Staff Firmware Engineer, Platform Security
Full-time
ALSO
Responsibilities
- Define secure boot architecture across MCU families, including image signing, verification, anti-rollback, and production debug/JTAG lockdown.
- Own on-device and fleet key strategies, key hierarchies, and HSM/OTP/secure-element integration with signing and PKI services.
- Lead CAN/CAN-FD network security, including authentication, integrity, encryption, protected diagnostics, and secure UDS access.
- Own end-to-end firmware update trust, including signed and encrypted payloads, on-device verification, rollback safety, and cloud-to-vehicle handoff.
- Architect reusable security libraries and APIs for cryptographic wrappers, secure storage, and authentication services.
- Lead threat modeling and hardening across boot, update, and network attack surfaces.
- Drive security testing through benchtop proofs of concept, negative tests, hardware-in-the-loop scenarios, and CI checks.
- Partner with firmware, cloud, manufacturing, and systems teams on requirements, production readiness, and trade-offs.
- Mentor engineers and provide design leadership across the organization.
Requirements
- 8+ years of embedded software or firmware development experience with deep ownership of secure boot, cryptography, or vehicle/IoT security architecture.
- Proven experience setting technical direction across multiple ECUs or products.
- BS in an engineering discipline, preferably Computer Science or Electrical Engineering.
- Hands-on expertise with AES, ECC/RSA, HMAC, certificates, key provisioning, OTP/fuse programming, and HSM or secure element usage in production.
- Experience designing and shipping secure boot chains, bootloaders, signed firmware images, and OTA trust models in production.
- Vehicle or industrial network security experience, including CAN/CAN-FD, authenticated messaging, and secure diagnostics, is preferred.
- Expert-level C/C++ experience on bare-metal or RTOS platforms, with familiarity with linkers, memory maps, and JTAG/SWD debugging tools.
- Ability to integrate signing and verification into CI and release pipelines and drive platform-wide adoption.
- Strong communication, documentation, threat-modeling, runbook, and engineering mentorship skills.
- Hardware-in-the-loop testing and emulation experience is preferred.
Benefits
- Health, dental, and vision insurance covered up to 100% with FSA and HSA options.
- One Medical membership and dedicated insurance advocates.
- Fertility and family-building benefits through Progyny.
- Flexible time off.
- 401(k) match.
- Located in Silicon Valley.
Vacancy posted more than 2 months ago
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Firmware Engineer, Platform Security. Be the first to apply!
Related searches
- assistant engineer Palo Alto, CA
- staff engineer Palo Alto, CA
- staff data engineer Palo Alto, CA
- software engineer staff Palo Alto, CA
- senior staff engineer Palo Alto, CA
- senior staff systems engineer Palo Alto, CA
- technology administrator Palo Alto, CA
- engineering aide Palo Alto, CA
- platform engineer Palo Alto, CA
- platform engineering manager Palo Alto, CA
