Product Security Architect
$160k - $226kEnphase Energy
DescriptionEnphase Energy is a global energy technology company and a leading provider of solar, battery, and electric vehicle charging products. Founded in 2006, our innovative microinverter technology revolutionized solar power, making it a safer, more reliable, and scalable energy source. Today, the Enphase Energy System enables users to make, use, save, and sell their own power. Enphase is also one of the most successful and innovative clean energy companies in the world, with more than 80 million products shipped across 160 countries. Join our dynamic teams designing and developing next-gen energy technologies and help drive a sustainable future!This role at Enphase requires working onsite 3 days a week, with plans to transition back to a full 5-day in-office schedule over time.About the RoleWe are hiring a Product Security Architect to drive product security across Enphase's entire hardware portfolio — from silicon to cloud. This is a senior, hands-on role that owns the full lifecycle of product security: architecting and implementing security controls, driving compliance with regulations such as the EU Cyber Resilience Act (CRA) and the RED Delegated Act (2022/30), leading product security testing and certification efforts, running vulnerability management, and serving as the primary technical point of contact for external penetration testers and independent security researchers.Our product families include:IQ Gateway (Envoy) — ARM Cortex-A SoC (AM335x/AM62x) running embedded Linux, acting as the on-premise brain for every Enphase solar installation. Connects to the cloud via Wi-Fi, Ethernet, or cellular (LTE Cat-M1) and orchestrates OTA firmware delivery to the entire on-site fleet.IQ8 Microinverters — Custom 8051-based ASIC with PLC (powerline communication) connectivity. Deployed at massive scale (80M+ units). Communicates with the gateway over the AC power line using proprietary PLC protocols with AES/XXTEA encryption and SHA-256 session key derivation.IQ Battery & System Controller (Enpower) — Safety-critical Battery Management System (BMS) and automatic transfer switch controlling solar/battery/grid interactions. CAN bus + PLC interfaces. Firmware controls high-voltage DC and AC switching with direct life-safety implications.IQ EV Charger & Balcony Solar — Network-connected consumer products entering the EU market, subject to ETSI EN 303 645, RED Article 3.3, the RED Delegated Act, and the EU Cyber Resilience Act.IQ Energy Router — Intelligent energy routing with grid-interactive capabilities, controlling power flows across solar, battery, grid, and loads.You will report to the Head of Security and work as a senior technical leader within a cross-functional team spanning firmware engineering, hardware engineering, cloud platform, and product management. You will drive security outcomes across the organization without necessarily holding formal management authority, though the scope may grow to include direct reports as the product security program matures.What You Will DoSecurity Architecture: Secure Boot & Hardware Root of TrustArchitect and harden secure boot chains across the product portfolio: AM335x/AM62x (Gateway), 8051 ASIC (Microinverters), and BMS controllers (Battery/Enpower) — signed bootloaders, anti-rollback counters, eFuse/OTP provisioning, and verified boot at every stageDesign ARM TrustZone partitioning (TEE/OP-TEE) on Gateway SoCs to isolate cryptographic operations, key material, and security-critical firmware from the normal-world OSAudit and remediate JTAG/SWD debug interface exposure across all hardware products — verify fuse-based disable on production units, define debug authentication policy for engineering buildsDefine the hardware Root-of-Trust architecture for next-generation products: secure elements, PUF-based device identity, and hardware crypto acceleratorsDevice Identity & Cryptographic Key ManagementOwn the end-to-end key lifecycle: manufacturing provisioning (per-device identity injection), field rotation, revocation, and decommissioning — across 80M+ deployed devicesRedesign PLC encryption key management for microinverters: migrate from hardcoded default keys to per-site or per-device key derivation; evaluate replacement of legacy ciphers (XXTEA) with AES-based encryption within ASIC silicon constraintsBuild and maintain the mutual-TLS and PKI infrastructure for device-to-cloud