Confidential mandate

Embodied-AI Safety Operations Director

Planned Hiring / New

Embodied-AI Safety Operations Director mandate in Tel Aviv, Israel · Autonomous Warehouse Robotics

An autonomous warehouse-robotics developer commissions an eight-week safety-operations build to connect hazards, simulation, field evidence and release authority before expanding mixed human-robot pilots across customer sites.

The mandate

Field pilots use separate safety records for robot hardware, perception, motion planning and site procedures, making it impossible to show which combined evidence supports release in mixed pedestrian traffic. The defined problem is to create one operational safety chain from credible hazard to test, deployment constraint, event signal and stop authority before pilot volume expands.

The deliverable is an Embodied-AI Safety Operations Pack containing a system hazard and claims map, scenario library, simulation-to-field evidence protocol, release and change gates, near-miss taxonomy, incident command design, site acceptance checklist and management safety-case template. It must remain usable when models, sensors, payloads or warehouse layouts change.

Milestone one on day ten is the agreed system boundary, hazard ledger and evidence-gap notice. Milestone two at week five comprises the prioritised scenario suite, witnessed test campaign and release-gate draft; milestone three at week eight supplies the final pack, completed pilot-site rehearsal, operating measures and Product Safety Council decision paper.

The COO and independent council chair will accept the work only when they can select a sampled hazard and trace its requirement, scenario, simulation result, field observation, residual constraint and accountable release decision. The client team must also execute one stop-and-recovery rehearsal within its target time; untraceable claims or unreproducible tests block acceptance.

The client will provide robot and simulator access, software and hardware configurations, event logs, prior incidents, operating design domains, customer site procedures and named engineering and field counterparts. Product redesign, formal third-party certification, legal interpretation and ownership of post-engagement pilot operations remain outside scope.

Why this is external work

Each engineering lead can defend a subsystem, but no internal owner is independent of the schedule for expanding customer pilots. The company has strong simulation capability without an accepted method for connecting it to field exposure and release decisions. External delivery supplies specialist operating discipline and political neutrality without taking continuing safety accountability.

What you will own

  • Define the robot, human, site and remote-operator boundary so every safety claim names the conditions under which it remains valid.
  • Consolidate subsystem hazards into interaction scenarios covering occlusion, localisation loss, unexpected pedestrian behaviour, payload shift and degraded stopping performance.
  • Design evidence rules linking simulation coverage, hardware-in-loop results, controlled-site trials and live pilot observations without treating volume as representativeness.
  • Set release and change gates for models, sensors, maps, speed envelopes and fallback behaviours, including named stop and exception authority.
  • Establish a near-miss taxonomy and event-capture standard that preserves context needed for replay, causal analysis and fleet-wide containment.
  • Conduct a witnessed pilot-site rehearsal spanning unsafe behaviour detection, robot isolation, human protection, evidence preservation and controlled restart.
  • Deliver the management safety-case template, operating scorecard, unresolved-evidence register and ninety-day adoption sequence for council acceptance.

Candidate qualifications

  • Led operational safety assurance for autonomous mobile robots, industrial robotics, automated vehicles or another embodied system sharing space with people.
  • Built a system-level hazard argument that reconciled perception, planning, controls, hardware and operating-procedure evidence.
  • Connected simulation scenarios to field validation through explicit coverage, fidelity and residual-uncertainty judgments rather than test-count targets.
  • Held or designed release-stop authority for learned behaviour and can evidence how a material change triggered reassessment.
  • Investigated robot near misses using preserved telemetry, configuration and environmental context to produce fleet-level corrective action.
  • Delivered an assurance pack that engineering, field operations and an independent safety reviewer could trace and operate after engagement closure.

Non-negotiables

  • The engagement lead must work in Tel Aviv during discovery and acceptance and attend the Haifa and customer-site observations in person.
  • No active paid relationship with the robot's sensor, simulation or safety-assurance suppliers may remain undisclosed.
  • Will not represent scenario volume, incident absence or subsystem certification as sufficient evidence of system safety.
  • Can begin within four weeks and reserve named capacity through all three immovable milestone reviews.
  1. 49 words maximum. Describe a system hazard that emerged only from interaction between autonomy software, hardware and site operations, and how you tested it.
  2. 49 words maximum. How would you decide whether simulation evidence is representative enough to support a mixed-traffic field-release gate?
  3. 49 words maximum. Which configuration and event data must be preserved before restarting a robot after an unexplained near miss?

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.