Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Product Security Architect

$160k - $226k

Enphase Energy

Description

Enphase Energy is a global energy technology company and a leading provider of solar, battery, and electric vehicle charging products. Founded in 2006, our innovative microinverter technology revolutionized solar power, making it a safer, more reliable, and scalable energy source. Today, the Enphase Energy System enables users to make, use, save, and sell their own power. Enphase is also one of the most successful and innovative clean energy companies in the world, with more than 80 million products shipped across 160 countries.


Join our dynamic teams designing and developing next-gen energy technologies and help drive a sustainable future!

This role at Enphase requires working onsite 3 days a week, with plans to transition back to a full 5-day in-office schedule over time.

About the Role

We are hiring a Product Security Architect to drive product security across Enphase's entire hardware portfolio - from silicon to cloud. This is a senior, hands-on role that owns the full lifecycle of product security: architecting and implementing security controls, driving compliance with regulations such as the EU Cyber Resilience Act (CRA) and the RED Delegated Act (2022/30), leading product security testing and certification efforts, running vulnerability management, and serving as the primary technical point of contact for external penetration testers and independent security researchers.

Our product families include:
  • IQ Gateway (Envoy) - ARM Cortex-A SoC (AM335x/AM62x) running embedded Linux, acting as the on-premise brain for every Enphase solar installation. Connects to the cloud via Wi-Fi, Ethernet, or cellular (LTE Cat-M1) and orchestrates OTA firmware delivery to the entire on-site fleet.
  • IQ8 Microinverters - Custom 8051-based ASIC with PLC (powerline communication) connectivity. Deployed at massive scale (80M+ units). Communicates with the gateway over the AC power line using proprietary PLC protocols with AES/XXTEA encryption and SHA-256 session key derivation.
  • IQ Battery & System Controller (Enpower) - Safety-critical Battery Management System (BMS) and automatic transfer switch controlling solar/battery/grid interactions. CAN bus + PLC interfaces. Firmware controls high-voltage DC and AC switching with direct life-safety implications.
  • IQ EV Charger & Balcony Solar - Network-connected consumer products entering the EU market, subject to ETSI EN 303 645, RED Article 3.3, the RED Delegated Act, and the EU Cyber Resilience Act.
  • IQ Energy Router - Intelligent energy routing with grid-interactive capabilities, controlling power flows across solar, battery, grid, and loads.
You will report to the Head of Security and work as a senior technical leader within a cross-functional team spanning firmware engineering, hardware engineering, cloud platform, and product management. You will drive security outcomes across the organization without necessarily holding formal management authority, though the scope may grow to include direct reports as the product security program matures.

