
Product Security Engineer
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in Alaska, +1 more state.
• Direct threat modeling and security assessments across hardware, firmware, and software throughout the entire product lifecycle.
• Create threat matrices, conduct risk assessments, and establish security requirements that are traceable during design reviews and release checkpoints.
• Manage CVE tracking, oversee vulnerability management, and ensure security baseline compliance for the product portfolio.
• Develop and enforce hardening standards for embedded Linux, RTOS, and bare-metal environments.
• Set up code signing policies, maintain secure boot chain integrity, and implement validation procedures.
• Collaborate with IT and Engineering to design and sustain the product signing and key management infrastructure utilizing HSMs, KMS, or similar systems.
• Take ownership of OKSI's anti-tamper strategy in accordance with DoD policies (DoDI 5200.39) and relevant Program Protection Plan requirements.
• Formulate an IP protection strategy that encompasses software binary protection, hardware design safeguards, firmware confidentiality, and cryptographic license enforcement.
• Act as OKSI's authority on product security.
• Establish enterprise-wide standards, lead design reviews, grant security approvals at program milestones, and integrate security requirements into the Systems Engineering process.
• Offer guidance and training to Engineering, IT, and Operations teams regarding secure design principles.
• Over 7 years of experience in product security, embedded security, or cybersecurity systems engineering within defense, aerospace, or advanced technology sectors.
• Proven ability to lead threat modeling, conduct security risk assessments, and perform vulnerability analyses across hardware, firmware, and software domains — including the creation of threat matrices, attack surface analyses, and trackable mitigation strategies.
• Practical experience in defining and executing security policies and standards (not merely performing implementation tasks). You own the policy and architecture.
• Solid understanding of secure boot architectures, anti-tamper methodologies, and embedded platform security (e.g., UEFI Secure Boot, ARM TrustZone, fuse-based root-of-trust).
• Hands-on experience in hardening embedded Linux: configuring kernels, signing modules, implementing RBAC/least-privilege access models, locking down debug interfaces, and managing production credentials.
• Experience with key management infrastructure and signing processes (HSMs, KMS, or equivalent) for firmware, software releases, and factory provisioning workflows.
• Knowledge of DoD program protection and anti-tamper policy frameworks (DoDI 5200.39) and experience in creating or reviewing Program Protection Plans (PPPs).
• Excellent written and verbal communication skills for policy documentation, risk reporting, and cross-functional leadership.
• Comprehensive medical, dental, and vision coverage fully paid by the employer for employees.
• Initial three weeks of vacation.
• Automatic company contribution to 401K – 5% of earned wages (no matching required).
• Support for educational assistance and professional development opportunities.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.