Product Security Engineer

🔥 3 hours ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of OKSI

OKSI

51 - 200 employees

Founded 1991

🎖️ Defense

🚀 Aerospace

🤖 Artificial Intelligence

💰 $206.5k Grant - Opto-Knowledge Systems on 2024-01

Defense • Aerospace • Artificial Intelligence

OKSI is a defense- and aerospace-focused sensor and autonomy company that develops electro-optical/infrared (EO/IR) seekers, precision guidance systems, GPS-denied navigation (e. g. , OMNInav), and machine-learning-enhanced hardware and software. For 35+ years the company has produced advanced computer-vision and AI/ML solutions, modeling & simulation tools, and unique sensor packages for high-speed events, hypersonics, combustion diagnostics, space and earth observation, and environmental sensing. OKSI primarily serves government and defense customers, holding 450+ government contracts and delivering capabilities for autonomy, precision guidance, and environmental monitoring.

📋 Description

• Lead threat modeling and security analysis across hardware, firmware, and software throughout the product lifecycle. • Produce threat matrices, risk assessments, and security requirements traceable through design reviews and release gates. • Own CVE tracking, vulnerability management, and security baseline compliance across the product portfolio. • Define and implement hardening standards for embedded Linux, RTOS, and bare-metal environments. • Establish code signing policies, secure boot chain integrity, and validation procedures. • Partner with IT and Engineering to architect and maintain the product signing and key management infrastructure using HSMs, KMS, or equivalent systems. • Own OKSI's anti-tamper posture aligned with DoD policy (DoDI 5200.39) and applicable Program Protection Plan requirements. • Define IP protection strategy spanning software binary protection, hardware design protection, firmware confidentiality, and cryptographically bound license enforcement. • Serve as OKSI's product security authority. • Establish company-wide standards, lead design reviews, provide security sign-off at program milestones, and embed security requirements into the Systems Engineering process. • Provide guidance and training to Engineering, IT, and Operations teams on secure design principles.

🎯 Requirements

• 7+ years of product security, embedded security, or cybersecurity systems engineering in a defense, aerospace, or advanced technology environment. • Demonstrated expertise leading threat modeling, security risk assessments, and vulnerability analysis across hardware, firmware, and software domains — including production of threat matrices, attack surface analyses, and traceable mitigation plans. • Hands-on experience defining and implementing security policies and standards (not just executing implementation tasks). You own the policy and architecture. • Working knowledge of secure boot architectures, anti-tamper techniques, and embedded platform security (e.g., UEFI Secure Boot, ARM TrustZone, fuse-based root-of-trust). • Practical experience with embedded Linux hardening: kernel configuration, module signing, RBAC/least-privilege access models, debug interface lockdown, and production credential management. • Experience with key management infrastructure and signing pipelines (HSMs, KMS, or equivalent) for firmware, software releases, and factory provisioning workflows. • Familiarity with DoD program protection and anti-tamper policy frameworks (DoDI 5200.39) and experience producing or reviewing Program Protection Plans (PPPs). • Strong written and verbal communication skills for policy documentation, risk reporting, and cross-functional leadership.

🏖️ Benefits

• Medical, dental, and vision coverage fully paid by the employer for employees • Three weeks of vacation to start • Automatic company contribution to 401K – 5% of earned wages (no matching required) • Educational assistance and professional development opportunities

Apply Now

Similar Jobs

🔥 3 hours ago

Dayforce

5001 - 10000

👥 HR Tech

☁️ SaaS

🏢 Enterprise

Senior Information Security Administrator responsible for security operations and compliance at the Credit Union. Collaborating with IT and business units to maintain security posture and incident response.

🇺🇸 United States – Remote

💵 $90.8k - $156.9k / year

💰 $1G Post-IPO Debt - Dayforce on 2024-03

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🔥 3 hours ago

Humana

10,000+ employees

🏥 Healthcare

🛡️ Insurance

⚕️ Healthcare Insurance

Lead of Red Team at Humana responsible for managing red team operations and adversary emulation campaigns. Directing the development of AI-enhanced security practices and establishing red team methodologies.

🔥 4 hours ago

Grow Therapy

201 - 500

🏥 Healthcare

⚕️ Healthcare Insurance

🏪 Marketplace

Staff Engineer, Security architecting secure infrastructure at Grow Therapy. Leading multi-year roadmap for security initiatives to protect customers and empower engineering organization.

🔥 4 hours ago

Valiant Solutions

201 - 500

💼 Consulting

🎖️ Defense

🔒 Cybersecurity

Security Architect leading the development of security architecture guidance for on-premise and cloud platforms at Valiant Solutions. Supporting cybersecurity design for a large government agency.

🔥 5 hours ago

Airtable

501 - 1000

🔌 API

🤝 B2B

⚡ Productivity

Product Security Engineer at Airtable developing security frameworks for AI-powered offerings. Collaborating with teams to ensure secure code practices and manage security risk mitigation.