What You Will Do

Security Architecture: Secure Boot & Hardware Root of Trust
  • Architect and harden secure boot chains across the product portfolio: AM335x/AM62x (Gateway), 8051 ASIC (Microinverters), and BMS controllers (Battery/Enpower) - signed bootloaders, anti-rollback counters, eFuse/OTP provisioning, and verified boot at every stage
  • Design ARM TrustZone partitioning (TEE/OP-TEE) on Gateway SoCs to isolate cryptographic operations, key material, and security-critical firmware from the normal-world OS
  • Audit and remediate JTAG/SWD debug interface exposure across all hardware products - verify fuse-based disable on production units, define debug authentication policy for engineering builds
  • Define the hardware Root-of-Trust architecture for next-generation products: secure elements, PUF-based device identity, and hardware crypto accelerators
Device Identity & Cryptographic Key Management
  • Own the end-to-end key lifecycle: manufacturing provisioning (per-device identity injection), field rotation, revocation, and decommissioning - across 80M+ deployed devices
  • Redesign PLC encryption key management for microinverters: migrate from hardcoded default keys to per-site or per-device key derivation; evaluate replacement of legacy ciphers (XXTEA) with AES-based encryption within ASIC silicon constraints
  • Build and maintain the mutual-TLS and PKI infrastructure for device-to-cloud authentication - per-device X.509 certificates, automated enrollment, and lifecycle management at fleet scale
  • Design key storage architecture leveraging hardware-backed keystores (secure elements, TrustZone secure storage, eFuse) to eliminate software-only key storage
Secure OTA Updates & Firmware Hardening
  • Architect the secure OTA pipeline for the Enphase fleet: signed and encrypted firmware images, A/B partition scheme, anti-rollback enforcement, and fail-safe recovery - covering gateway firmware, microinverter ASIC firmware, battery BMS firmware, and System Controller firmware
  • Drive compiler-level hardening across the firmware build system: stack canaries, ASLR/PIE, RELRO, FORTIFY_SOURCE, and control-flow integrity - integrate into the CMake/Clang toolchain
  • Establish firmware binary analysis as a release gate: static analysis, binary composition analysis (SBOM generation), and known-vulnerability scanning for all third-party components
Regulatory Compliance & Product Certification
  • Own end-to-end compliance with the EU Cyber Resilience Act: map Annex I essential requirements to technical controls, produce conformity evidence, and own the technical file and CE-marking documentation for each product family
  • Own compliance with the RED Delegated Act (2022/30) Article 3.3(d)(e)(f) cybersecurity requirements for radio equipment, coordinating with notified bodies and accredited test labs on conformity assessment routes
  • Plan and drive product security certification programs - scoping, evidence packages, remediation of test-lab findings, and audit readiness - across CRA, RED DA, and relevant standards (ETSI EN 303 645, IEC 62443)
  • Track evolving global IoT/embedded security regulation and translate new requirements into engineering roadmaps ahead of enforcement deadlines
Product Security Testing
  • Define and drive the product security test strategy across hardware, firmware, and protocol layers - static and dynamic analysis, fuzzing, protocol conformance testing, and hardware-level test benches (JTAG/SWD, side-channel, fault injection)
  • Build repeatable, release-gating security test suites in partnership with QA and firmware engineering; define pass/fail criteria and exit gates for each product line
  • Maintain a current security test and certification calendar aligned to product release schedules, flagging regulatory or test-lab dependencies early
Vulnerability Management & Coordinated Disclosure
  • Own the product vulnerability management program (PSIRT): intake, CVSS scoring, CVE assignment/tracking, remediation SLAs, and fleet-wide patch rollout across 80M+ deployed devices
  • Establish and run a coordinated vulnerability disclosure process, including researcher-facing policy, triage workflows, and cross-functional remediation ownership
  • Report on vulnerability posture and remediation status to engineering and business leadership; maintain audit-ready records for regulatory and customer inquiries
External Penetration Testing & Security Research Engagement
  • Serve as the primary technical point of contact for third-party penetration testing firms: define scope, coordinate access and lab hardware, and drive findings through triage and remediation to closure
  • Manage relationships with independent security researchers and bug bounty/responsible-disclosure channels, ensuring timely acknowledgment, validation, and resolution of externally reported issues
  • Translate pentest and researcher findings into architecture and process improvements, feeding lessons learned back into secure design standards
Threat Modeling & Security Standards
