Cryptography Firmware Engineer
The job description
Tech stack. Cryptographic algorithm implementation (AES, RSA, ECC, SHA), secure elements and TPM 2.0 integration, side-channel attack countermeasures, key lifecycle management, PKI fundamentals and manufacturing, constant-time coding discipline, secure boot chains
About the role
You will implement and integrate applied cryptography correctly in connected devices that must withstand determined, sophisticated, well-funded adversaries. Cryptography firmware engineers own the foundational security of the product: cryptographic algorithms and protocols, key generation and storage, random number generation quality, and the side-channel defenses that separate genuine security from compliance-theater checkbox exercises. Your code protects device identities, customer data, and firmware update channels across the entire product lifetime, often a decade or longer. Defects in this domain remain completely silent until they become catastrophic, so your engineering discipline must be absolute and your design reviews genuinely adversarial. Professional paranoia is a job requirement, not a personality flaw.
What you will achieve
- Implement cryptographic operations correctly using hardware accelerators, secure elements, or TPMs, with integration reviewed independently by qualified peers
- Deliver complete cryptographic key lifecycle management: secure generation with proper entropy, protected storage, defined rotation policies, and verified destruction procedures
- Harden device firmware systematically against side-channel attacks: constant-time algorithm implementations, power analysis countermeasures, and fault injection awareness in design
- Integrate secure boot, remote attestation, and encrypted storage seamlessly into the device lifecycle from factory provisioning through end-of-life decommissioning
- Support formal security certifications with thorough technical documentation, comprehensive test evidence, and auditor-ready design descriptions
What you will bring
Must-haves
- 2 to 5 years in security-focused firmware engineering, cryptographic engineering, or deeply security-conscious embedded development
- Solid understanding of applied cryptography: AES operation modes, RSA and ECC fundamentals, cryptographic hash functions, digital signatures, and key derivation functions
- Practical experience with secure elements, TPMs, or hardware security modules: secure provisioning flows, remote attestation protocols, and sealed storage mechanisms
- Knowledge of side-channel attack classifications (timing, power, electromagnetic, fault injection) and the standard, proven countermeasures for each class
- Familiarity with TLS protocol operation on constrained devices, secure boot chain architecture, and X.509 certificate handling in firmware
- Exceptionally disciplined coding practices: constant-time implementation discipline, sensitive memory zeroization, minimal attack surface design, and careful error handling that leaks nothing
- BS in Electrical Engineering, Computer Engineering, or Computer Science
Nice-to-haves
- Experience with post-quantum cryptographic algorithms and organizational migration planning for quantum resistance
- Familiarity with Common Criteria, FIPS 140-3, or SESIP security evaluation processes and their evidence requirements
- Knowledge of PKI operations at manufacturing scale: certificate authority hierarchies, secure certificate injection, and revocation infrastructure
- Experience performing vulnerability analysis of cryptographic implementations and coordinating responsible disclosure
Apple
Tesla
Qualcomm
Intel
Western Digital
Seagate