Jobiglo

No results.

Staff Firmware Engineer, Platform Security

ridealso · Palo Alto

Senior 🇬🇧 English
Secure boot Secure element CAN/CAN-FD Threat modeling

Job description

About the role

ALSO is building a new generation of small electric vehicles and needs a senior technical leader to define and own the security architecture for all vehicle firmware. As a Staff Firmware Security Architect you will set the direction for secure boot, key lifecycle, network integrity and OTA trust across every ECU in the product line.

Key responsibilities

  • Define and implement secure boot and root‑of‑trust across multiple MCU families, including image signing, verification, anti‑rollback and production debug lockdown.
  • Own on‑device and fleet key strategy (HSM, OTP, secure element), key hierarchy design and integration with signing and PKI services.
  • Lead CAN/CAN‑FD security design, establishing authentication, integrity and optional encryption, and define protected diagnostics and secure UDS access.
  • Architect end‑to‑end OTA security, covering signed/encrypted payloads, on‑device verification, rollback safety and secure handoff between cloud signing infrastructure and vehicle update flows.
  • Build reusable security libraries and APIs (crypto wrappers, secure storage, auth services) for adoption by all ECU teams.
  • Conduct threat modeling and hardening for boot, update and network attack surfaces, and drive security test strategy across benchtop, HIL and CI environments.
  • Mentor engineers, align cross‑functional stakeholders and ensure security requirements are met in production.

Required profile

  • 8+ years of embedded software/firmware development experience.
  • Deep expertise in secure boot, cryptography or vehicle/IoT security architecture.
  • Proven track record setting technical direction across multiple ECUs or products.
  • Strong leadership and cross‑functional collaboration skills.

Required skills

  • Embedded C/C++ development
  • Secure boot and root‑of‑trust design
  • Cryptography and key management (HSM, OTP, secure element, PKI)
  • CAN/CAN‑FD security (authentication, integrity, encryption)
  • OTA firmware update security
  • Threat modeling and security hardening
  • CI/CD integration for security testing
  • Hardware debugging (JTAG lockdown)

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec ridealso.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.
Source : ats:ashby

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

Apply now →

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 1 month ago

Expires 2 weeks from now

19 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

ridealso

Palo Alto