  • Lead product-level threat modeling (STRIDE/PASTA) for each hardware product family, defining attack surfaces, abuse cases, and mitigations - with particular focus on safety-critical products (System Controller, Battery) where cyber-physical attacks could cause electrical hazards
  • Define and maintain security architecture standards and design patterns for the embedded fleet - publish internal architecture decision records (ADRs) and conduct security design reviews for all new product and feature development
Communication Protocol Security
  • Harden the PLC (powerline communication) protocol stack: authentication, encryption, replay protection, and key exchange - working with the ASIC firmware team within the constraints of 8051-class microcontrollers
  • Secure all network interfaces on the IQ Gateway: eliminate unnecessary services (SSH, MQTT) from production firmware, enforce authenticated access on all exposed APIs, and resolve the localhost authentication bypass
  • Define security requirements for CAN bus communication between the System Controller and Battery BMS, and for BLE/Wi-Fi provisioning flows on consumer products
Who You Are & What You Bring
  • BE/BTech/MS/MTech in Computer Science, Electrical Engineering, Computer Engineering, or a related field
  • 12+ years of experience in product/embedded security, IoT security architecture, or security engineering for hardware products
  • Deep expertise in ARM security architecture: TrustZone (Cortex-A TEE/OP-TEE), TrustZone-M (Cortex-M), secure boot, chain-of-trust design, and hardware Root-of-Trust implementation
  • Hands-on experience with HSM/TPM/secure element integration, cryptographic key management (AES-128/256, RSA, ECC P-256/P-384), and hardware crypto accelerators
  • Strong knowledge of TLS 1.2/1.3, mutual TLS, X.509 PKI, certificate lifecycle management, and secure communication protocol design for constrained devices
  • Production experience with secure OTA update architectures: firmware signing, encrypted delivery, A/B partitioning, anti-rollback, and fleet-scale deployment
  • Direct experience driving product-level compliance with the EU Cyber Resilience Act and/or RED Delegated Act (2022/30) - technical files, conformity assessment, and engagement with notified bodies/test labs
  • Experience owning a vulnerability management/PSIRT function: CVSS scoring, CVE handling, coordinated disclosure, and remediation SLA management
  • Experience managing third-party penetration testing engagements end to end, and engaging directly with external security researchers
  • Proficiency in C/C++ for embedded systems - ARM Cortex-A (embedded Linux) and Cortex-M / 8051-class (bare-metal / RTOS) targets
  • Experience with compiler and binary hardening: stack protectors, PIE/ASLR, RELRO, CFI, and static/dynamic analysis tooling
  • Demonstrated ability to lead threat modeling exercises (STRIDE, attack trees) and translate findings into actionable architecture decisions
  • Working knowledge of IoT/embedded security standards: IEC 62443, ETSI EN 303 645, EU Cyber Resilience Act (Regulation 2024/2847), NIST SP 800-183
  • Strong cross-functional collaboration skills - ability to drive security outcomes across firmware, hardware, cloud, and product teams without direct authority
Preferred Qualifications
  • Experience securing powerline communication (PLC) protocols - HomePlug, G3-PLC, or proprietary PLC stacks
  • Experience with CAN bus security, automotive-grade secure boot, or BMS/battery management system security
  • Experience with manufacturing security provisioning: secure key injection, device identity enrollment, and factory line security at scale
  • Knowledge of side-channel analysis, fault injection, and hardware tamper resistance countermeasures
  • Experience with SBOM generation tooling (CycloneDX, SPDX) and software composition analysis for firmware
  • Familiarity with energy-sector regulations: NEK/IEC standards for energy equipment
  • Prior experience with security architecture for solar inverters, battery energy storage systems, or grid-edge devices
  • Prior people-management or team-lead experience, or demonstrated readiness to build and lead a small product security team
  • Relevant certifications: CISSP-ISSAP, GICSP (ICS security), OSCP, CCSP, or equivalent
What We Offer
  • Ownership of product security - architecture, testing, certification, and vulnerability management - for one of the world's largest deployed IoT energy fleets (80M+ devices)
  • Direct impact on global energy infrastructure security - your work protects millions of homes
  • Competitive compensation package with equity participation
  • Opportunity to shape Enphase's regulatory compliance posture for the EU CRA, RED Delegated Act, and emerging global IoT security regulations
  • Direct engagement with external researchers and pen test partners, with real influence over remediation priorities
  • Collaborative engineering culture with deep technical expertise in power electronics, embedded systems, and cloud platforms
  • Career growth in a high-visibility role reporting to the Head of Product Security, with potential to grow into a team-lead capacity

