OpenAI2 дня назад

Software Engineer, HSM Infrastructure Security, Consumer Devices

Зарплата не указана
РЫНОК
15 421медиана по профессии
CISO · 26 вакансий с указанной зарплатой
6 067половина предложений: 11 227–25 344785 375
Работодатель не указал зарплату — сравните с рынком сами.
Полная занятостьSan Francisco

Обязанности

  • 01Design and implement security-critical software and firmware for HSMs, secure elements, trusted execution environments, and hardware roots of trust.
  • 02Build and harden the policy-to-HSM boundary responsible for authorizing certificate issuance and cryptographic signing operations.
  • 03Develop HSM trusted applications, firmware components, host interfaces, device drivers, SDKs, or cryptographic service integrations.
  • 04Implement or extend cryptographic interfaces such as PKCS#11, OpenSSL providers or engines, platform key-storage APIs, or comparable hardware-security interfaces.
  • 05Build firmware and software that cryptographically enforces key generation, provisioning, usage, rotation, recovery, and destruction policies.
  • 06Design and implement HSM-backed certificate authority, code-signing, key-management, and device-identity systems.
  • 07Develop end-to-end cryptographic protocols spanning devices, secure hardware, policy services, and backend infrastructure.
  • 08Build security capabilities supporting device attestation, secure boot, factory provisioning and restoration, user registration, and authentication.
  • 09Design controls that make trusted software and policy changes verifiable, auditable, and subject to appropriate multi-party authorization.
  • 10Write, review, test, and audit secure embedded software for resource-constrained environments.
  • 11Develop test harnesses, emulators, fuzzers, and fault-injection tooling to validate security properties and failure behavior.
  • 12Threat-model hardware and software trust boundaries and translate findings into concrete engineering improvements.
  • 13Partner with hardware, firmware, infrastructure, application, and security teams to integrate secure-by-default capabilities into production systems.
  • 14Help establish engineering standards for HSM development, applied cryptography, secure key management, and certificate infrastructure.

Требования

  • 015+ years experience building secure embedded firmware for constrained environments
  • 02Deep programming experience in C, C++, or Rust.
  • 03Strong track record of designing, implementing, debugging, and shipping production systems software.
  • 04Hands-on experience developing security-critical software or firmware within, or directly adjacent to, an HSM, secure element, TEE, or hardware root of trust.
  • 05Experience developing one or more of: HSM firmware or trusted applications; cryptographic mechanisms or hardware-accelerated cryptographic services; HSM device drivers, host libraries, SDKs, or middleware; PKCS#11 providers, mechanisms, or integrations; secure key-provisioning or key-injection protocols; HSM-backed certificate authority or code-signing systems; signing-policy enforcement within a hardware-backed trust boundary.
  • 06Strong knowledge of applied cryptography, digital signatures, key hierarchies, secure key management, and cryptographic protocol design.
  • 07Experience with PKI, X.509 certificates, certificate authorities, certificate issuance, and certificate lifecycle protocols.
  • 08Familiarity with secure boot, measured boot, device identity, remote attestation, or hardware-backed storage.
  • 09Experience reasoning about concurrency, memory safety, privilege separation, hardware interfaces, failure modes, and side-channel or physical attack considerations.
  • 10Ability to evaluate security designs and personally implement the software required to realize them.
  • 11Clear communication skills and ability to collaborate across hardware, firmware, backend, and product teams.
Software Engineer, HSM Infrastructure Security, Consumer Devices · Rekru