Safety & Systems Engineer · San Francisco, CA

Katelyn
Wolfenberger

// Senior Software Systems Engineer · Latitude AI  ·  Founder, Control Action

A decade building safe, reliable cyber-physical systems at the frontier of autonomous vehicles — from powertrain calibration at Ford to L4 robotaxi deployment at Cruise to perception feature architecture at Latitude AI. Specialized in SOTIF, STPA, and ML validation for systems that have to work when it matters.

→ Consulting inquiry View architecture Control Action ↗
10yr
AV experience
L4
fleet certified
3
OEM programs

Career system architecture

Education
Role / employer
Skills acquired
Outputs
Foundation
KATELYN WOLFENBERGER :: CAREER SYSTEM ARCHITECTURE rev. 2025.1 · safety-critical cyber-physical systems · ~10yr runtime INIT SEQUENCE MIT · BSc Mechanical Engineering 2010 – 2015 · Cambridge, MA AUV Aluminum Reactor MIT LL · ONR Lead eng., 30-person Tesla · Battery Intern EV charge port V&V Summer 2014 Team leadership Rapid prototyping V&V test program Automotive dev MODULE 1 · FORD MOTOR COMPANY 2015 – 2018 · Dearborn, MI Powertrain Calibration Eng 3.5L engine · OBDII AV Systems Engineer L4 occupancy · SysML AV Systems Engineer Perception · TaaS Req · FMEA · SysML · RTOS · ML-to-production · regulatory compliance · functional architecture · L4 integration Ideal function analysis · embedded systems design Outputs ↗ Occupancy detection TaaS product prototype Emissions compliance L4 requirements Barbara P. James Award UPGRADE · U-MICHIGAN GRADUATE STUDIES IN ROBOTICS 2018 – 2020 Univ. of Michigan · Robotics Graduate studies · Ann Arbor, MI Advanced robotics · autonomous systems · ML for embodied AI MODULE 2 · CRUISE OCT 2021 – JUN 2024 · San Francisco, CA Inputs carried in Ford + robotics MS Senior Systems Engineer I/II L4 robotaxi · V&V · safety case Processing loops: Reqs → V&V → fleet SOTIF · STPA · FMEA at scale · safety case · behavioral reqs · sim + fleet analytics · statistics Cross-functional alignment · requirements traceability · fleet V&V Outputs ↗ Daytime L4 fleet ops Safety case docs Behavioral requirements V&V plans Multi-urban ops Failure mode analyses MODULE 3 · LATITUDE AI JUN 2024 – PRESENT · Palo Alto, CA Full stack loaded Decade of AV depth Sr. Software Systems Eng Perception · feature arch Processing loops: Func arch → ConOps ISO 26262 · SOTIF · safety analysis · perception systems · sensor HW collab · cross-fn reqs Bounding scenarios · V&V plan design Outputs ↗ Feature system archs ConOps documents Safety analyses Sensor requirements V&V plans (track+road) Cross-fn approvals SKILL BUS · ACCUMULATED TECHNICAL STACK Languages & tools Python · SQL · MATLAB Simulink · Linux · Git Automotive Ethernet Track/road/dyno testing Systems engineering Cyber-physical design Feature & functional reqs Functional arch design FMEA · ISO 26262 Safety analysis STPA · STAMP SOTIF docs Threat modeling Scenario def OUTPUT BUS · SYSTEM CAPABILITIES Deployable capability set End-to-end feature ownership: ConOps → architecture → requirements → verification → deployment SOTIF / STPA safety analysis · ISO 26262 · FMEA · sensor system integration · safety case L4 AV V&V at scale · statistical test design · cross-functional leadership · ML validation NEXT STATE → CONTROL ACTION CONSULTING Control Action · Independent Consulting AI/ML validation · robotics · AV · SOTIF & STPA analytical frameworks target: ROSCon · CoRL · Automate | substack: Control Action · SOTIF/STPA lens on AI + tech SYSTEM STATUS: NOMINAL · UPTIME: ~10 YEARS · ZERO CRITICAL FAILURES · SAFETY LEVEL: HIGH kmwolfenberger.com · v2025.1

Core expertise

Safety analysis

SOTIF & STPA

Applying STAMP-based hazard analysis to autonomous and ML-driven systems. Authoring FMEAs, conducting STPA, and writing SOTIF documentation that actually drives design decisions — not just compliance checkboxes.

STPA SOTIF FMEA ISO 26262 Threat modeling
Verification & validation

ML system V&V

Designing verification and validation programs for ML-driven autonomous capabilities — bounding scenario definition, structured track and fleet test design, statistical test planning, and sim-to-real gap analysis.

V&V plan design Track testing Fleet testing Sim analysis
Systems architecture

Feature & functional architecture

Authoring concept of operations, defining system I/Os, writing feature and functional requirements, and designing verification plans for perception and autonomy features across the full development lifecycle.

ConOps SysML Requirements Functional arch
Domain

Autonomous vehicles & robotics

A decade of embedded experience across Ford, Cruise, and Latitude AI — from powertrain calibration to L4 robotaxi safety cases to perception system architecture for ADAS features on production vehicles.

L4 AV ADAS Perception Embedded ML Robotics

Control Action

Safety engineering for systems that have to work.

Control Action is an independent consulting practice applying SOTIF and STPA frameworks to AI and embodied systems — robotics, autonomous vehicles, drones, and any ML system operating in the physical world.

The practice was built on a simple premise: most ML validation programs are designed for software, not for systems that crash. The frameworks that work for AV safety cases — STAMP, STPA, SOTIF — are underutilized everywhere else. That's the gap.

Writing on the Substack applies these lenses to broader AI and tech — accessible analysis for practitioners who want to think more rigorously about the systems they build.

Read Control Action on Substack ↗
01

SOTIF & STPA engagements

Hazard analysis, safety case review, and SOTIF documentation for ML-driven features in autonomous platforms.

02

V&V program design

Building verification and validation plans for new autonomous capabilities — bounding scenarios, test design, metrics, and deployment gates.

03

Safety architecture review

Reviewing functional architectures, requirements, and system designs against safety standards and deployment constraints.

04

Fractional systems engineering

Embedded support for early-stage robotics and AV teams building their first safety-engineering infrastructure.

Let's build something reliable.

Open to consulting engagements for AV, robotics, and embodied AI teams — particularly early-stage companies building their first serious safety engineering practice.