The base pay range for this position is $160,000 to $226,000. This salary range may be modified in the future. The successful candidate's starting pay will be determined based on job-related skills, experience, education or training, work location, and market conditions. This position is also eligible for bonus, equity, and benefits.
Vacancy posted 22 hours ago
Similar jobs that could be interesting for youBased on the Product Security Architect in Fremont, CA vacancy
  • $160k - $226k

     ...leading provider of solar, battery, and electric vehicle charging products. Founded in 2006, our innovative microinverter technology...  ...schedule over time.About the RoleWe are hiring a Product Security Architect to drive product security across Enphase's entire hardware portfolio... 
    Suggested
    Work at office
    3 days per week

    Enphase Energy

    Fremont, CA
    1 day ago
  •  ...must haves are: • 5+ years of experience as Automation Architect and doing web application security testing as per OWASP standards • 5+ years of...  ...Testing (IAST) o Web Application Penetration Testing o Product Security Testing o Cloud Application Security Testing... 
    Suggested

    Intelliswift

    Pleasanton, CA
    3 days ago
  • $189.99k - $256.5k

     ...rewards, along with the technology to deliver these products in seamless, integrated ways. BHN’s network...  ...real impact. Overview: As a Principal Security Engineer, you'll serve as the technical strategist and architect driving security and identity strategy across... 
    Suggested
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work
    Flexible hours

    Blackhawk Network

    Pleasanton, CA
    1 day ago
  •  ...will playa central roleinGraphcore'swork building the future of AI computing. About the Role We are seeking a Principal Security Architect to design, maintain and secure scalable infrastructure solutions for cryptographic key management. In this strategic role,... 
    Suggested
    Contract work
    Temporary work
    Work at office
    Flexible hours

    Jobleads-US

    Milpitas, CA
    1 day ago
  •  ...Blackhawk Network seeks a Principal Security Engineer to define security and IAM strategy across the organization, focusing on identity management, access governance, and zero-trust principles. You will guide architectural decisions across network, endpoint, and cloud... 
    Suggested
    Remote work

    Jobleads-US

    Pleasanton, CA
    1 day ago
  • $142.2k - $208.56k

     ...through deep vertical integration, with design, engineering, and production happening in-house across our global offices and manufacturing...  ...OverviewWe are seeking an experienced Cyber Incident Response Security Engineer to join our global security team in Newark, CA . This... 
    Hourly pay

    Lucid Motors

    Newark, CA
    1 day ago
  • $159.3k - $212.8k

     ...players and developers to the games and communities they love, ATG Security is at the center of customer, builder and content journeys. Our...  ...and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the... 
    Temporary work
    Internship
    Flexible hours

    Amazon

    Newark, CA
    1 day ago
  • $137.8k - $234.3k

     ...’s mission is to enable business growth and productivity by connecting people, process, and technology...  ...highly experienced Sr. Enterprise Identity Architect to lead the design and modernization of enterprise identity security across on‑prem and cloud environments. This... 
    Minimum wage
    Full time
    Flexible hours

    KLA-Tencor

    Milpitas, CA
    2 days ago
  • $92k - $211k

    The group you’ll be a part ofThis position will be part of Lam Information Security’s Application Security team, supporting Secure SDLC, product security, application risk assessments, threat modeling, vulnerability validation, penetration testing, and AI-related security... 
    Work experience placement
    Local area
    Remote work
    Flexible hours
    2 days per week
    3 days per week
    1 day per week

    Lam Research Corporation

    Fremont, CA
    4 days ago
  • $130.4k - $179k

     ...Purpose & Responsibilities: Elo is seeking an experienced Security Engineer to serve as a senior technical security leader within...  ...posture of Elo's Android devices, AWS cloud services, payment products, software development environments, and software supply chain.... 
    Full time
    Temporary work
    Work at office
    Local area

    ELO Touch

    Milpitas, CA
    3 days ago
  •  ...movement as a Senior Enterprise Solution Architect To support our rapid growth and...  ...our Enterprise Resource Planning (ERP), Product Lifecycle Management (PLM), Manufacturing...  ...Cross-System Integration: Architect secure, scalable integrations connecting shop-floor... 
    Full time
    Flexible hours
    Shift work
    Night shift
    Weekend work

    Commonwealth Fusion Systems

    Milpitas, CA
    2 days ago
  •  ...Client in Pleasanton is seeking a Sr. Full Stack Security Software Engineer IAM to design, build, and maintain secure IAM features for...  ...HIPAA, NIST, and ISO 27001 standards. You’ll collaborate with Product, DevOps, and Security teams in a fast-growing healthcare tech... 
    3 days per week

    Jobleads-US

    Pleasanton, CA
    12 hours ago
  • $137k - $287k

     ...information, and systems to achieve their business objectives.The impact you’ll makeResponsible for the planning, design and build of security architectures; oversees the implementation of network and computer security and ensures compliance with corporate cybersecurity... 
    Local area
    Immediate start
    Remote work
    Flexible hours
    2 days per week
    3 days per week
    1 day per week

