Product Security Architect
Listed on 2026-09-21
-
Engineering
Cybersecurity, Hardware Engineer, Systems Engineer -
IT/Tech
Cybersecurity, Hardware Engineer, Systems Engineer
Enphase Energy is a global energy technology company and a leading provider of solar, battery, and electric vehicle charging products. Founded in 2006, our innovative microinverter technology revolutionized solar power, making it a safer, more reliable, and scalable energy source. Today, the Enphase Energy System enables users to make, use, save, and sell their own power. Enphase is also one of the most successful and innovative clean energy companies in the world, with more than 80 million products shipped across 160 countries.
Join our dynamic teams designing and developing next-gen energy technologies and help drive a sustainable future!
This role at Enphase requires working onsite 3 days a week, with plans to transition back to a full 5-day in-office schedule over time.
About the RoleWe are hiring a Product Security Architect to drive product security across Enphase's entire hardware portfolio — from silicon to cloud. This is a senior, hands‑on role that owns the full lifecycle of product security: architecting and implementing security controls, driving compliance with regulations such as the EU Cyber Resilience Act (CRA) and the RED Delegated Act (2022/30), leading product security testing and certification efforts, running vulnerability management, and serving as the primary technical point of contact for external penetration testers and independent security researchers.
Our product families include:
- IQ Gateway (Envoy) — ARM Cortex‑A SoC (AM335x/AM62x) running embedded Linux, acting as the on‑premise brain for every Enphase solar installation. Connects to the cloud via Wi‑Fi, Ethernet, or cellular (LTE Cat‑M1) and orchestrates OTA firmware delivery to the entire on‑site fleet.
- IQ8 Microinverters — Custom 8051‑based ASIC with PLC (powerline communication) connectivity. Deployed at massive scale (80M+ units). Communicates with the gateway over the AC power line using proprietary PLC protocols with AES/XXTEA encryption and SHA‑256 session key derivation.
- IQ Battery & System Controller (Enpower) — Safety‑critical Battery Management System (BMS) and automatic transfer switch controlling solar/battery/grid interactions. CAN bus + PLC interfaces. Firmware controls high‑voltage DC and AC switching with direct life‑safety implications.
- IQ EV Charger & Balcony Solar — Network‑connected consumer products entering the EU market, subject to ETSI EN 303 645, RED Article 3.3, the RED Delegated Act, and the EU Cyber Resilience Act.
- IQ Energy Router — Intelligent energy routing with grid‑interactive capabilities, controlling power flows across solar, battery, grid, and loads.
You will report to the Head of Security and work as a senior technical leader within a cross‑functional team spanning firmware engineering, hardware engineering, cloud platform, and product management. You will drive security outcomes across the organization without necessarily holding formal management authority, though the scope may grow to include direct reports as the product security program matures.
What You Will Do Security Architecture:Secure Boot & Hardware Root of Trust
- Architect and harden secure boot chains across the product portfolio: AM335x/AM62x (Gateway), 8051 ASIC (Microinverters), and BMS controllers (Battery/Enpower) — signed bootloaders, anti‑rollback counters, eFuse/OTP provisioning, and verified boot at every stage
- Design ARM Trust Zone partitioning (TEE/OP‑TEE) on Gateway SoCs to isolate cryptographic operations, key material, and security‑critical firmware from the normal‑world OS
- Audit and remediate JTAG/SWD debug interface exposure across all hardware products — verify fuse‑based disable on production units, define debug authentication policy for engineering builds
- Define the hardware Root‑of‑Trust…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).