authentication — per-device X.509 certificates, automated enrollment, and lifecycle management at fleet scaleDesign key storage architecture leveraging hardware-backed keystores (secure elements, TrustZone secure storage, eFuse) to eliminate software-only key storageSecure OTA Updates & Firmware HardeningArchitect the secure OTA pipeline for the Enphase fleet: signed and encrypted firmware images, A/B partition scheme, anti-rollback enforcement, and fail-safe recovery — covering gateway firmware, microinverter ASIC firmware, battery BMS firmware, and System Controller firmwareDrive compiler-level hardening across the firmware build system: stack canaries, ASLR/PIE, RELRO, FORTIFY_SOURCE, and control-flow integrity — integrate into the CMake/Clang toolchainEstablish firmware binary analysis as a release gate: static analysis, binary composition analysis (SBOM generation), and known-vulnerability scanning for all third-party componentsRegulatory Compliance & Product CertificationOwn end-to-end compliance with the EU Cyber Resilience Act: map Annex I essential requirements to technical controls, produce conformity evidence, and own the technical file and CE-marking documentation for each product familyOwn compliance with the RED Delegated Act (2022/30) Article 3.3(d)(e)(f) cybersecurity requirements for radio equipment, coordinating with notified bodies and accredited test labs on conformity assessment routesPlan and drive product security certification programs — scoping, evidence packages, remediation of test-lab findings, and audit readiness — across CRA, RED DA, and relevant standards (ETSI EN 303 645, IEC 62443)Track evolving global IoT/embedded security regulation and translate new requirements into engineering roadmaps ahead of enforcement deadlinesProduct Security TestingDefine and drive the product security test strategy across hardware, firmware, and protocol layers — static and dynamic analysis, fuzzing, protocol conformance testing, and hardware-level test benches (JTAG/SWD, side-channel, fault injection)Build repeatable, release-gating security test suites in partnership with QA and firmware engineering; define pass/fail criteria and exit gates for each product lineMaintain a current security test and certification calendar aligned to product release schedules, flagging regulatory or test-lab dependencies earlyVulnerability Management & Coordinated DisclosureOwn the product vulnerability management program (PSIRT): intake, CVSS scoring, CVE assignment/tracking, remediation SLAs, and fleet-wide patch rollout across 80M+ deployed devicesEstablish and run a coordinated vulnerability disclosure process, including researcher-facing policy, triage workflows, and cross-functional remediation ownershipReport on vulnerability posture and remediation status to engineering and business leadership; maintain audit-ready records for regulatory and customer inquiriesExternal Penetration Testing & Security Research EngagementServe as the primary technical point of contact for third-party penetration testing firms: define scope, coordinate access and lab hardware, and drive findings through triage and remediation to closureManage relationships with independent security researchers and bug bounty/responsible-disclosure channels, ensuring timely acknowledgment, validation, and resolution of externally reported issuesTranslate pentest and researcher findings into architecture and process improvements, feeding lessons learned back into secure design standardsThreat Modeling & Security StandardsLead product-level threat modeling (STRIDE/PASTA) for each hardware product family, defining attack surfaces, abuse cases, and mitigations — with particular focus on safety-critical products (System Controller, Battery) where cyber-physical attacks could cause electrical hazardsDefine and maintain security architecture standards and design patterns for the embedded fleet — publish internal architecture decision records (ADRs) and conduct security design reviews for all new product and feature developmentCommunication Protocol SecurityHarden the PLC (powerline communication) protocol stack: authentication, encryption, replay protection, and key exchange — working with the ASIC firmware team within the constraints of 8051-class microcontrollersSecure all network interfaces on the IQ Gateway: eliminate unnecessary services (SSH, MQTT) from production firmware, enforce authenticated access on all