Zoox (Lever)Hybrid
Staff Network Security Architect
Zoox · Foster City, CA
See description for any pay details
Published 2026-06-03 · Seen in source Sep 27, 2026 at 21:45 UTC
Job details and requirements
Zoox's Network Security team architects and defends the digital borders of the company, from corporate offices to engineering labs and product/mission environments. As Staff Network Security Architect, you own the target-state design for how Zoox segments, connects, and controls trust across enterprise IT, OT and lab networks, and hybrid cloud (AWS, GCP). You set the standards other teams build to, you are the security design authority on new infrastructure, and you are accountable for the coherence of the whole picture rather than the health of any one platform. You'll partner closely with Network Engineering, IT, Product Security, Hardware, and Software Engineering, and you'll influence far more systems than you personally operate. In This Role, You Will... Own Zoox's network security reference architecture across corporate, data center, lab/OT, and edge environments, and define the segmentation and trust model that everything else is built against Serve as the security design authority for new infrastructure: run design reviews and threat models early enough to change the design, and define the criteria under which a design is approved, conditionally approved, or rejected Translate security frameworks into buildable engineering standards. Map controls to NIST CSF 2.0, NIST 800-53, and ISO 27001 (IEC 62443 a plus for OT/lab), and turn them into reference patterns, guardrails, and acceptance criteria engineers can implement without interpreting policy Define the zero-trust and identity-to-network strategy, including 802.1X/certificate-based NAC, PKI trust hierarchy, ZTNA and remote access, and how non-human and headless lab/vehicle assets are authenticated and authorized Architect secure hybrid and multi-cloud connectivity (CloudWAN, SD-WAN, transit and inspection architectures, cloud-native controls) and define where inspection, enforcement, and logging belong Drive secure-by-design into the delivery path: encode standards as Terraform modules, policy-as-code, and CI/CD guardrails so the secure pattern is the default one, not a review gate Own data flow and trust boundary analysis for sensitive environments, including vehicle data, lab telemetry, and third-party and vendor connectivity Own the governance side of architecture: risk articulation for leadership, exception and compensating control decisions, architecture decision records, and the multi-year roadmap that retires legacy patterns Set technical direction and raise the bar across the team through mentorship, design review, and written standards rather than through direct ownership of day-to-day operations Qualifications 10+ years in network and security engineering, including 4+ years in an architecture or technical-lead role where you owned designs others implemented Demonstrated ownership of an enterprise-scale segmentation or zero-trust architecture from concept through adoption, including what you changed when it met reality Ability to reason about security frameworks as design inputs, not audit artifacts: fluency with NIST CSF 2.0, NIST 800-53, and ISO 27001, and a track record of turning them into engineering standards and evidence Depth in threat modeling and secure-by-design for network and infrastructure, including data flow analysis, trust boundaries, blast radius, and failure modes Strong platform grounding to keep designs buildable: next-gen firewalls (Palo Alto, Fortinet), AWS NFW, IDS/IPS, NAC/802.1X, PKI, VPN, ZTNA (Zscaler, Prisma Access, or equivalent), and core protocols (TCP/IP, BGP, OSPF, VLAN, TLS/PKI) Cloud network security depth in AWS and/or GCP, including inspection architecture, cloud-native enforcement, and IaC delivery with Terraform Bonus Qualifications OT, ICS, robotics, automotive, or manufacturing network security experience (IEC 62443, Purdue model, or equivalent) Autonomous vehicle or safety-critical systems exposure Certifications: CISSP-ISSAP, SABSA, TOGAF, CCIE Security, PCNSE, AWS Security Specialty Experience applying AI/ML to network or cloud security (anomaly detection, behavioral analytics, LLM-assisted design review or policy analysis)
This is the description supplied by the source. Review the employer’s full requirements before applying. A current listing does not guarantee hiring or eligibility.
Applications are completed on the employer’s site. Creating an account or saving a job does not submit an application.