Cybersecurity Application Security Engineer

Rivian

Rivian

Belgrade, Serbia

Posted on May 15, 2026

Job Description

About Rivian

Rivian is on a mission to keep the world adventurous forever. This goes for the emissions-free Electric Adventure Vehicles we build, and the curious, courageous souls we seek to attract.

As a company, we constantly challenge what’s possible, never simply accepting what has always been done. We reframe old problems, seek new solutions and operate comfortably in areas that are unknown. Our backgrounds are diverse, but our team shares a love of the outdoors and a desire to protect it for future generations.


Role Summary

We are seeking an experienced Application Security Engineer to join our Enterprise Cybersecurity team. You will play a crucial role in enhancing and maintaining the Secure Software Development Lifecycle (SSDLC) by guiding software development teams to write secure code and effectively remediate vulnerabilities. The ideal candidate acts as a bridge between security and engineering, fostering a culture of secure-by-design development with a heavy emphasis on software supply chain integrity.


Responsibilities

  • Vulnerability Management: Review source code and application architectures to identify and communicate security vulnerabilities to development teams.
  • Supply Chain Security: Drive the adoption of Software Bill of Materials (SBOM) to provide visibility into the software supply chain and ensure license compliance and vulnerability tracking.
  • 3rd Party Risk Mitigation: Implement and manage automated Software Composition Analysis (SCA) to identify and remediate vulnerabilities in open-source and third-party libraries.
  • CI/CD Pipeline Security: Develop and support automated security tooling and agentic security workflows within CI/CD pipelines to streamline vulnerability triage, third-party scanning, and threat modeling.
  • Remediation Support: Work closely with the penetration testing team to identify and implement remediations for identified security vulnerabilities.
  • Threat Response: Support the implementation of security configurations and countermeasures based on emerging threats and industry trends.

Qualifications

  • Experience: 4+ years of application security experience.
  • Technical Proficiency: Proficiency with GraphQL, AWS, React, Java, Node.js, Python, and containerization technologies like Docker and Kubernetes.
  • Vulnerability Expertise: Hands-on experience with reviewing and remediating common SAST and SCA vulnerabilities.
  • Automation: Strong hands-on coding or scripting skills (e.g., Python, Go) for building security utilities and automation.
  • Soft Skills: Strong problem-solving and decision-making capabilities.

Preferred Qualifications

  • Experience in the automotive, manufacturing, or technology industries.
  • Experience with cloud native (AWS preferred) and Kubernetes hosted applications
  • Experience with Gitlab CI/CD or other popular DevOps technologies
  • Experience identifying and mitigating AI-specific vulnerabilities



Equal Opportunity

Rivian is an equal opportunity employer and complies with all applicable federal, state, and local fair employment practices laws. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender, gender expression, gender identity, genetic information or characteristics, physical or mental disability, marital/domestic partner status, age, military/veteran status, medical condition, or any other characteristic protected by law.

Rivian is committed to ensuring that our hiring process is accessible for persons with disabilities. If you have a disability or limitation, such as those covered by the Americans with Disabilities Act, that requires accommodations to assist you in the search and application process, please email us at candidateaccommodations@rivian.com.

Candidate Data Privacy

Rivian may collect, use and disclose your personal information or personal data (within the meaning of the applicable data protection laws) when you apply for employment and/or participate in our recruitment processes (“Candidate Personal Data”). This data includes contact, demographic, communications, educational, professional, employment, social media/website, network/device, recruiting system usage/interaction, security and preference information. Rivian may use your Candidate Personal Data for the purposes of (i) tracking interactions with our recruiting system; (ii) carrying out, analyzing and improving our application and recruitment process, including assessing you and your application and conducting employment, background and reference checks; (iii) establishing an employment relationship or entering into an employment contract with you; (iv) complying with our legal, regulatory and corporate governance obligations; (v) recordkeeping; (vi) ensuring network and information security and preventing fraud; and (vii) as otherwise required or permitted by applicable law.

Rivian may share your Candidate Personal Data with (i) internal personnel who have a need to know such information in order to perform their duties, including individuals on our People Team, Finance, Legal, and the team(s) with the position(s) for which you are applying; (ii) Rivian affiliates; and (iii) Rivian’s service providers, including providers of background checks, staffing services, and cloud services.

Rivian may transfer or store internationally your Candidate Personal Data, including to or in the United States, Canada, the United Kingdom, and the European Union and in the cloud, and this data may be subject to the laws and accessible to the courts, law enforcement and national security authorities of such jurisdictions.

Please note that we are currently not accepting applications from third party application services.