Product Security Engineer

🕒 July 27

🐻 Alaska, California – Remote

infoinfo

💵 $154k - $210k / year

⏰ Full Time

🟠 Senior

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 14%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of OKSI

OKSI

51 - 200 employees

Founded 1991

🎖️ Defense

🚀 Aerospace

🤖 Artificial Intelligence

💰 $206.5k Grant - Opto-Knowledge Systems on 2024-01

Defense • Aerospace • Artificial Intelligence

OKSI is a defense- and aerospace-focused sensor and autonomy company that develops electro-optical/infrared (EO/IR) seekers, precision guidance systems, GPS-denied navigation (e. g. , OMNInav), and machine-learning-enhanced hardware and software. For 35+ years the company has produced advanced computer-vision and AI/ML solutions, modeling & simulation tools, and unique sensor packages for high-speed events, hypersonics, combustion diagnostics, space and earth observation, and environmental sensing. OKSI primarily serves government and defense customers, holding 450+ government contracts and delivering capabilities for autonomy, precision guidance, and environmental monitoring.

📋 Description

• Lead threat modeling and security analysis across hardware, firmware, and software throughout the product lifecycle. • Produce threat matrices, risk assessments, and security requirements traceable through design reviews and release gates. • Own CVE tracking, vulnerability management, and security baseline compliance across the product portfolio. • Define and implement hardening standards for embedded Linux, RTOS, and bare-metal environments. • Establish code signing policies, secure boot chain integrity, and validation procedures. • Partner with IT and Engineering to architect and maintain the product signing and key management infrastructure using HSMs, KMS, or equivalent systems. • Own OKSI's anti-tamper posture aligned with DoD policy (DoDI 5200.39) and applicable Program Protection Plan requirements. • Define IP protection strategy spanning software binary protection, hardware design protection, firmware confidentiality, and cryptographically bound license enforcement. • Serve as OKSI's product security authority. • Establish company-wide standards, lead design reviews, provide security sign-off at program milestones, and embed security requirements into the Systems Engineering process. • Provide guidance and training to Engineering, IT, and Operations teams on secure design principles.

🎯 Requirements

• 7+ years of product security, embedded security, or cybersecurity systems engineering in a defense, aerospace, or advanced technology environment. • Demonstrated expertise leading threat modeling, security risk assessments, and vulnerability analysis across hardware, firmware, and software domains — including production of threat matrices, attack surface analyses, and traceable mitigation plans. • Hands-on experience defining and implementing security policies and standards (not just executing implementation tasks). You own the policy and architecture. • Working knowledge of secure boot architectures, anti-tamper techniques, and embedded platform security (e.g., UEFI Secure Boot, ARM TrustZone, fuse-based root-of-trust). • Practical experience with embedded Linux hardening: kernel configuration, module signing, RBAC/least-privilege access models, debug interface lockdown, and production credential management. • Experience with key management infrastructure and signing pipelines (HSMs, KMS, or equivalent) for firmware, software releases, and factory provisioning workflows. • Familiarity with DoD program protection and anti-tamper policy frameworks (DoDI 5200.39) and experience producing or reviewing Program Protection Plans (PPPs). • Strong written and verbal communication skills for policy documentation, risk reporting, and cross-functional leadership.

🏖️ Benefits

• Medical, dental, and vision coverage fully paid by the employer for employees • Three weeks of vacation to start • Automatic company contribution to 401K – 5% of earned wages (no matching required) • Educational assistance and professional development opportunities

Apply Now

Similar Jobs

🕒 July 27

Grow Therapy

201 - 500

🏥 Healthcare

⚕️ Healthcare Insurance

🏪 Marketplace

Staff Engineer, Security architecting secure infrastructure at Grow Therapy. Leading multi-year roadmap for security initiatives to protect customers and empower engineering organization.

🕒 July 27

Legence

10,000+ employees

🏗️ Construction

🤝 B2B

⚡ Energy

Lead Cybersecurity Specialist responsible for advancing cybersecurity in Legence’s IT security team. Oversee team initiatives and collaborate cross-functionally for effective risk management in various IT domains.

🕒 July 27

Cadence Solutions

11 - 50

💼 Consulting

🏢 Enterprise

🤝 B2B

Senior Software Engineer developing scalable security infrastructure at Cadence Solutions. Involved in AI governance and risk controls to ensure compliance in the healthcare sector.

🕒 July 27

Cogent Security

11 - 50

🔒 Cybersecurity

🤖 Artificial Intelligence

☁️ SaaS

Senior Security Engineer ensuring application security while embedding security in the development lifecycle at a leading AI cybersecurity startup. Collaborating closely with engineering teams on secure software practices.

🕒 July 27

Cogent Security

11 - 50

🔒 Cybersecurity

🤖 Artificial Intelligence

☁️ SaaS

Senior Security Engineer focused on securing corporate systems and endpoints at Cogent Security. Building automation and tooling in a dynamic environment to manage IT security programs.