Remotery

Product Security Engineer

Posted Jul 28

This is a fully remote position, open to applicants in Alaska, +1 more state.

📋 Description

• Direct threat modeling and security assessments across hardware, firmware, and software throughout the entire product lifecycle.

• Create threat matrices, conduct risk assessments, and establish security requirements that are traceable during design reviews and release checkpoints.

• Manage CVE tracking, oversee vulnerability management, and ensure security baseline compliance for the product portfolio.

• Develop and enforce hardening standards for embedded Linux, RTOS, and bare-metal environments.

• Set up code signing policies, maintain secure boot chain integrity, and implement validation procedures.

• Collaborate with IT and Engineering to design and sustain the product signing and key management infrastructure utilizing HSMs, KMS, or similar systems.

• Take ownership of OKSI's anti-tamper strategy in accordance with DoD policies (DoDI 5200.39) and relevant Program Protection Plan requirements.

• Formulate an IP protection strategy that encompasses software binary protection, hardware design safeguards, firmware confidentiality, and cryptographic license enforcement.

• Act as OKSI's authority on product security.

• Establish enterprise-wide standards, lead design reviews, grant security approvals at program milestones, and integrate security requirements into the Systems Engineering process.

• Offer guidance and training to Engineering, IT, and Operations teams regarding secure design principles.


⛳️ Requirements

• Over 7 years of experience in product security, embedded security, or cybersecurity systems engineering within defense, aerospace, or advanced technology sectors.

• Proven ability to lead threat modeling, conduct security risk assessments, and perform vulnerability analyses across hardware, firmware, and software domains — including the creation of threat matrices, attack surface analyses, and trackable mitigation strategies.

• Practical experience in defining and executing security policies and standards (not merely performing implementation tasks). You own the policy and architecture.

• Solid understanding of secure boot architectures, anti-tamper methodologies, and embedded platform security (e.g., UEFI Secure Boot, ARM TrustZone, fuse-based root-of-trust).

• Hands-on experience in hardening embedded Linux: configuring kernels, signing modules, implementing RBAC/least-privilege access models, locking down debug interfaces, and managing production credentials.

• Experience with key management infrastructure and signing processes (HSMs, KMS, or equivalent) for firmware, software releases, and factory provisioning workflows.

• Knowledge of DoD program protection and anti-tamper policy frameworks (DoDI 5200.39) and experience in creating or reviewing Program Protection Plans (PPPs).

• Excellent written and verbal communication skills for policy documentation, risk reporting, and cross-functional leadership.


🏝️ Benefits

• Comprehensive medical, dental, and vision coverage fully paid by the employer for employees.

• Initial three weeks of vacation.

• Automatic company contribution to 401K – 5% of earned wages (no matching required).

• Support for educational assistance and professional development opportunities.

People also viewed

ASG Technologies9 hours ago

IT Security Director

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$165k – $190k/year
ApplyView job
CrowdStrike9 hours ago

Associate Security Engineer

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$70k – $95k/year
ApplyView job
Culmen International10 hours ago

Border Security Trainer

US flagUnited States OnlyFreelanceCybersecurity / Security Engineer
ApplyView job
Threatscape10 hours ago

Security Consultant – Purview

GB flagUnited Kingdom, +1 more countryFull-timeCybersecurity / Security Engineer£35k – £47k/year
ApplyView job
Unity11 hours ago

Staff Security Architect

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$160.3k – $305.4k/year
ApplyView job
Truist13 hours ago

Cybersecurity Group Manager

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers