software security vulnerabilities
  • Familiarity with Linux and cloud or distributed systems, with an interest in learning how to secure production environments

Preferred Qualifications 

  • Internship, coursework, project, or hands-on experience in cybersecurity, embedded systems, automotive, IoT, or edge computing
  • Familiarity with containers, Kubernetes, AWS, infrastructure as code (Terraform, Pulumi), or CI/CD systems
  • Interest in or exposure to AI/LLM security topics such as prompt injection, model supply chain, agent sandboxing, or AI guardrails
  • Familiarity with IAM, secrets management, PKI, or zero-trust concepts
  • Experience with security tooling such as SAST/DAST, dependency scanning, SBOMs, SIEM, or vulnerability scanners through work, coursework, or personal projects
  • Awareness of security standards and frameworks such as ISO/SAE 21434, NIST, OWASP, or SOC 2
  • Exposure to threat modeling, incident response, capture-the-flag exercises, security research, or responsible vulnerability disclosure

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

U.S. Standard Demographic Questions

We invite applicants to share their demographic background. If you choose to complete this survey, your responses may be used to identify areas of improvement in our hiring process.
Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Bot Auto’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...