Platform Security Engineer, DRTM / Secure Launch

United States Digital Space LLC

San Francisco (CA, WA)

Hybrid

USD 320,000 - 405,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

United States Digital Space LLC is building the platform security foundation for frontier model infrastructure. This role owns DRTM across x86 and ARM, delivering attestation and isolation capabilities while hardening the platform at firmware, bootloader, kernel, and silicon levels.

You will collaborate with firmware security, hardware, and OS hardening engineers, engage with vendors and OEMs, and contribute upstream to Linux Secure Launch and related projects.

Qualifications

  • Measured boot, roots of trust, TPM 1.2/2.0 concepts and measurement chains.
  • Strong C and assembly skills with Linux kernel and early-boot knowledge.
  • Experience landing upstream work in Linux, TianoCore, or GRUB.
  • Hardware/firmware boundary troubleshooting with debugging tooling (JTAG, serial).
  • Cross-functional leadership with external vendors and OEMs.
  • Clear written communication and public technical writing.

Responsibilities

  • Own adoption and integration of DRTM hardware security features across x86 and ARM.
  • Implement attestation services and privacy capabilities enabled by DRTM.
  • Design bootloader-agnostic solutions to initiate and relaunch DRTM sessions.
  • Hardening of DRTM solutions including SMM isolation and ACPI handling.
  • Interface with vendors and OEMs to refine requirements and feasibility.
  • Publish work upstream and help maintain Linux Secure Launch leadership.
  • Act as technical lead in architecture and disseminate work via papers and talks.
  • Support open source efforts and upstream interactions.
  • Build and harden platform security features like TDX and SEV.
  • Develop drivers for custom hardware and diagnose firmware issues.
  • Debug kernel and system-level issues on production hardware.
  • Pursue investigative work in new technical areas (dTPMs, fTPMs).

Skills

Measured boot), DRTM experience

Job description

About the company

the company’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.

About the role

the company is building the platform security foundation for the infrastructure that trains and serves frontier models. This role owns Dynamic Root of Trust for Measurement (DRTM) across that fleet: bringing it up on x86 and ARM, building the attestation and isolation properties it makes possible, and hardening the parts of the platform that DRTM alone does not cover.

The work sits at the lowest layers of the stack: firmware, bootloaders, kernel, and the silicon features underneath them. It is also unusually public. We expect the DRTM work done here to land upstream, and the person in this role will be a visible participant in the Linux and firmware communities rather than a consumer of them.

Security carries the same design weight as performance and scalability at datacenter scale. You will partner closely with our firmware security, hardware, and OS hardening engineers, and directly with vendor and OEM partners whose DRTM implementations we depend on.

Key responsibilities

DRTM adoption and integration:

  • Own adoption and integration of DRTM hardware security features across the company infrastructure, on both x86 and ARM platforms
  • Implement attestation services and the additional security and privacy capabilities that DRTM presence enables
  • Design and implement a bootloader-agnostic solution for initiating and relaunching DRTM sessions
  • Investigate further hardening of existing DRTM solutions: PPAM to isolate SMM on x86, VMM features to isolate UEFI runtime services, ACPI handling and hardening in DRTM environments

Vendors and upstream:

  • Interface with vendor and OEM partners on their DRTM solutions: refine requirements jointly and determine which changes are desirable and feasible
  • Publish relevant DRTM work upstream and help carry Linux Secure Launch maintainership as tboot is retired
  • Act as technical lead in architecture and design, and disseminate the work through technical papers, conference talks, and community engagement
  • Assist other the company teams with their own open source efforts and upstream interactions

Broader low-level platform work:

  • Build and harden other platform security features, including confidential computing solutions such as TDX and SEV
  • Support custom operating system artifacts, implement device drivers for custom hardware and features, and do firmware diagnosis and enhancement work
  • Debug and diagnose kernel and system-level issues on production hardware
  • Take on investigative work in new technical areas and old unsolved ones (for example, the distinct security problems in dTPMs and fTPMs)
Minimum qualifications
  • Deep hands-on experience with measured boot and roots of trust: DRTM (Intel TXT, AMD SKINIT, ARM equivalents), SRTM, TPM 1.2/2.0, and the measurement chains built on them
  • Strong C and assembly, with deep Linux kernel and early-boot fundamentals (bootloaders, UEFI, ACPI, SMM)
  • A record of landing non-trivial work upstream in Linux, TianoCore, GRUB, or a comparable community
  • Comfort at the hardware/firmware boundary and with the debugging that comes with it: JTAG, serial, platform-level bring-up, silicon errata
  • Strong technical cross-functional leadership and direction setting, including with external vendors and OEMs
  • Clear written communication: this role produces specifications, design docs, and public technical writing
  • Working knowledge of NIST firmware security guidance, particularly SP 800-193 and 800-147/155
Preferred qualifications
  • 8+ years in systems security, with at least 5 years focused on firmware, bootloader, and OS-level security
  • Existing maintainership or subsystem ownership in Linux, or standing in the TCG, UEFI Forum, or OCP communities
  • Confidential computing implementation experience: TDX, SEV-SNP, ARM CCA, and their attestation flows
  • Hardware roots of trust and attestation beyond the TPM: Caliptra, OCP S.A.F.E., SPDM
  • Memory-safe systems code in Rust
  • Firmware vulnerability research, reverse engineering, or fuzzing
  • Previous work with AI/ML infrastructure security

The annual compensation range for this role is listed below.

For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role.

Annual Salary:

$320,000—$405,000 USD

LogisticsMinimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experienceRequired field of study:A field relevant to the role as demonstrated through coursework, training, or professional experienceMinimum years of experience: Years of experience required will correlate with the internal job level requirements for the positionLocation-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.Visa sponsorship:We do sponsor visas! However, we aren't able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you're interested in this work. We think AI systems like the ones we're building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Platform Security Engineering, Auditor
Platform Security Engineering, Auditor

United States Digital Space LLC • San Francisco (CA)

Hybrid
USD 320,000 - 405,000
Platform Security Engineer, DRTM / Secure Launch
Platform Security Engineer, DRTM / Secure Launch

Anthropic • San Francisco (CA)

On-site
USD 320,000 - 405,000
Competitive compensation
Equity donation matching
Generous vacation
+1
Platform Security Engineer, DRTM / Secure Launch
Platform Security Engineer, DRTM / Secure Launch

Anthropic • New York (NY)

Hybrid
USD 320,000 - 405,000
Equity donation matching
Generous vacation
Parental leave
+2
Platform Hardware Security
Platform Hardware Security

Anthropic • San Francisco (CA)

Hybrid
USD 405,000
Platform Hardware Security
Platform Hardware Security

Anthropic • Seattle (WA)

Hybrid
USD 405,000
Platform Hardware Security San Francisco, CA | New York City, NY | Seattle, WA
Platform Hardware Security San Francisco, CA | New York City, NY | Seattle, WA

Anthropic • San Francisco (CA)

On-site
USD 405,000
Embedded Linux Security Engineer
Embedded Linux Security Engineer

United States Digital Space LLC • San Mateo (CA)

On-site
USD 130,000 - 280,000
Healthcare programs
Vision, dental coverage
HSA with employer contributions
+1
Offensive Hardware Security Engineer, Platform Security
Offensive Hardware Security Engineer, Platform Security

Anthropic • New York (NY)

Hybrid
USD 320,000 - 405,000
Platform Security Engineer, OpenBMC
Platform Security Engineer, OpenBMC

Anthropic • San Francisco (CA)

Hybrid
USD 405,000
Member of Technical Staff - Security Engineering
Member of Technical Staff - Security Engineering

Fractile • Bristol Township

Hybrid
USD 160,000 - 241,000
Equity
Private Medical
Pension