exposed APIs, and resolve the localhost authentication bypassDefine security requirements for CAN bus communication between the System Controller and Battery BMS, and for BLE/Wi-Fi provisioning flows on consumer productsWho You Are & What You BringBE/BTech/MS/MTech in Computer Science, Electrical Engineering, Computer Engineering, or a related field12+ years of experience in product/embedded security, IoT security architecture, or security engineering for hardware productsDeep expertise in ARM security architecture: TrustZone (Cortex-A TEE/OP-TEE), TrustZone-M (Cortex-M), secure boot, chain-of-trust design, and hardware Root-of-Trust implementationHands-on experience with HSM/TPM/secure element integration, cryptographic key management (AES-128/256, RSA, ECC P-256/P-384), and hardware crypto acceleratorsStrong knowledge of TLS 1.2/1.3, mutual TLS, X.509 PKI, certificate lifecycle management, and secure communication protocol design for constrained devicesProduction experience with secure OTA update architectures: firmware signing, encrypted delivery, A/B partitioning, anti-rollback, and fleet-scale deploymentDirect experience driving product-level compliance with the EU Cyber Resilience Act and/or RED Delegated Act (2022/30) — technical files, conformity assessment, and engagement with notified bodies/test labsExperience owning a vulnerability management/PSIRT function: CVSS scoring, CVE handling, coordinated disclosure, and remediation SLA managementExperience managing third-party penetration testing engagements end to end, and engaging directly with external security researchersProficiency in C/C++ for embedded systems — ARM Cortex-A (embedded Linux) and Cortex-M / 8051-class (bare-metal / RTOS) targetsExperience with compiler and binary hardening: stack protectors, PIE/ASLR, RELRO, CFI, and static/dynamic analysis toolingDemonstrated ability to lead threat modeling exercises (STRIDE, attack trees) and translate findings into actionable architecture decisionsWorking knowledge of IoT/embedded security standards: IEC 62443, ETSI EN 303 645, EU Cyber Resilience Act (Regulation 2024/2847), NIST SP 800-183Strong cross-functional collaboration skills — ability to drive security outcomes across firmware, hardware, cloud, and product teams without direct authorityPreferred QualificationsExperience securing powerline communication (PLC) protocols — HomePlug, G3-PLC, or proprietary PLC stacksExperience with CAN bus security, automotive-grade secure boot, or BMS/battery management system securityExperience with manufacturing security provisioning: secure key injection, device identity enrollment, and factory line security at scaleKnowledge of side-channel analysis, fault injection, and hardware tamper resistance countermeasuresExperience with SBOM generation tooling (CycloneDX, SPDX) and software composition analysis for firmwareFamiliarity with energy-sector regulations: NEK/IEC standards for energy equipmentPrior experience with security architecture for solar inverters, battery energy storage systems, or grid-edge devicesPrior people-management or team-lead experience, or demonstrated readiness to build and lead a small product security teamRelevant certifications: CISSP-ISSAP, GICSP (ICS security), OSCP, CCSP, or equivalentWhat We OfferOwnership of product security — architecture, testing, certification, and vulnerability management — for one of the world's largest deployed IoT energy fleets (80M+ devices)Direct impact on global energy infrastructure security — your work protects millions of homesCompetitive compensation package with equity participationOpportunity to shape Enphase's regulatory compliance posture for the EU CRA, RED Delegated Act, and emerging global IoT security regulationsDirect engagement with external researchers and pen test partners, with real influence over remediation prioritiesCollaborative engineering culture with deep technical expertise in power electronics, embedded systems, and cloud platformsCareer growth in a high-visibility role reporting to the Head of Product Security, with potential to grow into a team-lead capacityThe base pay range for this position is $160,000 to $226,000. This salary range may be modified in the future. The successful candidate’s starting pay will be determined based on job-related skills, experience, education or training, work location, and market conditions. This position is also eligible for bonus, equity, and benefits.
