Embedded Security Engineer: HSMs, PKCS#11 & Trust

OpenAI

San Francisco (CA)

On-site

USD 210,000 - 310,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

OpenAI is hiring a Security Software Engineer in San Francisco to design and implement hardware-backed security foundations across our device ecosystem. You will harden the boundary between policy systems and HSMs that protect cryptographic keys, and develop security-critical software near or within the HSM trust boundary.

The role involves designing, coding, debugging, and deploying across hardware and software boundaries, including PKCS#11 interfaces, secure key management, and device identity

Qualifications

  • 5+ years experience building secure embedded firmware for constrained environments.
  • Deep programming experience in C, C++, or Rust.

Responsibilities

  • Design and implement security-critical software and firmware for HSMs, secure elements, trusted execution environments, and hardware roots of trust.
  • Build and harden the policy-to-HSM boundary responsible for authorizing certificate issuance and cryptographic signing operations.
  • Develop HSM trusted applications, firmware components, host interfaces, device drivers, SDKs, or cryptographic service integrations.
  • Implement or extend cryptographic interfaces such as PKCS#11, OpenSSL providers or engines, platform key-storage APIs, or comparable hardware-security interfaces.

Skills

C/C++/Rust

Tools

PKCS#11
OpenSSL
KMIP

Job description

OpenAI is hiring a Security Software Engineer in San Francisco to design and implement hardware-backed security foundations across our device ecosystem. You will harden the boundary between policy systems and HSMs that protect cryptographic keys, and develop security-critical software near or within the HSM trust boundary.

The role involves designing, coding, debugging, and deploying across hardware and software boundaries, including PKCS#11 interfaces, secure key management, and device identity

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Embedded Security Engineer - HSM Trust & Device Crypto
Embedded Security Engineer - HSM Trust & Device Crypto

JobCubby • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
HSM & Hardware-Backed Security Engineer
HSM & Hardware-Backed Security Engineer

Triwill Group • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Software Engineer, HSM Infrastructure Security, Consumer Devices
Software Engineer, HSM Infrastructure Security, Consumer Devices

JobCubby • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Software Engineer, HSM Infrastructure Security, Consumer Devices
Software Engineer, HSM Infrastructure Security, Consumer Devices

OpenAI • San Francisco (CA)

On-site
USD 210,000 - 310,000
Hardware Security Engineer — First-Party Systems
Hardware Security Engineer — First-Party Systems

OpenAI • California (MO)

Hybrid
USD 150,000 - 190,000
Relocation assistance
Software Engineer, HSM Infrastructure Security, Consumer Devices
Software Engineer, HSM Infrastructure Security, Consumer Devices

Triwill Group • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Senior HSM Engineer - Secure Crypto Platform
Senior HSM Engineer - Secure Crypto Platform

Crypto Pro Network • San Francisco (CA), New York (NY), Sioux Falls (SD)

On-site
USD 120,000 - 150,000
Secure Hardware Architect for Trusted Computing & Enclaves
Secure Hardware Architect for Trusted Computing & Enclaves

OpenAI • Northern (KY)

Hybrid
USD 293,000 - 490,000
Secure Silicon & Enclave Architect
Secure Silicon & Enclave Architect

Triwill Group • United States

Remote
USD 180,000 - 240,000
Security Engineer, AI Hardware Platform (Hybrid SF)
Security Engineer, AI Hardware Platform (Hybrid SF)

OpenAI • San Francisco (CA)

Hybrid
USD 230,000 - 385,000
Relocation assistance
Equity offers