Skip to content
OpenAIOpenAI

Software Engineer, HSM Infrastructure Security, Consumer Devices

Design and ship security-critical software and firmware at the boundary between policy systems and hardware-backed cryptographic protection. The role requires 5+ years of secure embedded development and deep C, C++, or Rust experience.

About the job

Responsibilities

  • Design and implement security-critical software and firmware for HSMs, secure elements, trusted execution environments, and hardware roots of trust.
  • Harden policy-to-HSM boundaries for certificate issuance and cryptographic signing.
  • Develop HSM trusted applications, firmware components, host interfaces, device drivers, SDKs, and cryptographic service integrations.
  • Implement cryptographic interfaces such as PKCS#11, OpenSSL providers or engines, and platform key-storage APIs.
  • Build systems enforcing policies for key generation, provisioning, usage, rotation, recovery, and destruction.
  • Design HSM-backed certificate authority, code-signing, key-management, and device-identity systems.
  • Develop protocols spanning devices, secure hardware, policy services, and backend infrastructure.
  • Support device attestation, secure boot, factory provisioning and restoration, registration, and authentication.
  • Build verifiable, auditable controls for trusted software and policy changes.
  • Write, review, test, and audit secure embedded software; develop test harnesses, emulators, fuzzers, and fault-injection tooling.
  • Threat-model hardware and software trust boundaries and translate findings into engineering improvements.
  • Collaborate across hardware, firmware, infrastructure, application, security, and product teams.
  • Establish engineering standards for HSM development, applied cryptography, secure key management, and certificate infrastructure.

Requirements

  • 5+ years of experience building secure embedded firmware for constrained environments.
  • Deep programming experience in C, C++, or Rust.
  • Experience designing, implementing, debugging, and shipping production systems software.
  • Hands-on experience with security-critical software or firmware in or adjacent to an HSM, secure element, TEE, or hardware root of trust.
  • Strong knowledge of applied cryptography, digital signatures, key hierarchies, secure key management, and cryptographic protocol design.
  • Experience with PKI, X.509 certificates, certificate authorities, certificate issuance, and certificate lifecycle protocols.
  • Familiarity with secure boot, measured boot, device identity, remote attestation, or hardware-backed storage.
  • Understanding of concurrency, memory safety, privilege separation, hardware interfaces, failure modes, and side-channel or physical attack considerations.
  • Ability to evaluate security designs and implement the software needed to realize them.

Nice-to-Haves

  • ARM TrustZone or another trusted execution environment.
  • Commercial or cloud HSM platforms such as Thales Luna, Entrust/nShield, Utimaco, Marvell LiquidSecurity, AWS CloudHSM, or comparable systems.
  • PKCS#11, KMIP, OpenSSL providers or engines, secure-element APIs, or platform-native key-storage frameworks.
  • Device manufacturing, secure provisioning, factory restore, or silicon bring-up.
  • Secure boot ROM, bootloader, firmware signing, anti-rollback, or authenticated updates.
  • Trusted applications or cryptographic services inside an HSM or secure coprocessor.
  • Hardware/software co-design involving cryptographic accelerators, secure processors, or custom silicon.
  • Multi-party authorization, quorum-controlled deployments, tamper-resistant audit mechanisms, or attestable policy systems.
  • Hardware-protected-key storage systems.
  • Sustaining high-assurance security software in production.

Skills

C, C++, Rust, Hsm, Embedded Firmware, Applied Cryptography, Pkcs#11, Openssl, Pki, X.509, Secure Boot, Remote Attestation, Arm Trustzone, Aws Cloudhsm, Fuzzing

Anthropic

Anthropic

New York, NY
Security Engineer - Threat Intel
$320k+/yrHybrid5+ YOESecurity Engineering

This hands-on security engineer will research sophisticated threat actors, build intelligence pipelines, conduct threat hunts, analyze malware and infrastructure, and translate findings into durable detections. The role requires at least five years of cyber threat intelligence or related experience, strong Python engineering, and malware and detection-analysis expertise.

Anthropic

Anthropic

San Francisco, CA
Security Engineer, Corporate Security
$320k+/yrHybrid5+ YOESecurity Engineering

Senior hands-on security engineer responsible for endpoint hardening, device trust, identity and SaaS governance, and scalable corporate-security automation across a growing organization. Requires endpoint security expertise, Python scripting, IAM and zero-trust depth, and strong threat-modeling judgment.

Anthropic

Anthropic

San Francisco, CA
Security Engineer, Offensive Security
$300k+/yrHybrid5+ YOESecurity Engineering

Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.

Anthropic

Anthropic

San Francisco, CA
Cyber Evaluations Engineer
$300k+/yrHybridSecurity Engineering

Build and operate evaluations for cyber capabilities and safeguard robustness in AI models, analyze adversarial data, and develop cyber-abuse detection probes. The role requires hands-on cybersecurity experience, Python proficiency, evaluation expertise, and strong cross-functional communication.

Fluidstack

Fluidstack

New York, NY
Security Engineer, Threat Intelligence
$220k+/yrOn-siteSecurity Engineering

The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.