
Hybrid opportunity at
ZooxStaff Network Security Architect
Zoox is seeking a Staff Network Security Architect to establish and oversee the security design for its enterprise IT, OT, lab, and multi-cloud environments. The employer…
Career Tools
About This Role
Zoox is seeking a Staff Network Security Architect to establish and oversee the security design for its enterprise IT, OT, lab, and multi-cloud environments. The employer is building a custom, ground-up fully autonomous vehicle fleet and urban mobility service. In this hybrid role, the professional will act as the principal security design authority, shaping target-state segmentation, zero-trust strategies, and infrastructure standards without managing day-to-day operations. This position suits an experienced…
Job Description
Zoox is seeking a Staff Network Security Architect to establish and oversee the security design for its enterprise IT, OT, lab, and multi-cloud environments. The employer is building a custom, ground-up fully autonomous vehicle fleet and urban mobility service. In this hybrid role, the professional will act as the principal security design authority, shaping target-state segmentation, zero-trust strategies, and infrastructure standards without managing day-to-day operations. This position suits an experienced architect who can translate complex compliance frameworks into actionable engineering patterns, guide cross-functional teams, and establish secure-by-design defaults using tools like Terraform and policy-as-code.
Responsibilities
- Design and establish the network security reference architecture spanning corporate, data center, lab, OT, and edge systems.
- Evaluate new infrastructure as the security design authority by conducting early threat models and design reviews.
- Convert regulatory frameworks into practical engineering guidelines, guardrails, and acceptance criteria.
- Develop the enterprise zero-trust model, covering certificate-based network access control, public key infrastructure, and remote access.
- Build secure hybrid and multi-cloud connectivity architectures across cloud-native environments.
- Integrate security measures into deployment pipelines by encoding standards as Terraform modules and policy-as-code.
- Analyze data flows and trust boundaries for sensitive zones, including vehicle data and vendor connections.
- Handle architecture governance tasks such as risk reporting, exception management, and legacy retirement roadmaps.
Requirements
- Possess at least ten years of combined experience in network and security engineering.
- Have a minimum of four years working in an architecture or technical leadership capacity overseeing designs implemented by others.
- Demonstrate hands-on creation and adoption of enterprise-scale zero-trust or segmentation architectures.
- Show proficiency in interpreting NIST CSF 2.0, NIST 800-53, and ISO 27001 as design inputs.
- Display deep expertise in threat modeling, data flow analysis, and infrastructure blast radius management.
- Bring practical knowledge of next-generation firewalls, intrusion detection systems, VPN, ZTNA, and standard networking protocols.
- Prove cloud network security capability in AWS or GCP, alongside infrastructure-as-code deployment experience using Terraform.
Qualifications
- Familiarity with OT, industrial control systems, robotics, or manufacturing network security standards like IEC 62443.
- Exposure to safety-critical systems or autonomous vehicle technology.
- Professional certifications including CISSP-ISSAP, SABSA, TOGAF, CCIE Security, PCNSE, or AWS Security Specialty.
- Background in leveraging artificial intelligence or machine learning for anomaly detection and automated security policy analysis.
Core Skills
Frequently Asked Questions
What is the remote work policy for this position?
The role is structured as a hybrid position, though specific office attendance rules are not detailed in the posting.
What kind of projects will the architect work on?
The architect will design segmentation, connectivity, and trust models across corporate offices, engineering labs, OT networks, and hybrid cloud environments supporting an autonomous vehicle fleet.
Are specific certifications required to apply?
Certifications such as CISSP-ISSAP, SABSA, TOGAF, CCIE Security, PCNSE, or AWS Security Specialty are listed as bonus qualifications rather than strict requirements.
What is the salary range for this job?
The salary information is not specified in the job posting.
Sample Interview Questions
AI-generated questions tailored to this specific role — a preview of the full practice set.