Member of Technical Staff - Security Engineering
HybridLondon, England, United Kingdom
Job Summary
Shape the security of the control chain across device, board, chassis, and rack controllers by defining threat models and trust boundaries. Design secure boot and root of trust mechanisms, including verified boot, signing, and anti-rollback protection. Secure interconnects between components with authentication and integrity, while building cryptographic mechanisms for key management and remote attestation. Make firmware updates safe end-to-end with signed images and staged rollouts. Harden the host Linux kernel and on-die firmware to protect the running system. Collaborate with hardware and software teams to run threat-model reviews, triage vulnerabilities, and drive fixes to closure. Work across bare metal, RTOS, and Linux to build security into the product from early specifications through first bring-up and silicon validation.
Required Qualifications
- An adversarial mindset and sharp threat-modeling instincts: trust boundaries, assets, attacks, and honesty about residual risk
- Hands-on experience with the core security primitives in software and in silicon: secure boot, root of trust, cryptography, and key management, including how they're implemented and where they can fail
- Secure protocol and channel design between components
- Strong C and Rust, and the instinct for memory safety and defensive coding that low-level security work needs
- Experience building, not just using, security mechanisms: a secure-boot chain, key hierarchy, or attestation flow you shaped
Desired Qualifications
- Attestation at boot and at runtime, and management-plane protocols (DICE, IETF RATS, SPDM, MCTP, PLDM; confidential-computing directions like TDISP)
- Hardware building blocks and firmware/Linux hardening (HSM, TPM, secure element, Caliptra, secure debug; open firmware/boot projects, image minimisation)
- Assurance and resistance (supply-chain security with SBOM and SLSA, fuzzing and testing, standards like NIST 800-series, Common Criteria, OCP incl. S.A.F.E., TCG/DMTF; physical and side-channel awareness)
- AI/LLM-assisted security tooling, and RISC-V / GPU / ML-accelerator experience
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.