Software Engineer, HSM Infrastructure Security
Core
Design and implement security-critical software and firmware for HSMs, secure elements, and trusted execution environments to govern certificate issuance and cryptographic signing operations.
Role type
Senior IC embedded security engineer (HSM infrastructure)
Builds
HSM trusted applications, firmware components, host interfaces, device drivers, SDKs, and cryptographic service integrations
Domain
Hardware security / Cryptography / Embedded systems
Deliverable
production ML models | product features | infrastructure
Required skills
C, C++, Rust, applied cryptography, digital signatures, key hierarchies, PKI, X.509, certificate lifecycle protocols, secure boot, remote attestation, concurrency, memory safety, privilege separation
Preferred skills
ARM TrustZone, commercial or cloud HSM platforms, PKCS#11, KMIP, OpenSSL providers, secure-element APIs, boot ROM, bootloader, firmware signing, anti-rollback, authenticated updates, cryptographic accelerators, multi-party authorization, tamper-resistant audit mechanisms
Technologies
PKCS#11, OpenSSL, KMIP, ARM TrustZone
Responsibilities
Design and implement security-critical software and firmware for HSMs and secure elements; Build and harden policy-to-HSM boundaries for certificate issuance and cryptographic signing; Develop HSM trusted applications, firmware components, host interfaces, device drivers, SDKs, and cryptographic service integrations; Implement interfaces involving PKCS#11, OpenSSL providers, platform key-storage APIs, and hardware-security interfaces; Build systems enforcing key generation, provisioning, usage, rotation, recovery, and destruction policies; Design HSM-backed certificate authority, code-signing, key-management, device-identity, attestation, secure-boot, and provisioning systems; Write, review, test, and audit secure embedded software including test harnesses, emulators, fuzzers, and fault-injection tooling; Threat-model hardware and software trust boundaries and convert findings into engineering improvements; Collaborate with hardware, firmware, infrastructure, application, security, and product teams to integrate secure-by-default capabilities; Help establish engineering standards for HSM development, applied cryptography, secure key management, and certificate infrastructure
Seniority
Senior, hands-on IC
