
Job Description
Join Us, and Ship Robots
Weave was founded to build the robots we’d want to have in our own home. We believe the next generation of robotics will transform everyday life by enabling people to do more and to reclaim time to spend on what’s important.
We also believe robots are in a sense like any other product: to matter, they have to ship. Our robots are already operating in real homes and businesses, giving us the opportunity to rapidly improve from real-world experience. With a growing team, strong customer demand, and capital for expansion, we’re entering an exciting stage of growth—and we’re looking for people with exceptional talent and standards to help bring home robotics to millions of households.
The Role
At Weave, we’re building robots designed to operate in the most personal environment there is: the home. Our robots combine cameras, sensors, actuators, embedded compute, cloud infrastructure, and consumer applications into a deeply integrated system—and earning our customers’ trust requires making security a fundamental part of that system from the beginning.
As a Senior Security Engineer, you’ll work on security and system integrity across the full surface area of our product, from embedded devices and robot software to cloud infrastructure, APIs, mobile applications, and fleet operations. You’ll work directly with engineers to threat-model new systems, find vulnerabilities, design secure architectures, and build the infrastructure that protects robots already operating in the real world. This is a highly hands-on role: you’ll help define our long-term security strategy while remaining close enough to the product to inspect code, probe systems, investigate incidents, and ship fixes yourself.
Responsibilities
-
Own product security: Define and continuously improve the security architecture of our robots, applications, backend services, and supporting infrastructure.
-
Threat modeling & secure design: Lead threat modeling and security reviews for new hardware and software capabilities, identifying remote and physical attack surfaces and designing mitigations before systems reach production.
-
Robot & embedded security: Secure device identity, boot and update chains, firmware, embedded Linux systems, and hardware interfaces.
-
Cloud & application security: Identify and mitigate vulnerabilities across cloud infrastructure, APIs, authentication systems, web services, and iOS/Android applications.
-
Security testing: Perform code review, penetration testing, vulnerability research, and adversarial testing across our product stack. Develop tooling that makes security testing increasingly automated.
-
Detection & incident response: Build logging, monitoring, detection, and incident-response capabilities that allow us to rapidly identify, investigate, contain, and remediate security events.
-
Raise the security bar: Establish practical security standards and processes, educate engineers, and build a culture where security is owned across the engineering organization.
What You'll Bring
-
Product security expertise: 4+ years securing connected products, embedded systems, robotics, IoT, autonomous systems, or other physical platforms, with experience reasoning across hardware, firmware, embedded Linux, operating systems, networks, cloud services, and applications.
-
Linux & systems security: Strong understanding of Linux security boundaries, processes, permissions, networking, containers, system hardening, and common privilege-escalation techniques.
-
Application security: Experience finding and mitigating vulnerabilities across APIs, backend services, web or mobile applications, including familiarity with OWASP Top 10 and modern application security practices.
-
Software engineering: Strong programming ability in Python, C++, Go, Rust, or similar languages, with the ability to reason about production code and build security tooling yourself.
-
Security testing: Hands-on experience with source-code review, SAST/DAST, dependency analysis, fuzzing, penetration testing, and security tools such as Burp Suite, Semgrep, CodeQL, Ghidra, or similar.
-
Threat modeling: Experience using structured approaches such as STRIDE, attack trees, or similar methodologies to reason about complex systems and drive architectural improvements.
-
Incident response: Experience investigating security incidents, analyzing logs and telemetry, performing root-cause analysis, and driving remediation.
Nice to Have
-
Networking depth: Familiarity with Ethernet, Wi-Fi, TCP/IP, and common network protocols, including experience using Wireshark, tcpdump, or similar packet-analysis tools to diagnose networking and security issues.
-
Security standards: Familiarity with security standards and guidance relevant to connected consumer products, such as NIST IR 8259, NIST SSDF, UL 2900, or similar.
-
Connected-device security: Experience with device provisioning, PKI/mTLS, device identity, signed OTA updates, credential rotation/revocation, and fleet-scale secrets management.
Optimize Your Resume for This Job
Get a match score and see exactly which keywords you're missing
Job Details
- Category
- Security
- Employment Type
- Full Time
- Location
- San Francisco, CA
- Posted
About Weave Robotics
Weave Robotics is a Robotics Engineering firm offering Personal robots for the home.
More Roles at Weave Robotics





Similar Security Roles



Found this role interesting?