Platform Security Engineer, DRTM / Secure Launch
Owns DRTM adoption, attestation, and platform hardening across x86 and ARM infrastructure, working across firmware, bootloaders, kernels, hardware, and silicon security. The role requires deep systems-security experience, upstream Linux or firmware contributions, and strong vendor and OEM leadership.
About the job
Responsibilities
DRTM adoption and integration
- Own adoption and integration of Dynamic Root of Trust for Measurement (DRTM) hardware security features across infrastructure on x86 and ARM platforms.
- Implement attestation services and related security and privacy capabilities enabled by DRTM.
- Design and implement a bootloader-agnostic solution for initiating and relaunching DRTM sessions.
- Harden existing DRTM solutions, including PPAM isolation of SMM on x86, VMM isolation of UEFI runtime services, and ACPI handling in DRTM environments.
Vendors and upstream
- Interface with vendor and OEM partners on DRTM solutions, jointly refining requirements and assessing feasible changes.
- Publish DRTM work upstream and help maintain Linux Secure Launch as tboot is retired.
- Lead architecture and design efforts and communicate results through technical papers, conference talks, and community engagement.
- Assist other teams with open-source efforts and upstream interactions.
Broader low-level platform security
- Build and harden platform security features, including confidential computing solutions such as TDX and SEV.
- Support custom operating system artifacts, implement device drivers, and perform firmware diagnosis and enhancement.
- Debug kernel and system-level issues on production hardware.
- Investigate new and unresolved technical areas, including security problems in dTPMs and fTPMs.
Requirements
- 8+ years of systems security experience, including at least 5 years focused on firmware, bootloader, and OS-level security.
- Hands-on experience with measured boot and roots of trust, including DRTM, Intel TXT, AMD SKINIT, ARM equivalents, SRTM, TPM 1.2/2.0, and measurement chains.
- Strong C and assembly skills with deep Linux kernel and early-boot fundamentals, including bootloaders, UEFI, ACPI, and SMM.
- Record of landing substantial work upstream in Linux, TianoCore, GRUB, or a comparable community.
- Experience at the hardware/firmware boundary, including JTAG, serial debugging, platform bring-up, and silicon errata.
- Strong technical cross-functional leadership and direction setting with vendors and OEMs.
- Clear written communication skills for specifications, design documents, and public technical writing.
- Working knowledge of NIST firmware security guidance, particularly SP 800-193 and SP 800-147/155.
- Bachelor’s degree or equivalent combination of education, training, and experience in a relevant field.
Nice-to-haves
- Linux maintainership or subsystem ownership, or standing in the TCG, UEFI Forum, or OCP communities.
- Confidential computing experience with TDX, SEV-SNP, ARM CCA, and attestation flows.
- Experience with hardware roots of trust and attestation beyond TPM, including Caliptra, OCP S.A.F.E., and SPDM.
- Memory-safe systems programming in Rust.
- Firmware vulnerability research, reverse engineering, or fuzzing.
- AI/ML infrastructure security experience.
Compensation and benefits
- Annual salary: $320,000–$405,000 USD.
- Competitive compensation and benefits, optional equity donation matching, generous vacation and parental leave, flexible working hours, and office collaboration space.
Skills
Drtm, Intel Txt, Amd Skinit, Srtm, Tpm, C, Assembly, Linux Kernel, Uefi, Acpi, Smm, Jtag, Tdx, Sev-Snp, Rust
Similar jobs
Security Engineering jobsLeads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.
Leads cyber-focused AI misuse enforcement, managing analysts and contractors while developing detection and mitigation strategies for attacks, malware, and exploitation. Requires people management, cybersecurity expertise, high-volume abuse enforcement, data analysis with SQL or Python, and cross-functional risk communication.
Defines the security architecture for a next-generation operating system, spanning trust boundaries, hardware-backed protections, isolation, secure updates, and AI-agent guardrails. The role requires deep privileged-systems expertise, systems programming ability, and experience securing platforms across hardware, firmware, and software.
Leads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.
Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.