- ...capabilities and our industry-leading portfolio of products that are recognized globally for... ...Job Description Sandisk’s Product Security Engineering & Assurance (PSEA)... ...experienced Product Security Assurance Architect to strengthen security assurance across...SuggestedTemporary workRemote workFlexible hoursShift work
$220k - $250k
...Position Overview We are seeking a highly skilledPrincipal Cloud Security Architect with deep experience designing and securing distributed... ...the security of our cloud-connected robotic and inspection products. They will also support the creation of cloud-based multiple...SuggestedFull timeWorldwide- ...must haves are: ~5+ years of experience as Automation Architect and doing web application security testing as per OWASP standards ~5+ years of... ...Testing (IAST) o Web Application Penetration Testing o Product Security Testing o Cloud Application Security Testing...Suggested
- Role:- SAP Security Architect - GRC S/4HANA Location:- Fremont, CA( Hybrid look for locals) Mode of Hire:- FTE/Subcon Visa:- Any JD 5. SAP Security Architect Required skills: SAP security roles and authorizations Strong SAP security architecture experience Yantran LLCSuggestedLocal area
- ...difference Job Details We're looking for a Senior Application Security Architect to own and advance application security across our... ...What We're Looking For: 8+ years of Application Security / Product Security / Secure SDLC experience. 8+ years of hands-on C#/....SuggestedWork at officeLocal area
- ...capabilities and our industry-leading portfolio of products that are recognized globally for... ...Job Description Sandisk’s Product Security Engineering & Assurance (PSEA)... ...Collaborate closely with: Platform Security Architects, Firmware Engineering, Hardware/ASIC...Temporary workRemote workFlexible hoursShift work
$150k - $200k
...Solutions Business Unit and are seeking an Backplane Solutions Architect to join our Enterprise Solutions team. This is an exciting opportunity... ...such as accelerated compute (AI/ML). Identify and develop new product development opportunities through direct customer engagement,...Flexible hours- LAM RESEARCH Corporation in Fremont, California is seeking an AI Ontology Knowledge Architect to lead the design and implementation of enterprise AI architectures. This role will define and govern enterprise meaning for AI, working alongside engineers and domain experts...
- Enterprise Architect/Developer Dynamics CRMHiring Alert: We at Infosys Microsoft Practice are hiring talents for "Enterprise Architect"... ...business objectives.Translate business requirements into scalable, secure, and supportable solution designs.Drive solution design across...
$92k - $211k
The group you’ll be a part ofThis position will be part of Lam Information Security’s Application Security team, supporting Secure SDLC, product security, application risk assessments, threat modeling, vulnerability validation, penetration testing, and AI-related security...Work experience placementLocal areaRemote workFlexible hours2 days per week3 days per week1 day per week- ...capabilities and our industry-leading portfolio of products that are recognized globally for... ...with business leaders and domain architects to map business capabilities and value... ...spanning applications, integration, data/AI, security, and infrastructure—ensuring consistency...Temporary workRemote workFlexible hoursShift work
- Sr. Security Engineer Application (more important): Angular (TypeScript), Java, Okta. Infrastructure: GitHub, Jenkins, Terraform, Ansible... ...Top 10 attacks. It is also very important the experience on product development area working extensively in SDLC (not only on the DevOps...
- ...solutions, including designing scalable architectures and data pipelines. The candidate will work closely with engineering teams and product managers to create innovative AI models and ensure best practices in MLOps and data governance. Flexible work from home options are...Remote jobWork from homeFlexible hours
- ...worldwide from increasingly sophisticated cyber and AI-driven threats, securing their AI transformation. Our prevention-first approach... ...on prospect conference calls and onsite visits by providing product demonstrations, responding to technical questions and explaining...Worldwide
- ...manufacturing capabilities and our industry-leading portfolio of products that are recognized globally for innovation, performance and... ...world moving forward. Job Description Sandisk’s Product Security Engineering & Assurance (PSEA) organization is seeking highly motivated...Temporary workRemote workFlexible hoursShift work
- Job Overview: We are seeking a skilled Integration Architect/Engineer to lead the design and implementation of integration solutions between... .... PI Management: Oversee API management processes, ensuring secure, efficient, and scalable access to integration endpoints. Error...
