Rivian and Volkswagen Group Technologies is a joint venture between two industry leaders with a clear vision for automotive’s next chapter. From operating systems to zonal controllers to cloud and connectivity solutions, we’re addressing the challenges of electric vehicles through technology that will set the standards for software-defined vehicles around the world.
The road to the future is uncharted. By combining our expertise across connectivity, AI, security and more, we’ll map a new way forward. Working together, we’ll create a future that’s more connected, more intelligent, more sustainable for everyone.
Role SummaryWe're looking for a senior/staff security engineer who is a genuine PKI expert, comfortable owning certificate lifecycle management end-to-end and who also brings solid platform/infrastructure experience.
You'll help us run and modernize the systems that issue, provision, and manage digital identity for our products, with particular depth needed in charging standards (e.g., ISO 15118, OCPP) and authN/authZ standards (e.g., X.509, mTLS, OAuth2, OIDC).
ResponsibilitiesOwn PKI and certificate lifecycle management: design, issue, provision, renew, and revoke certificates across the systems you support; maintain trust stores and certificate authorities.
Apply charging-standard expertise: work with EV charging PKI and protocols (e.g., ISO 15118 Plug & Charge, OCPP) to support certificate provisioning and interoperability for charging use cases.
Design and implement authN/authZ: apply standards such as X.509, mTLS, OAuth2, and OIDC to secure service-to-service and client-facing authentication and authorization flows.
Build and operate platform infrastructure: work with Kubernetes, service mesh, and workload identity technologies to move cert issuance and auth off bespoke one-off solutions and onto shared, reusable infrastructure.
Support secure boot and key management: contribute to signature validation, key revocation, and related secure-provisioning workflows.
Operate what you build: deploy, monitor, and support production services (GitOps deployment, observability/tracing), and be a responsive point of contact when certificate or auth issues arise.
Document and mentor: write clear design docs and runbooks, and help other engineers ramp up on PKI and platform concepts.
Core (must-have):
5+ years in security engineering with hands-on, production experience in PKI and certificate lifecycle management (issuance, provisioning, renewal, revocation).
Strong grasp of public-key cryptography fundamentals: X.509 certificates, TLS/mTLS, HSM/TPM-backed key storage.
Working knowledge of authN/authZ standards (X.509, mTLS, OAuth2, OIDC) and experience implementing them in production systems.
Familiarity with EV charging PKI or charging communication standards (e.g., ISO 15118, OCPP), or comparable domain-specific PKI experience.
Proficiency in at least one backend language (Go, Python, or similar) and experience building/operating production services.
Strongly preferred:
Experience with service mesh and workload identity technologies (e.g., Istio, SPIRE/SPIFFE, Cilium/eBPF).
Experience designing API gateway/ingress patterns for external or partner-facing traffic, including mTLS termination and identity-provider integration.
Experience operating cloud infrastructure with strong observability practices (metrics, tracing, logging).
Nice-to-have:
Exposure to intrusion detection or broader security monitoring across distributed systems.
Experience in a regulated or safety-critical industry.
Track record contributing to cross-functional security architecture decisions at scale.
We build the exceptional — and we believe the people doing that work should be rewarded accordingly. In addition to a competitive base salary, full-time positions may be is eligible to participate in our annual company performance bonus program.
Payments are discretionary and not guaranteed; actual amounts depend on company results and the terms of the plan in effect, and require active employment at the time of payout. This role is also eligible for equity in the form of Restricted Stock Units (RSUs), subject to board approval and the terms of our equity incentive plans, including applicable vesting requirements.
In addition to our compensation programs, we invest in our people with a comprehensive benefits package designed to support the health, wellbeing, and financial future for full-time employees — including health coverage, retirement savings, time off, and family planning programs. Offerings vary by country. Learn more about our global benefit programs.
External candidates can apply for this role through the Rivian and Volkswagen Group Technologies careers site (https://rivianvw.tech/#careers). If you are a current employee, please apply through our internal job board.
