Software Security Engineer
$150,000–$200,000 year
On-siteTorrance, California, United States
Job Summary
Design and implement secure boot chains, hardware-backed root of trust mechanisms, and firmware verification processes for embedded flight systems. Develop and integrate cryptographic protocols and libraries for symmetric/asymmetric encryption, key exchange, and digital signatures across embedded and distributed systems. Own software signing infrastructure and verification workflows to ensure the authenticity and integrity of firmware, flight software, and field updates. Design secure key generation, storage, rotation, and provisioning systems across development, manufacturing, and deployed environments. Implement and review authenticated and encrypted communication channels between vehicle, ground systems, and internal subsystems. Conduct threat modeling and security reviews across the software stack to identify vulnerabilities and implement practical mitigations aligned with mission constraints. Partner with embedded, avionics, hardware, and infrastructure teams to embed security principles into system architecture from initial design through deployment.
Required Qualifications
- Bachelors degree in Computer Science, Computer Engineering, Electrical Engineering, or related STEM field
- 3+ years of professional experience in software engineering with exposure to applied cryptography or security engineering
- Experience implementing encryption, authentication, or digital signature systems in C, C++, Rust, or similar systems languages
- Strong understanding of cryptographic fundamentals (PKI, TLS, key exchange, hashing, signatures)
- Experience working in Linux-based or embedded environments
- U.S. citizen or national
- U.S. lawful, permanent resident (aka green card holder)
- Refugee under 8 U.S.C. § 1157
- Asylee under 8 U.S.C. § 1158
- Eligible to obtain the required authorizations from the U.S. Department of State
Desired Qualifications
- Experience implementing secure boot or hardware root-of-trust mechanisms
- Experience with code signing pipelines and artifact verification
- Familiarity with TPMs, HSMs, or secure elements
- Experience in embedded, aerospace, defense, or other safety-critical systems
- Experience designing secure provisioning workflows in manufacturing environments
- Understanding of real-time systems and resource-constrained devices
- Experience with mTLS, certificate lifecycle management, and replay protection mechanisms
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.