# Software Engineer, HSM Infrastructure Security, Consumer Devices

**Company:** [OpenAI](https://hotfix.jobs/companies/openai)
**Location:** San Francisco, CA
**Role:** Security Engineering
**Salary:** $347k – $445k/yr
**Experience:** 5+ years
**Skills:** C, C++, Rust, Hsm, Embedded Firmware, Applied Cryptography, Pkcs#11, Openssl, Pki, X.509, Secure Boot, Remote Attestation, Arm Trustzone, Aws Cloudhsm, Fuzzing
**Posted:** 2026-09-04

> Design and ship security-critical software and firmware at the boundary between policy systems and hardware-backed cryptographic protection. The role requires 5+ years of secure embedded development and deep C, C++, or Rust experience.

## Job Description

## Responsibilities
- Design and implement security-critical software and firmware for HSMs, secure elements, trusted execution environments, and hardware roots of trust.
- Harden policy-to-HSM boundaries for certificate issuance and cryptographic signing.
- Develop HSM trusted applications, firmware components, host interfaces, device drivers, SDKs, and cryptographic service integrations.
- Implement cryptographic interfaces such as PKCS#11, OpenSSL providers or engines, and platform key-storage APIs.
- Build systems enforcing policies for key generation, provisioning, usage, rotation, recovery, and destruction.
- Design HSM-backed certificate authority, code-signing, key-management, and device-identity systems.
- Develop protocols spanning devices, secure hardware, policy services, and backend infrastructure.
- Support device attestation, secure boot, factory provisioning and restoration, registration, and authentication.
- Build verifiable, auditable controls for trusted software and policy changes.
- Write, review, test, and audit secure embedded software; develop test harnesses, emulators, fuzzers, and fault-injection tooling.
- Threat-model hardware and software trust boundaries and translate findings into engineering improvements.
- Collaborate across hardware, firmware, infrastructure, application, security, and product teams.
- Establish engineering standards for HSM development, applied cryptography, secure key management, and certificate infrastructure.

## Requirements
- 5+ years of experience building secure embedded firmware for constrained environments.
- Deep programming experience in C, C++, or Rust.
- Experience designing, implementing, debugging, and shipping production systems software.
- Hands-on experience with security-critical software or firmware in or adjacent to an HSM, secure element, TEE, or hardware root of trust.
- Strong knowledge of applied cryptography, digital signatures, key hierarchies, secure key management, and cryptographic protocol design.
- Experience with PKI, X.509 certificates, certificate authorities, certificate issuance, and certificate lifecycle protocols.
- Familiarity with secure boot, measured boot, device identity, remote attestation, or hardware-backed storage.
- Understanding of concurrency, memory safety, privilege separation, hardware interfaces, failure modes, and side-channel or physical attack considerations.
- Ability to evaluate security designs and implement the software needed to realize them.

## Nice-to-Haves
- ARM TrustZone or another trusted execution environment.
- Commercial or cloud HSM platforms such as Thales Luna, Entrust/nShield, Utimaco, Marvell LiquidSecurity, AWS CloudHSM, or comparable systems.
- PKCS#11, KMIP, OpenSSL providers or engines, secure-element APIs, or platform-native key-storage frameworks.
- Device manufacturing, secure provisioning, factory restore, or silicon bring-up.
- Secure boot ROM, bootloader, firmware signing, anti-rollback, or authenticated updates.
- Trusted applications or cryptographic services inside an HSM or secure coprocessor.
- Hardware/software co-design involving cryptographic accelerators, secure processors, or custom silicon.
- Multi-party authorization, quorum-controlled deployments, tamper-resistant audit mechanisms, or attestable policy systems.
- Hardware-protected-key storage systems.
- Sustaining high-assurance security software in production.

## Similar jobs

- [Security Engineer - Threat Intel](https://hotfix.jobs/jobs/6755c877-3974-4901-9d13-a4c8d6591236) - Anthropic - New York, NY - $320k – $405k/yr
- [Security Engineer, Corporate Security](https://hotfix.jobs/jobs/5bfe00e1-07b2-44ee-b927-2586d89c7fe7) - Anthropic - San Francisco, CA - $320k – $405k/yr
- [Security Engineer, Offensive Security](https://hotfix.jobs/jobs/e5c4fc22-2c3a-4334-8eae-e8ab5bcf2a8a) - Anthropic - San Francisco, CA - $300k – $320k/yr
- [Cyber Evaluations Engineer](https://hotfix.jobs/jobs/5720917b-cc75-4d96-9629-7c3fc9a5d6cd) - Anthropic - San Francisco, CA - $300k – $405k/yr
- [Security Engineer, Threat Intelligence](https://hotfix.jobs/jobs/a9d333c0-2242-416f-a470-d3a19f982046) - Fluidstack - New York, NY - $220k – $280k/yr

**Apply:** https://hotfix.jobs/jobs/c59b2911-dd77-45cf-a787-90da0f7be1b7
**Canonical:** https://hotfix.jobs/jobs/c59b2911-dd77-45cf-a787-90da0f7be1b7