Security Engineer, Hardware/Device
The Security Engineer will establish hardware and embedded security practices for connected devices, covering secure boot, firmware, manufacturing, architecture reviews, threat modeling, and lifecycle controls. The role requires at least five years of hardware security, product security design, and hands-on Python and C/C++ development experience.
About the job
Responsibilities
- Build the hardware and embedded security baseline and processes across Motive devices, including the boot chain, firmware, FOTA, and manufacturing.
- Partner with the hardware engineering team to ensure findings are prioritized, validated, and remediated.
- Identify and assess hardware security risks across the product lifecycle, including design, manufacturing, deployment, updating, and decommissioning.
- Lead hardware security architecture reviews, threat modeling, and security testing for product systems.
- Define and review security requirements for hardware platforms, embedded systems, firmware interfaces, boot processes, debug capabilities, and device lifecycle controls in cloud-connected environments.
- Drive end-to-end security for device hardware across IoT and cloud security infrastructure.
Requirements
- 5+ years of experience in hardware security, including creating security-by-design patterns for new devices and platforms.
- 5+ years of experience working with product teams to create security designs and provide security requirements.
- 5+ years of hands-on development experience with Python and C/C++.
- Strong understanding of hardware root of trust, secure boot, attestation, key protection, device identity, and secure provisioning concepts.
- Hands-on experience designing, reviewing, and validating security controls for hardware and low-level system architectures.
- Experience with cloud security, runtime security, supply chain security, and application security best practices.
Compensation and Benefits
- Compensation range: CAD 146,000–195,000.
- Compensation may depend on education, work experience, and certifications.
- Certain roles may include restricted stock units.
- Benefits include health, pharmacy, optical and dental care, paid time off, sick time off, short- and long-term disability coverage, life insurance, and 401k contributions, subject to eligibility requirements.
Skills
Python, C, C++, Embedded Systems, Secure Boot, Hardware Root Of Trust, Attestation, Device Identity, Threat Modeling, Cloud Security, Runtime Security, Supply Chain Security, Application Security, Fota
Similar jobs
Security Engineering jobsConduct cloud-focused red team operations, adversary simulations, and offensive security assessments while validating detection coverage and driving remediation. Requires at least five years of offensive security experience and familiarity with attacker techniques, cloud environments, and MITRE ATT&CK.
Develop AI-augmented offensive security tooling, red-team internal AI systems, and automate vulnerability workflows. The role requires at least three years of application or offensive security experience, programming ability, and hands-on experience with LLM security.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.
This role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.