Product Security Engineer

🕒 il y a 8 jours

🗣️🇺🇸🇬🇧 Anglais requis

Cyber Security

Linux

RTOS

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of OKSI

OKSI

51 - 200 employés

Fondée en 1991

🎖️ Défense

🚀 Aérospatiale

🤖 Intelligence artificielle

💰 €206 500 Grant - Opto-Knowledge Systems en 2024-01

Defense • Aerospace • Artificial Intelligence

OKSI est une entreprise spécialisée dans les capteurs axés sur la défense et l'aérospatiale, développant des capteurs électro-optiques/infrarouges (EO/IR), des systèmes de guidage de précision, la navigation sans GPS (par exemple, OMNInav) et du matériel et logiciel améliorés par apprentissage automatique. Depuis plus de 35 ans, la société produit des solutions avancées de vision par ordinateur et d'IA/ML, des outils de modélisation et de simulation, et des ensembles de capteurs uniques pour les événements à grande vitesse, l'hypersonique, le diagnostic de combustion, l'observation spatiale et terrestre, et la détection environnementale. OKSI sert principalement les clients gouvernementaux et de défense, détenant plus de 450 contrats gouvernementaux et fournissant des capacités pour l'autonomie, le guidage de précision et la surveillance environnementale.

Description

• Lead threat modeling and security analysis across hardware, firmware, and software throughout the product lifecycle. • Produce threat matrices, risk assessments, and security requirements traceable through design reviews and release gates. • Own CVE tracking, vulnerability management, and security baseline compliance across the product portfolio. • Define and implement hardening standards for embedded Linux, RTOS, and bare-metal environments. • Establish code signing policies, secure boot chain integrity, and validation procedures. • Partner with IT and Engineering to architect and maintain the product signing and key management infrastructure using HSMs, KMS, or equivalent systems. • Own OKSI's anti-tamper posture aligned with DoD policy (DoDI 5200.39) and applicable Program Protection Plan requirements. • Define IP protection strategy spanning software binary protection, hardware design protection, firmware confidentiality, and cryptographically bound license enforcement. • Serve as OKSI's product security authority. • Establish company-wide standards, lead design reviews, provide security sign-off at program milestones, and embed security requirements into the Systems Engineering process. • Provide guidance and training to Engineering, IT, and Operations teams on secure design principles.

🎯 Exigences

• 7+ years of product security, embedded security, or cybersecurity systems engineering in a defense, aerospace, or advanced technology environment. • Demonstrated expertise leading threat modeling, security risk assessments, and vulnerability analysis across hardware, firmware, and software domains — including production of threat matrices, attack surface analyses, and traceable mitigation plans. • Hands-on experience defining and implementing security policies and standards (not just executing implementation tasks). You own the policy and architecture. • Working knowledge of secure boot architectures, anti-tamper techniques, and embedded platform security (e.g., UEFI Secure Boot, ARM TrustZone, fuse-based root-of-trust). • Practical experience with embedded Linux hardening: kernel configuration, module signing, RBAC/least-privilege access models, debug interface lockdown, and production credential management. • Experience with key management infrastructure and signing pipelines (HSMs, KMS, or equivalent) for firmware, software releases, and factory provisioning workflows. • Familiarity with DoD program protection and anti-tamper policy frameworks (DoDI 5200.39) and experience producing or reviewing Program Protection Plans (PPPs). • Strong written and verbal communication skills for policy documentation, risk reporting, and cross-functional leadership.

🏖️ Avantages

• Medical, dental, and vision coverage fully paid by the employer for employees • Three weeks of vacation to start • Automatic company contribution to 401K – 5% of earned wages (no matching required) • Educational assistance and professional development opportunities

Postuler Maintenant

Emplois Similaires

🕒 il y a 8 jours

Humana

10 000+ employés

🏥 Santé

🛡️ Assurance

⚕️ Assurance santé

Lead of Red Team at Humana responsible for managing red team operations and adversary emulation campaigns. Directing the development of AI-enhanced security practices and establishing red team methodologies.

🗣️🇺🇸🇬🇧 Anglais requis

Python

Ruby

🕒 il y a 8 jours

Grow Therapy

201 - 500

🏥 Santé

⚕️ Assurance santé

🏪 Place de marché

Staff Engineer, Security architecting secure infrastructure at Grow Therapy. Leading multi-year roadmap for security initiatives to protect customers and empower engineering organization.

🇺🇸 États-Unis – Télétravail

💵 $182 000 - $288 000 / an

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 8 jours

Valiant Solutions

201 - 500

💼 Conseil

🎖️ Défense

🔒 Cybersecurity

Security Architect leading the development of security architecture guidance for on-premise and cloud platforms at Valiant Solutions. Supporting cybersecurity design for a large government agency.

🇺🇸 États-Unis – Télétravail

💵 $150 000 - $160 000 / an

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 8 jours

Airtable

501 - 1000

🔌 API

🤝 B2B

⚡ Productivité

Product Security Engineer at Airtable developing security frameworks for AI-powered offerings. Collaborating with teams to ensure secure code practices and manage security risk mitigation.

🇺🇸 États-Unis – Télétravail

💵 $187 000 - $260 000 / an

💰 Secondary Market en 2022-06

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 8 jours

Lexitas

501 - 1000

⚖️ Juridique

☁️ SaaS

🤝 B2B

Vice President of Information Security building, scaling, and modernizing security programs at Lexitas. Collaborating with teams to leverage AI and improve security operations.

🇺🇸 États-Unis – Télétravail

💵 $200 000 - $230 000 / an

💰 Debt financing en 2016-10

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis