Platform Security Engineering - OpenBMC
Core
Designing, building, and hardening OpenBMC-based management firmware for server fleets, focusing on production manageability and security against sophisticated adversaries.
Role type
Senior IC Platform Security Engineer (Firmware/Hardware)
Builds
Production OpenBMC firmware, management stacks (DMTF/OCP standards), and security verification tooling for x86 and Arm platforms.
Domain
Server infrastructure security, embedded firmware, hardware management interfaces.
Deliverable
production ML models | product features | infrastructure
Required skills
OpenBMC/BMC firmware development, C/C++, Python, Linux kernel/user-space, Yocto/OpenEmbedded, secure boot, attestation (SPDM), threat modeling, static analysis, fuzzing.
Preferred skills
Rust or Zig, hardware roots of trust (Caliptra, TPM/HRoT), firmware vulnerability research, AI/ML infrastructure security.
Technologies
OpenBMC, Yocto, OpenEmbedded, DMTF, OCP, MCTP, PLDM, SPDM, Redfish, RDE, IPMI, KCS, eSPI, LPC, PMBus, I2C, I3C, SPI, PCIe, SMBus, U-Boot, D-Bus, sdbusplus.
Responsibilities
Design and ship OpenBMC firmware from bring-up to production; implement BMC-to-BIOS/host communications and management stacks; own BMC security posture including secure boot and authenticated updates; lead threat modeling and secure design reviews; build verification tooling for static analysis and fuzzing.
Seniority
Senior, hands-on IC with leadership responsibilities.