×
Register Here to Apply for Jobs or Post Jobs. X

Software Engineer, HSM Infrastructure Security, Consumer Devices

Job in San Francisco, San Francisco County, California, 94199, USA
Listing for: Triwill Group
Full Time position
Listed on 2026-09-07
Job specializations:
  • Software Development
Salary/Wage Range or Industry Benchmark: 180000 - 240000 USD Yearly USD 180000.00 240000.00 YEAR
Job Description & How to Apply Below

Description:

We are hiring a Security Software Engineer to design and implement the hardware-backed security foundations used across OpenAI’s device ecosystem.

In This Role, You Will
  • Design and implement security-critical software and firmware for HSMs, secure elements, trusted execution environments, and hardware roots of trust.
  • Build and harden the policy-to-HSM boundary responsible for authorizing certificate issuance and cryptographic signing operations.
  • Develop HSM trusted applications, firmware components, host interfaces, device drivers, SDKs, or cryptographic service integrations.
  • Implement or extend cryptographic interfaces such as PKCS#11, OpenSSL providers or engines, platform key-storage APIs, or comparable hardware-security interfaces.
  • Build firmware and software that cryptographically enforces key generation, provisioning, usage, rotation, recovery, and destruction policies.
  • Design and implement HSM-backed certificate authority, code-signing, key-management, and device-identity systems.
  • Develop end-to-end cryptographic protocols spanning devices, secure hardware, policy services, and backend infrastructure.
  • Build security capabilities supporting device attestation, secure boot, factory provisioning and restoration, user registration, and authentication.
  • Design controls that make trusted software and policy changes verifiable, auditable, and subject to appropriate multi-party authorization.
  • Write, review, test, and audit secure embedded software for resource-constrained environments.
  • Develop test harnesses, emulators, fuzzers, and fault-injection tooling to validate security properties and failure behavior.
  • Threat‑model hardware and software trust boundaries and translate findings into concrete engineering improvements.
  • Partner with hardware, firmware, infrastructure, application, and security teams to integrate secure‑by‑default capabilities into production systems.
  • Help establish engineering standards for HSM development, applied cryptography, secure key management, and certificate infrastructure.
Minimum Qualifications
  • 5+ years experience building secure embedded firmware for constrained environments
  • Deep programming experience in C, C++, or Rust.
You Might Thrive in This Role If You Have
  • A strong track record of designing, implementing, debugging, and shipping production systems software.
  • Hands‑on experience developing security‑critical software or firmware within, or directly adjacent to, an HSM, secure element, TEE, or hardware root of trust.
  • Experience developing one or more of the following:
    • HSM firmware or trusted applications
    • Cryptographic mechanisms or hardware‑accelerated cryptographic services
    • HSM device drivers, host libraries, SDKs, or middleware
    • PKCS#11 providers, mechanisms, or integrations
    • Secure key‑provisioning or key‑injection protocols
    • HSM‑backed certificate authority or code‑signing systems
    • Signing‑policy enforcement within a hardware‑backed trust boundary
  • Strong knowledge of applied cryptography, digital signatures, key hierarchies, secure key management, and cryptographic protocol design.
  • Experience with PKI, X.509 certificates, certificate authorities, certificate issuance, and certificate lifecycle protocols.
  • Familiarity with secure boot, measured boot, device identity, remote attestation, or hardware‑backed storage.
  • Experience reasoning about concurrency, memory safety, privilege separation, hardware interfaces, failure modes, and side‑channel or physical attack considerations.
  • The ability to evaluate security designs and personally implement the software required to realize them.
  • Clear communication skills and the ability to collaborate across hardware, firmware, backend, and product teams.
Additional Experience That May Be Helpful
  • Firmware development for ARM Trust Zone or another trusted execution environment.
  • Experience with commercial or cloud HSM platforms such as Thales Luna, Entrust/nShield, Utimaco, Marvell Liquid Security, AWS CloudHSM, or comparable systems.
  • Experience with PKCS#11, KMIP, OpenSSL providers or engines, secure‑element APIs, or platform‑native key‑storage frameworks.
  • Device manufacturing, secure provisioning, factory restore, or silicon bring‑up experience.
  • Secure…
Position Requirements
5+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary