Product Security Engineer

🕒 il y a 1 mois

🐻 Alaska, California – Distant

infoinfo

💵 $154 000 - $210 000 / an

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

👻 Score fantôme 21%

infoinfo

🗣️🇺🇸🇬🇧 Anglais requis

Cyber Security

Linux

RTOS

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of OKSI

OKSI

51 - 200 employés

Fondée en 1991

🎖️ Défense

🚀 Aérospatiale

🤖 Intelligence artificielle

💰 €206 500 Grant - Opto-Knowledge Systems en 2024-01

Defense • Aerospace • Artificial Intelligence

OKSI est une entreprise spécialisée dans les capteurs axés sur la défense et l'aérospatiale, développant des capteurs électro-optiques/infrarouges (EO/IR), des systèmes de guidage de précision, la navigation sans GPS (par exemple, OMNInav) et du matériel et logiciel améliorés par apprentissage automatique. Depuis plus de 35 ans, la société produit des solutions avancées de vision par ordinateur et d'IA/ML, des outils de modélisation et de simulation, et des ensembles de capteurs uniques pour les événements à grande vitesse, l'hypersonique, le diagnostic de combustion, l'observation spatiale et terrestre, et la détection environnementale. OKSI sert principalement les clients gouvernementaux et de défense, détenant plus de 450 contrats gouvernementaux et fournissant des capacités pour l'autonomie, le guidage de précision et la surveillance environnementale.

Description

• Lead threat modeling and security analysis across hardware, firmware, and software throughout the product lifecycle. • Produce threat matrices, risk assessments, and security requirements traceable through design reviews and release gates. • Own CVE tracking, vulnerability management, and security baseline compliance across the product portfolio. • Define and implement hardening standards for embedded Linux, RTOS, and bare-metal environments. • Establish code signing policies, secure boot chain integrity, and validation procedures. • Partner with IT and Engineering to architect and maintain the product signing and key management infrastructure using HSMs, KMS, or equivalent systems. • Own OKSI's anti-tamper posture aligned with DoD policy (DoDI 5200.39) and applicable Program Protection Plan requirements. • Define IP protection strategy spanning software binary protection, hardware design protection, firmware confidentiality, and cryptographically bound license enforcement. • Serve as OKSI's product security authority. • Establish company-wide standards, lead design reviews, provide security sign-off at program milestones, and embed security requirements into the Systems Engineering process. • Provide guidance and training to Engineering, IT, and Operations teams on secure design principles.

🎯 Exigences

• 7+ years of product security, embedded security, or cybersecurity systems engineering in a defense, aerospace, or advanced technology environment. • Demonstrated expertise leading threat modeling, security risk assessments, and vulnerability analysis across hardware, firmware, and software domains — including production of threat matrices, attack surface analyses, and traceable mitigation plans. • Hands-on experience defining and implementing security policies and standards (not just executing implementation tasks). You own the policy and architecture. • Working knowledge of secure boot architectures, anti-tamper techniques, and embedded platform security (e.g., UEFI Secure Boot, ARM TrustZone, fuse-based root-of-trust). • Practical experience with embedded Linux hardening: kernel configuration, module signing, RBAC/least-privilege access models, debug interface lockdown, and production credential management. • Experience with key management infrastructure and signing pipelines (HSMs, KMS, or equivalent) for firmware, software releases, and factory provisioning workflows. • Familiarity with DoD program protection and anti-tamper policy frameworks (DoDI 5200.39) and experience producing or reviewing Program Protection Plans (PPPs). • Strong written and verbal communication skills for policy documentation, risk reporting, and cross-functional leadership.

🏖️ Avantages

• Medical, dental, and vision coverage fully paid by the employer for employees • Three weeks of vacation to start • Automatic company contribution to 401K – 5% of earned wages (no matching required) • Educational assistance and professional development opportunities

Postuler Maintenant

Emplois Similaires

🕒 il y a 1 mois

Grow Therapy

201 - 500

🏥 Santé

⚕️ Assurance santé

🏪 Place de marché

Staff Engineer, Security architecting secure infrastructure at Grow Therapy. Leading multi-year roadmap for security initiatives to protect customers and empower engineering organization.

🇺🇸 États-Unis – Télétravail

💵 $182 000 - $288 000 / an

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Legence

10 000+ employés

🏗️ Construction

🤝 B2B

⚡ Énergie

Lead Cybersecurity Specialist responsible for advancing cybersecurity in Legence’s IT security team. Oversee team initiatives and collaborate cross-functionally for effective risk management in various IT domains.

🇺🇸 États-Unis – Télétravail

💵 $125 000 - $165 000 / an

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Cloud

Cyber Security

Firewalls

Python

🕒 il y a 1 mois

Cadence Solutions

11 - 50

💼 Conseil

🏢 Entreprise

🤝 B2B

Senior Software Engineer developing scalable security infrastructure at Cadence Solutions. Involved in AI governance and risk controls to ensure compliance in the healthcare sector.

🇺🇸 États-Unis – Télétravail

💵 $170 000 - $220 000 / an

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Cogent Security

11 - 50

🔒 Cybersecurity

🤖 Intelligence artificielle

☁️ SaaS

Senior Security Engineer ensuring application security while embedding security in the development lifecycle at a leading AI cybersecurity startup. Collaborating closely with engineering teams on secure software practices.

🇺🇸 États-Unis – Télétravail

💵 $100 000 - $300 000 / an

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Dropzone AI

51 - 200

🤖 Intelligence artificielle

Senior Security Engineer ensuring AI SOC Analyst generates accurate, timely reports for cybersecurity transformation at Dropzone AI. Collaborating across teams for continuous investigation quality improvement

🇺🇸 États-Unis – Télétravail

💵 $175 000 - $217 000 / an

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis