CrawlJobs Logo

Product Security Engineer

1X Technologies

Location Icon

Location:
United States, Palo Alto

Category Icon
Category:
IT - Software Development

Job Type Icon

Contract Type:
Employment contract

Salary Icon

Salary:

Not provided

Job Description:

As a Product Security Engineer specializing in cryptography and PKI, you will design, implement, and scale cryptographic infrastructure to secure firmware, devices, and communications. You will work on hardware security modules (HSMs), secure pipelines, device provisioning, attestation, and lifecycle management to ensure the trustworthiness of robot fleets.

Job Responsibility:

  • Design and manage end‑to‑end cryptographic services, including public key infrastructure (PKI) and key lifecycle management
  • Establish HSM infrastructure as the root‑of‑trust for firmware signing and IoT endpoint authentication
  • Lead evaluation, procurement, installation, configuration, and integration of HSM vendor solutions
  • Architect key management systems that scale from hundreds of devices today to millions over time
  • Design remote device attestation mechanisms (e.g. fTPM, OP‑TEE, or equivalent) tied to the HSM root‑of‑trust
  • Build and automate secure firmware/bootloader signing pipelines
  • Define trust infrastructure and policies for author key generation, provisioning, rotation, and destruction
  • Secure build/artifact pipelines and code‑signing workflows
  • Develop factory provisioning architecture for mass key/certificate distribution
  • Support the development of secure communication protocols
  • Collaborate closely with Product Security, Cloud Infrastructure, Device Engineering, and SecOps teams as an individual contributor

Requirements:

  • Strong experience with cryptography, PKI design, and key management
  • Experience working with hardware security modules (HSMs), including vendor selection, integration, and root‑of‑trust establishment
  • Familiarity with remote device attestation frameworks (such as fTPM, OP‑TEE, or similar)
  • Demonstrated ability to design and scale secure firmware signing and code signing pipelines
  • Proven track record in defining and enforcing trust policies (key generation, rotation, destruction) and provisioning mechanisms
  • Experience securing build/artifact pipelines and developing secure communication protocols
  • Ability to work cross‑functionally with hardware, software, security operations, and infrastructure teams
  • High attention to detail, strong problem solving, with a mindset of anticipating vulnerabilities and designing defendable systems

Nice to have:

  • Vendor-specific HSM credentials or labs (Thales, Utimaco, AWS CloudHSM)
  • NVIDIA Orin or similar SoC platform experience
  • Background in post-quantum crypto evaluation and migration planning
  • Familiarity with large-scale factory provisioning tools (KMIP gateways, ACME/SCEP)
  • ProdSec/supply-chain security expertise (SBOMs, CI/CD hardening)
  • Experience in C/C++/Rust/GoLang (in addition to Python / Bash)
  • GoLang preferred
  • Additional security certifications

Additional Information:

Job Posted:
December 01, 2025

Employment Type:
Fulltime
Work Type:
On-site work
Job Link Share:
Welcome to CrawlJobs.com
Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.