$137.8k - $234.3k
...’s mission is to enable business growth and productivity by connecting people, process, and technology... ...highly experienced Sr. Enterprise Identity Architect to lead the design and modernization of enterprise identity security across on‑prem and cloud environments. This...Minimum wageFull timeFlexible hours- A leading technology solutions provider is seeking a PCD/TOC Security Systems Application Specialist to support cybersecurity systems in Fremont, CA. The ideal candidate will program access control systems, provide field support, and monitor operational systems. A Bachelor...
$137k - $287k
...users globally with data, information, and systems to achieve their business objectives.What you’ll doLam Research is looking for a Security Engineer to join our team. The Cloud Security Engineer is responsible for the engineering, operationalization, and continuous...Local areaImmediate startRemote workFlexible hours2 days per week3 days per week1 day per week$92k - $211k
...data, information, and systems to achieve their business objectives. The impact you’ll makeLam Research is seeking an Information Security Engineer to support the engineering, implementation, and ongoing operation of enterprise security platforms. This role is responsible...Local areaRemote workFlexible hours2 days per week3 days per week1 day per week$137k - $287k
...information, and systems to achieve their business objectives.The impact you’ll makeResponsible for the planning, design and build of security architectures; oversees the implementation of network and computer security and ensures compliance with corporate cybersecurity...Local areaImmediate startRemote workFlexible hours2 days per week3 days per week1 day per week- Salesforce Developer (Enterprise Architect) Sonsoft, Inc. is a USA based corporation duly... ...Deployment, Apex, VF, Salesforce Integration, Security implementations Experience on Force.com... ..., and other objects from Sandbox to Production environment Customizations of Reports, Dashboards...Permanent employmentFull timeH1bFlexible hours
$137k - $287k
...globally with data, information, and systems to achieve their business objectives. The Impact You'll Make Lam Research is looking for a Security Engineer to join our growing team. The Senior Cybersecurity Engineer will support DLP and CASB, focusing on Netskope. The Cyber...Local areaImmediate startRemote workFlexible hours2 days per week3 days per week1 day per week- Job Title: Enterprise Solution Architect Location: Pleasanton, CA 94588 Duration: 13 months Job Description: • s a Solution Architect, you will be responsible for translating client requirements into differentiated, deliverable solutions by leveraging your in-depth knowledge...
- Role: Java Security Developer/Lead Location: Milpitas, CA-Day one onsite Duration: 6+ Months Job Description: Look for Java Security Developer/Lead. Experience working in federal/Government domain Needs to have some FEDRAMP/ certification experience. 8+ years of experience...
$186.9k - $267.7k
...premises, and mobile offerings depend on secure, reliable automation that enables... ...closely with Engineering, Architecture, Product Management, SRE, Compliance, Cisco's Security... ...priorities.Partner with development teams, architects, product management, SRE, compliance,...Full timeTemporary workLocal areaFlexible hours$75k - $110k
A leading security solutions provider in Fremont, CA is seeking a Sales Engineer to design and implement innovative security systems. This role involves site assessments, interfacing with clients and sales teams, and ensuring that projects are completed according to high...- Saviynt is seeking a Principal Software Engineer to join its AI Security team. You will design, implement, and release end-to-end workflows for AI security products across platforms like AWS and Google Cloud. The ideal candidate should have strong expertise in Java, Spring...
$187k - $280.6k
...you join, you'll feel it. Not just in the products we build, but in how we show up for each... ...the Role The Enterprise Solutions Architect for Engineering Platform Services will set... ...services function as a cohesive, scalable, and secure ecosystem. This a hand-on role where the...Work experience placementWork at officeRemote workHome officeFlexible hours- ResponsibilitiesTechnical lead for the Avocado security platform & pico-segmentation componentsPartner with other lead developers, product managers, and sales engineers for customer-centric product and feature delivery including definition & deployment using Agile DevOpsDeliver...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Product Security Architect. Be the first to apply!

