Software Engineer, Host Assurance
Build and operate Host Assurance services and host software that establish trust in bare-metal and virtual machine infrastructure through secure bootstrap, identity, attestation, and verification. The role requires production software engineering experience across reliable systems, platform or infrastructure security, and host-system boundaries.
About the job
Responsibilities
- Design, build, and operate Host Assurance platform components that establish trust in bare-metal and virtual machine hosts before production use.
- Ensure hosts remain verifiably trustworthy from delivery and installation through secure bootstrap and orchestration readiness.
- Build and improve machine identity, certificate issuance and enrollment, HSM- or key-management-backed trust services, host attestation, measurement, and baseline verification tooling.
- Validate delivered hardware and firmware against vendor claims and detect and manage drift over time.
- Eliminate insecure bootstrap patterns while preserving deployment throughput and operational reliability.
- Partner with provisioning, fleet, orchestration, infrastructure, research, and confidential-computing teams.
- Own software through implementation, testing, operational readiness, launch, staged rollout, monitoring, recovery procedures, runbooks, and ongoing operation.
- Define readiness criteria, validate behavior under load and failure, establish actionable alerts, and improve reliability.
- Participate in a production on-call rotation.
- Define observable and testable security properties for host platforms and improve telemetry and validation.
Requirements
- Strong software engineering experience building and operating reliable production systems at scale.
- Depth in distributed systems, backend or platform engineering, operating systems, or infrastructure security.
- Ability to reason across services, APIs, host software, boot processes, firmware, and hardware trust mechanisms.
- Production-quality coding skills and clear reasoning about failure modes, operational safety, and maintainability.
- Experience supporting critical production systems at scale, including on-call support.
- Practical judgment balancing rigorous security controls with deployability and operational reliability.
- Self-directed, collaborative, low-ego approach to ambiguous, cross-disciplinary problems.
Nice-to-haves
- Experience with PKI, HSMs, machine identity, host attestation, secure boot, or hardware security.
- Experience validating hardware and firmware or working with confidential computing.
Compensation
- Annual salary range: $266,000–$445,000.
Skills
Distributed Systems, Backend Engineering, Platform Engineering, Operating Systems, Infrastructure Security, Pki, Hsms, Machine Identity, Host Attestation, Secure Boot, Hardware Security, Firmware Validation, Observability, On-Call
Similar jobs
Backend Engineering jobsBuild backend infrastructure and customer-facing workflows that enable developers and AI agents to operate reliably in secure cloud environments. The role requires strong Go and production backend experience, distributed-systems expertise, and practical knowledge of cloud infrastructure, networking, and security.
Build and own Baseten’s identity and authorization platform, including fine-grained permissions, credential systems, and enterprise administration. The role requires backend systems experience, production authorization expertise, and the ability to operate secure multi-tenant systems at scale.
Build backend systems, data infrastructure, agentic workflows, and enterprise integrations that make AI useful and trustworthy for financial institutions. The role requires 5+ years of software engineering experience, backend-language proficiency, and experience with production data-intensive or distributed systems.
Build and operate scalable backend services, APIs, and real-time data systems while contributing to architecture, reliability, and product-driven solutions. Requires a relevant master’s degree with 3 years of experience or a bachelor’s degree with 5 years, plus broad distributed systems and programming expertise.
Build and operate secure, scalable sandboxing infrastructure for untrusted, model-generated code and tool calls. The role requires backend programming, virtualization or isolation experience, and strong knowledge of Linux security primitives.