    Lam Research Corporation

    Fremont, CA
    3 days ago
  • $137k - $287k

     ...users globally with data, information, and systems to achieve their business objectives.What you’ll doLam Research is looking for a Security Engineer to join our team. The Cloud Security Engineer is responsible for the engineering, operationalization, and continuous... 
    Local area
    Immediate start
    Remote work
    Flexible hours
    2 days per week
    3 days per week
    1 day per week

    Lam Research Corporation

    Fremont, CA
    3 days ago
  •  ...Coding Standards, Deployment, Apex, VF, Salesforce Integration, Security implementationsExperience on Force.com Integration...  ...Custom Configurations, packages, and other objects from Sandbox to Production environmentCustomizations of Reports, Dashboards, Workflows, Approval... 
    Permanent employment
    Full time
    H1b
    Flexible hours

    Sonsoft

    Pleasanton, CA
    4 days ago
  • $137k - $287k

     ...globally with data, information, and systems to achieve their business objectives.The impact you’ll makeLam Research is looking for a Security Engineer to join our growing team. The Senior Cybersecurity Engineer will support DLP and CASB, focusing on Netskope. The Cyber... 
    Local area
    Immediate start
    Remote work
    Flexible hours
    2 days per week
    3 days per week
    1 day per week

    Lam Research Corporation

    Fremont, CA
    2 days ago
  • $121k - $190k

     ...Applications team is looking for a Staff PLM Architect to help build core systems and improve...  ...ERP solutions, RFQ/RFP of in use or new products to align business teams, systems...  ...accountable for maintaining compliance with security, regulatory, and audit requirements, enforcing... 
    Full time
    Temporary work
    Remote work
    Relocation package
    Flexible hours

    Agility Robotics

    Fremont, CA
    1 day ago
  • $92k - $211k

     ...information, and systems to achieve their business objectives. The impact you'll make Lam Research is seeking an Information Security Engineer to support the engineering, implementation, and ongoing operation of enterprise security platforms. This role is... 
    Local area
    Remote work
    Flexible hours
    2 days per week
    3 days per week
    1 day per week

    Lam Research

    Fremont, CA
    3 days ago
  • $140k - $170k

     ...Location 5567 Cushing Pkwy,Fremont, CA, 94538,United States Employee Type Full Time Exempt Senior Information Security Engineer FLSA: Exemptposition LOCATION: Fremont, CA (Onsite) SALARY: $140,000 - $170,000 Job Summary The Information Security Engineer... 
    Full time

    Entertimeonline

    Fremont, CA
    2 days ago
  • $186.9k - $267.7k

     ...platform, our SaaS, on-premises, and mobile offerings depend on secure, reliable, and high-performance software engineering to build,...  ...development. Partnering closely with Engineering, Architecture, Product Management, SRE, and Cisco’s Security and Trust Organization (... 
    Full time
    Temporary work
    Local area
    Flexible hours

    CISCO Systems

    Milpitas, CA
    1 day ago
  •  ...Staff Cloud Security Engineer Are you ready to take the next step in your career? Join us for an exciting opportunity at Albertsons...  ...ability to deploy, scale, and support security platforms in production environments Preferred Experience supporting or... 
    Weekly pay

    Vons

    Pleasanton, CA
    1 day ago
  •  ...Elo is seeking a Security Engineer to join our R&D team in Milpitas, CA. This hands-on senior role strengthens security across Android devices, AWS cloud, payment products, and the software supply chain. You will define security strategy, implement controls, and lead... 

    Jobleads-US

    Milpitas, CA
    22 hours ago
  • ResponsibilitiesTechnical lead for the Avocado security platform & pico-segmentation componentsPartner with other lead developers, product managers, and sales engineers for customer-centric product and feature delivery including definition & deployment using Agile DevOpsDeliver... 

    Avocado Systems

    Milpitas, CA
    more than 2 months ago
  •  ...Job Description Job Description Company Description About the Host Security Engineer Opportunity Talent Connection is partnering with a leading enterprise organization seeking an experienced Host Security Engineer to strengthen and advance enterprise security... 

    Talent Connection

    Pleasanton, CA
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Product Security Architect. Be the first to apply!