Staff Firmware Engineer, Platform Security
ridealso · Palo Alto
Job description
About the role
ALSO is building a new generation of small electric vehicles and needs a senior technical leader to define and own the security architecture for all vehicle firmware. As a Staff Firmware Security Architect you will set the direction for secure boot, key lifecycle, network integrity and OTA trust across every ECU in the product line.
Key responsibilities
- Define and implement secure boot and root‑of‑trust across multiple MCU families, including image signing, verification, anti‑rollback and production debug lockdown.
- Own on‑device and fleet key strategy (HSM, OTP, secure element), key hierarchy design and integration with signing and PKI services.
- Lead CAN/CAN‑FD security design, establishing authentication, integrity and optional encryption, and define protected diagnostics and secure UDS access.
- Architect end‑to‑end OTA security, covering signed/encrypted payloads, on‑device verification, rollback safety and secure handoff between cloud signing infrastructure and vehicle update flows.
- Build reusable security libraries and APIs (crypto wrappers, secure storage, auth services) for adoption by all ECU teams.
- Conduct threat modeling and hardening for boot, update and network attack surfaces, and drive security test strategy across benchtop, HIL and CI environments.
- Mentor engineers, align cross‑functional stakeholders and ensure security requirements are met in production.
Required profile
- 8+ years of embedded software/firmware development experience.
- Deep expertise in secure boot, cryptography or vehicle/IoT security architecture.
- Proven track record setting technical direction across multiple ECUs or products.
- Strong leadership and cross‑functional collaboration skills.
Required skills
- Embedded C/C++ development
- Secure boot and root‑of‑trust design
- Cryptography and key management (HSM, OTP, secure element, PKI)
- CAN/CAN‑FD security (authentication, integrity, encryption)
- OTA firmware update security
- Threat modeling and security hardening
- CI/CD integration for security testing
- Hardware debugging (JTAG lockdown)
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the United States.
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 1 month ago
Expires 2 weeks from now
19 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
ridealso
Palo Alto