Equal OpportunityRivian and Volkswagen Group Technologies is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender, gender expression, gender identity, genetic information or characteristics, physical or mental disability, marital/domestic partner status, age, military/veteran status, medical condition, or any other characteristic protected by law. We are also committed to ensuring compliance with all applicable fair employment practice laws regarding citizenship and immigration status.
Rivian and Volkswagen Group Technologies is committed to ensuring that our hiring process is accessible for persons with disabilities. If you have a disability or limitation, such as those covered by the Americans with Disabilities Act, that requires accommodations to assist you in the search and application process, please email us at [email protected].
Candidate Data PrivacyRivian and Volkswagen Group Technologies” may collect, use and disclose your personal information or personal data (within the meaning of the applicable data protection laws) when you apply for employment and/or participate in our recruitment processes (“Candidate Personal Data”). This data includes contact, demographic, communications, educational, professional, employment, social media/website, network/device, recruiting system usage/interaction, security and preference information. Rivian and Volkswagen Group Technologies may use your Candidate Personal Data for the purposes of (i) tracking interactions with our recruiting system; (ii) carrying out, analyzing and improving our application and recruitment process, including assessing you and your application and conducting employment, background and reference checks; (iii) establishing an employment relationship or entering into an employment contract with you; (iv) complying with our legal, regulatory and corporate governance obligations; (v) record keeping; (vi) ensuring network and information security and preventing fraud; and (vii) as otherwise required or permitted by applicable law.
Rivian and Volkswagen Group Technologies may share your Candidate Personal Data with (i) internal personnel who have a need to know such information in order to perform their duties, including individuals on our People Team, Finance, Legal, and the team(s) with the position(s) for which you are applying; (ii) Rivian and Volkswagen Group Technologies affiliates; and (iii) Rivian and Volkswagen Group Technologies’ service providers, including providers of background checks, staffing services, and cloud services.
Rivian and Volkswagen Group Technologies may transfer or store internationally your Candidate Personal Data, including to or in the United States, Canada, and the European Union and in the cloud, and this data may be subject to the laws and accessible to the courts, law enforcement and national security authorities of such jurisdictions.
If you provide a mobile telephone number as part of your application or during the recruitment process, Rivian and Volkswagen Group Technologies may use that number to contact you via SMS text message for recruitment-related purposes, including scheduling, logistics, and status updates. Message and data rates may apply. You may opt out of SMS communications at any time by replying STOP to any text message you receive from us. Consent to receive SMS messages is not a condition of applying for or being considered for employment.
Please see our Candidate Data Privacy Notice (English) and Candidate Data Privacy Notice (Serbian) for more information.
--
Please note this job posting represents an open, active vacancy. Additionally, we are not currently accepting applications from third party application services.
Skills Required
- 5+ years of security engineering experience
- Hands-on production experience with PKI and certificate lifecycle management, including issuance, provisioning, renewal, and revocation
- Strong understanding of public-key cryptography fundamentals, X.509 certificates, TLS/mTLS, and HSM/TPM-backed key storage
- Production experience implementing X.509, mTLS, OAuth2, and OIDC authentication and authorization standards
- Familiarity with EV charging PKI or charging communication standards such as ISO 15118 and OCPP, or comparable domain-specific PKI experience
- Proficiency in at least one backend language, such as Go or Python, and experience building and operating production services
- Experience with service mesh and workload identity technologies such as Istio, SPIRE/SPIFFE, or Cilium/eBPF
- Experience designing API gateway and ingress patterns for external or partner-facing traffic, including mTLS termination and identity-provider integration
- Experience operating cloud infrastructure with metrics, tracing, and logging
- Exposure to intrusion detection or broader security monitoring across distributed systems
- Experience in a regulated or safety-critical industry
- Track record contributing to cross-functional security architecture decisions at scale
What We Do
Rivian and Volkswagen Group Technologies, LLC is a joint venture creating software-defined vehicle platforms for electric vehicles. Combining Rivians software and zonal architecture with Volkswagens scale, the company develops operating systems, zonal controllers, cloud and connectivity solutions to enable over-the-air updates, simplify vehicle electronics, and accelerate deployment of shared vehicle software across multiple automotive brands and segments.








