Product Security Engineer

🕒 Julho 27

🐻 Alaska, California – Remoto

infoinfo

💵 $154.000 - $210.000 / ano

⏰ Tempo Integral

🟠 Sênior

🔴 Especialista

👮‍♂️ Cibersegurança / Engenheiro de Segurança

👻 Score fantasma 31%

infoinfo

🗣️🇺🇸🇬🇧 Inglês obrigatório

Candidatar-se
Encontrar Vagas Remotas Similares

📊 Verifique sua pontuação de currículo para esta vaga

Melhore suas chances de conseguir uma entrevista verificando sua pontuação de currículo antes de se candidatar.

Logo of OKSI

OKSI

51 - 200 funcionários

Fundada em 1991

🎖️ Defesa

🚀 Aeroespacial

🤖 Inteligência Artificial

💰 $206.500 Grant - Opto-Knowledge Systems em 2024-01

Defense • Aerospace • Artificial Intelligence

A OKSI é uma empresa de sensores e autonomia voltada para defesa e aeroespacial, que desenvolve buscadores eletro-ópticos/infravermelhos (EO/IR), sistemas de orientação precisa, navegação em ambientes sem GPS (por exemplo, OMNInav) e hardware e software aprimorados por aprendizado de máquina. Há mais de 35 anos, a empresa tem produzido soluções avançadas de visão computacional e IA/ML, ferramentas de modelagem e simulação, e pacotes de sensores exclusivos para eventos de alta velocidade, hipersônica, diagnósticos de combustão, observação espacial e terrestre, e sensoriamento ambiental. A OKSI atende principalmente clientes governamentais e de defesa, possuindo mais de 450 contratos governamentais e oferecendo capacidades para autonomia, precisão de orientação e monitoramento ambiental.

Descrição

• Lead threat modeling and security analysis across hardware, firmware, and software throughout the product lifecycle. • Produce threat matrices, risk assessments, and security requirements traceable through design reviews and release gates. • Own CVE tracking, vulnerability management, and security baseline compliance across the product portfolio. • Define and implement hardening standards for embedded Linux, RTOS, and bare-metal environments. • Establish code signing policies, secure boot chain integrity, and validation procedures. • Partner with IT and Engineering to architect and maintain the product signing and key management infrastructure using HSMs, KMS, or equivalent systems. • Own OKSI's anti-tamper posture aligned with DoD policy (DoDI 5200.39) and applicable Program Protection Plan requirements. • Define IP protection strategy spanning software binary protection, hardware design protection, firmware confidentiality, and cryptographically bound license enforcement. • Serve as OKSI's product security authority. • Establish company-wide standards, lead design reviews, provide security sign-off at program milestones, and embed security requirements into the Systems Engineering process. • Provide guidance and training to Engineering, IT, and Operations teams on secure design principles.

🎯 Requisitos

• 7+ years of product security, embedded security, or cybersecurity systems engineering in a defense, aerospace, or advanced technology environment. • Demonstrated expertise leading threat modeling, security risk assessments, and vulnerability analysis across hardware, firmware, and software domains — including production of threat matrices, attack surface analyses, and traceable mitigation plans. • Hands-on experience defining and implementing security policies and standards (not just executing implementation tasks). You own the policy and architecture. • Working knowledge of secure boot architectures, anti-tamper techniques, and embedded platform security (e.g., UEFI Secure Boot, ARM TrustZone, fuse-based root-of-trust). • Practical experience with embedded Linux hardening: kernel configuration, module signing, RBAC/least-privilege access models, debug interface lockdown, and production credential management. • Experience with key management infrastructure and signing pipelines (HSMs, KMS, or equivalent) for firmware, software releases, and factory provisioning workflows. • Familiarity with DoD program protection and anti-tamper policy frameworks (DoDI 5200.39) and experience producing or reviewing Program Protection Plans (PPPs). • Strong written and verbal communication skills for policy documentation, risk reporting, and cross-functional leadership.

🏖️ Benefícios

• Medical, dental, and vision coverage fully paid by the employer for employees • Three weeks of vacation to start • Automatic company contribution to 401K – 5% of earned wages (no matching required) • Educational assistance and professional development opportunities

Candidatar-se

Vagas Similares

🕒 Julho 27

Grow Therapy

201 - 500

🏥 Saúde

⚕️ Seguro de Saúde

🏪 Marketplace

Staff Engineer, Security architecting secure infrastructure at Grow Therapy. Leading multi-year roadmap for security initiatives to protect customers and empower engineering organization.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $182.000 - $288.000 / ano

⏰ Tempo Integral

🔴 Especialista

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Julho 27

Legence

10.000+ funcionários

🏗️ Construção

🤝 B2B

⚡ Energia

Lead Cybersecurity Specialist responsible for advancing cybersecurity in Legence’s IT security team. Oversee team initiatives and collaborate cross-functionally for effective risk management in various IT domains.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $125.000 - $165.000 / ano

⏰ Tempo Integral

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Julho 27

NVIDIA

10.000+ funcionários

🏥 Saúde

🏭 Manufatura

🤖 Inteligência Artificial

Leading NVIDIA’s AI safety engineering team and founding engineering group. Building tooling to find, validate, and patch software vulnerabilities.

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Julho 27

Cadence Solutions

11 - 50

💼 Consultoria

🏢 Corporativo

🤝 B2B

Senior Software Engineer developing scalable security infrastructure at Cadence Solutions. Involved in AI governance and risk controls to ensure compliance in the healthcare sector.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $170.000 - $220.000 / ano

⏰ Tempo Integral

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Julho 27

Cogent Security

11 - 50

🔒 Cibersegurança

🤖 Inteligência Artificial

☁️ SaaS

Senior Security Engineer ensuring application security while embedding security in the development lifecycle at a leading AI cybersecurity startup. Collaborating closely with engineering teams on secure software practices.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $100.000 - $300.000 / ano

⏰ Tempo Integral

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório