The SF Climate Week 2025 calendar is now open! 🎉 Register for 200+ events now before they fill up.
Back

VSOC Analyst - Security Tools Developer

4 months ago
Full time role
In-person · Newark, CA, US... more
Leading the future in luxury electric and mobility
At Lucid, we set out to introduce the most captivating, luxury electric vehicles that elevate the human experience and transcend the perceived limitations of space, performance, and intelligence. Vehicles that are intuitive, liberating, and designed for the future of mobility.
 
We plan to lead in this new era of luxury electric by returning to the fundamentals of great design – where every decision we make is in service of the individual and environment. Because when you are no longer bound by convention, you are free to define your own experience.
 
Come work alongside some of the most accomplished minds in the industry. Beyond providing competitive salaries, we’re providing a community for innovators who want to make an immediate and significant impact. If you are driven to create a better, more sustainable future, then this is the right place for you.

Job TitleVSOC Analyst , Security Tools Developer

Overview:

We are seeking a mid-level security professional to join our Vehicle Security Operations Center (VSOC) team and focus on designing, building, and improving security tools. In this role, you will help detect and respond to threats targeting connected vehicles and related infrastructure while creating and maintaining specialized tools for threat detection, firmware analysis, network enumeration, and security assessments. A successful candidate will have intermediate-level cybersecurity experience, strong development skills in Python/C, and a passion for building solutions that protect modern automotive ecosystems.

Key Responsibilities:

  1. Security Tool Development
  • Automated Threat Detection: Develop and maintain scripts, modules, or full-fledged applications (in Python, C, etc.) to identify malicious behavior in real time.
  • Firmware Analysis & Data Gathering: Create tools to extract, parse, and analyze firmware images, identifying potential vulnerabilities or indicators of compromise.
  • Network Enumeration: Implement enumeration capabilities for connected devices, scanning for open ports, services, and known vulnerabilities in automotive or supporting networks.
  • Threat Modeling: Collaborate with security architects and engineering teams to design tools that simulate potential attack vectors on vehicle electronics, wireless interfaces, back-end systems, and applications.
  • Security Assessment Tools: Build or integrate solutions for testing wireless protocols, OS, and applications used in the automotive ecosystem (e.g., Wi-Fi, Bluetooth, cellular, infotainment).
  • Incident Detection & Investigation
    • Monitor security events across in-vehicle networks, embedded systems, and supporting infrastructure.
    • Perform initial triage and investigation of alerts before escalating complex incidents to Tier 2 or Tier 3 analysts.
    • Use custom-built tooling and threat intelligence to quickly identify and prioritize threats.
  • Event Management & Analysis
    • Coordinate event logging and alerting from multiple data sources, including vehicle telemetry, SIEM platforms, and cloud services.
    • Conduct deep-dive analyses of security events and recommend improvements to detection logic and correlation rules.
    • Continuously refine detection capabilities by incorporating lessons learned from security research or real-world incidents.
  • SIEM Integration
    • Integrate new data sources (e.g., firmware scans, network enumerations, wireless assessments) into SIEM platforms (Splunk etc.).
    • Develop custom dashboards, rules, and queries to filter noise, highlight anomalies, and surface critical threats.
    • Ensure scalability and efficiency of data ingestion processes, working closely with DevOps and infrastructure teams.
  • UX & Workflow Optimization
    • Apply basic UX best practices to design intuitive interfaces, streamlined workflows, and clear visualizations for both custom tools and SIEM dashboards.
    • Gather feedback from VSOC analysts to improve usability, effectiveness, and speed of security tools.
  • Standard Operating Procedures (SOPs)
    • Adhere to established SOPs, Incident Response Plans, and automotive security regulations (e.g., ISO/SAE 21434, UNECE WP.29).
    • Contribute to the creation and continuous improvement of SOPs by integrating insights from tool development and incident handling.
  • Collaboration & Documentation
    • Work closely with cross-functional teams (vehicle engineering, software development, IT operations) to align tool functionality with broader security requirements.
    • Thoroughly document new tools, libraries, processes, and code repositories to ensure consistent use and ongoing maintainability.
    • Communicate findings, metrics, and recommendations to both technical and non-technical stakeholders.

    Qualifications:

    • Education & Experience
      • Bachelor’s degree in Computer Science, Cybersecurity, Electrical Engineering, or a related field (or equivalent practical experience).
      • 3+ years of v, or a related role.
      • Familiarity with automotive security or embedded systems (ISO/SAE 21434, UNECE WP.29) is a plus, but not mandatory.
    • Technical Skills
      • Proficiency in Python and C for automated tooling (e.g., firmware analysis, network enumeration, threat modeling).
      • Experience with standard SOC tools and processes (SIEM platforms, IDS/IPS, EDR, log management, etc.).
      • Strong understanding of networking fundamentals (TCP/IP, DNS, firewalls) and experience analyzing network traffic.
      • Basic knowledge of wireless technologies (Wi-Fi, Bluetooth, cellular) and cloud platforms (AWS, Azure, GCP).
      • Familiarity with containerization (Docker, Kubernetes), CI/CD pipelines, and DevSecOps principles is beneficial.
    • Soft Skills
      • Strong analytical and problem-solving skills, with attention to detail.
      • Effective communication, able to convey complex security concerns to diverse audiences.
      • Proactive mindset, collaborating well in a fast-paced, evolving security environment.
    • Certifications (Nice-to-Have)
      • CompTIA Security+, GIAC (e.g., GCIH, GCDA), or other relevant security certifications.
      • Automotive cybersecurity training or credentials.
    Salary Range: The compensation range for this position is specific to the locations listed below and is the range Lucid reasonably and in good faith expects to pay for the position taking into account the wide variety of factors that are considered in making compensation decisions, including job-related knowledge; skillset; experience, education and training; certifications; and other relevant business and organizational factors.
     
    Additional Compensation and Benefits: Lucid offers a wide range of competitive benefits, including medical, dental, vision, life insurance, disability insurance, vacation, and 401k. The successful candidate may also be eligible to participate in Lucid’s equity program and/or a discretionary annual incentive program, subject to the rules governing such programs.  (Cash or equity incentive awards, if any, will depend on various factors, including, without limitation, individual and company performance.)
    Base Pay Range (Annual)
    $145,600$200,200 USD

    By Submitting your application, you understand and agree that your personal data will be processed in accordance with our Candidate Privacy Notice. If you are a California resident, please refer to our California Candidate Privacy Notice.

    To all recruitment agencies: Lucid Motors does not accept agency resumes. Please do not forward resumes to our careers alias or other Lucid Motors employees. Lucid Motors is not responsible for any fees related to unsolicited resumes. 
     
    Subscribe