Product Security Engineer
Job in
Torrance, Los Angeles County, California, 90504, USA
Listed on 2026-09-25
Listing for:
OKSI
Full Time
position Listed on 2026-09-25
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security & Data Protection
Job Description & How to Apply Below
Position Overview
We are seeking a Product Security Engineer to own product-level security across OKSI's hardware and software systems. You will define and maintain the policies, standards, and architectural practices that protect our systems from design through field deployment. This is a strategic role requiring both the depth to establish security standards company-wide and the hands-on technical background to assess implementation and guide engineering teams.
WhatYou'll Do
- Lead threat modeling and security analysis across hardware, firmware, and software throughout the product lifecycle. Produce threat matrices, risk assessments, and security requirements traceable through design reviews and release gates. Own CVE tracking, vulnerability management, and security baseline compliance across the product portfolio.
- Define and implement hardening standards for embedded Linux, RTOS, and bare-metal environments. Establish code signing policies, secure boot chain integrity, and validation procedures. Partner with IT and Engineering to architect and maintain the product signing and key management infrastructure using HSMs, KMS, or equivalent systems.
- Own OKSI's anti-tamper posture aligned with DoD policy (DoDI 5200.39) and applicable Program Protection Plan requirements. Define IP protection strategy spanning software binary protection, hardware design protection, firmware confidentiality, and cryptographically bound license enforcement.
- Serve as OKSI's product security authority. Establish company-wide standards, lead design reviews, provide security sign-off at program milestones, and embed security requirements into the Systems Engineering process. Provide guidance and training to Engineering, IT, and Operations teams on secure design principles.
- 7+ years of product security, embedded security, or cybersecurity systems engineering in a defense, aerospace, or advanced technology environment.
- Demonstrated expertise leading threat modeling, security risk assessments, and vulnerability analysis across hardware, firmware, and software domains — including production of threat matrices, attack surface analyses, and traceable mitigation plans.
- Hands-on experience defining and implementing security policies and standards (not just executing implementation tasks). You own the policy and architecture.
- Working knowledge of secure boot architectures, anti-tamper techniques, and embedded platform security (e.g., UEFI Secure Boot, ARM Trust Zone, fuse-based root-of-trust).
- Practical experience with embedded Linux hardening: kernel configuration, module signing, RBAC/least-privilege access models, debug interface lockdown, and production credential management.
- Experience with key management infrastructure and signing pipelines (HSMs, KMS, or equivalent) for firmware, software releases, and factory provisioning workflows.
- Familiarity with DoD program protection and anti-tamper policy frameworks (DoDI 5200.39) and experience producing or reviewing Program Protection Plans (PPPs).
- Strong written and verbal communication skills for policy documentation, risk reporting, and cross-functional leadership.
- Active DoD Secret or Top Secret clearance.
- Experience establishing a secure product development lifecycle (SPDLC) or embedding security checkpoints into an engineering development process.
- Familiarity with secure CI/CD pipeline design, software supply chain security, and artifact integrity controls.
- Background in ITAR/EAR technology protection controls and export-controlled program environments.
- Familiarity with CMMC, RMF, IEC 62443, or NIST SP 800-193/800-147 frameworks.
- Experience with EO/IR, UAS, autonomous systems, or other embedded defense technology programs.
- Relevant certifications: CISSP, CSSLP,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×