Principal Embedded Systems Security Engineer

True Anomaly, Inc.

Denver, Northern (CO, KY)

Hybrid

USD 180,000 - 240,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health insurance
Equity
401K
Parental Leave

Job summary

True Anomaly, Inc. seeks a Principal Embedded Systems Security Engineer to own the security of our spacecraft, radio systems and hardware platforms.

You’ll build secure-by-default flight software, firmware and tooling for real-time environments. In this hands-on leadership role, you’ll drive security architecture, PKI and cryptography across C/C++, embedded C, FPGA and RTOS, embedding security into the full lifecycle with the Platform Security team.

Qualifications

  • Active security clearance or ability to obtain one.
  • Hands-on embedded hardware and firmware security experience.
  • Strong C/C++ development and low-level programming skills.
  • Proven track record building production security platforms and tooling.
  • Deep PKI knowledge for embedded and resource-constrained systems.
  • Expert cryptography aligned with government standards (FIPS 140-3).

Responsibilities

  • Own the security architecture, threat modeling, and defensive controls for our spacecraft platform.
  • Architect and build the security platforms, tooling, and foundational services that make secure-by-default the standard across flight software, firmware, and hardware configuration.
  • Design and implement PKI for resource-constrained spacecraft, covering device authentication, firmware signing and verification, secure boot, lifecycle management, and secure key storage.
  • Architect cryptographic and security implementations to meet stringent government standards, including FIPS 140-3, CNSA 2.0, and CCSDS.
  • Space Data Link Security (SDLS), and drive the migration to post-quantum cryptography across the platform.
  • Secure the flight software build and deployment pipeline by hardening the tooling itself and protecting the supply-chain integrity of build outputs, dependencies, and third-party components.
  • Lead security assessments and penetration testing against our spacecraft, RF systems, and test environments.
  • Drive the adoption of secure design practices across the organization, partnering with flight software, hardware, and test engineering teams to embed security into the full development and validation lifecycle.
  • Tackle novel security challenges in space-based systems where established solutions don't exist, and stay ahead of emerging embedded and RF threats to proactively harden our systems.
  • Use AI to move faster — accelerating development, analyzing security data, and closing technical knowledge gaps.

Skills

Embedded security
C/C++
PKI knowledge
Security testing
Leadership
System architecture

Tools

HSM integration

Job description

Principal Embedded Systems Security Engineer

Denver, CO or Long Beach, CA

Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it.

OUR MISSION

True Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors — enabling the U.S. and its Allies to secure the space environment and counter threats from the ultimate high ground.

OUR VALUES
  • Be the offset.We create asymmetric advantages with creativity and ingenuity.
  • What would it take?We challenge assumptions to deliver ambitious results.
  • It’s the people.Our team is our competitive advantage and we are better together.
YOUR MISSION

Embedded systems security for space operations poses unique challenges: remote systems that must operate in adversarial RF environments, resource-constrained hardware, and trade-offs between security and performance in real-time systems. As our Principal Embedded Systems Security Engineer,you'll own the security of our spacecraft, radio systems, and hardware platforms. You'll build security platforms and foundational services that enable ourhardware and software teams to develop secure embedded systems by default.This role demands deep security expertise and the rigor that comes from engineering systems that cannot fail. As part of the Platform Security team, you'llwork hands-on across C++ flight software, embedded C firmware within microcontrollers and radiation-hardened SoCs, FPGA designs, and real-timeoperating systems. Your work will impact the spacecraft's critical subsystems, from flight computer through command and control, RF, and payload. Ifyou've secured systems where failure means loss of life or national security impact, you'll understand the constraints and rigor required here.This is a hands-on technical leadership role combining deep hardware security expertise with strong software engineering skills. You will write productioncode and build the tooling, test frameworks, and security validation platforms that harden our embedded systems at scale. You'll tackle novel securitychallenges that don't have an established playbook as we aim to set the standard for space-based security. In our AI-native environment, you'll use AI toaccelerate your work and help solve the hard problems of embedded systems security.

This position requires the ability to obtain and maintain a security clearance.

Responsibilities
  • Own the security architecture, threat modeling, and defensive controls for our spacecraft platform. This spans the flight computer, subsystemfirmware, FPGA gateware, cryptographic implementations, and secure boot.
  • Architect and build the security platforms, tooling, and foundational services that make secure-by-default the standard across flight software,firmware, and hardware configuration.
  • Design and implement PKI for resource-constrained spacecraft, covering device authentication, firmware signing and verification, secure boot,lifecycle management, and secure key storage.
  • Architect cryptographic and security implementations to meet stringent government standards, including FIPS 140-3, CNSA 2.0, and CCSDS
  • Space Data Link Security (SDLS), and drive the migration to post-quantum cryptography across the platform.
  • Secure the flight software build and deployment pipeline by hardening the tooling itself and protecting the supply-chain integrity of build outputs,dependencies, and third-party components.
  • Secure our test environments against supply-chain attacks while keeping them representative of the flight security posture, so we can exercise onthe ground the controls used to protect the spacecraft in orbit.
  • Lead security assessments and penetration testing against our spacecraft, RF systems, and test environments.
  • Drive the adoption of secure design practices across the organization, partnering with flight software, hardware, and test engineering teams toembed security into the full development and validation lifecycle.
  • Tackle novel security challenges in space-based systems where established solutions don't exist, and stay ahead of emerging embedded and RFthreats to proactively harden our systems.
  • Use AI to move faster — accelerating development, analyzing security data, and closing technical knowledge gaps.
Required Qualifications
  • Active security clearance, or the ability to obtain and maintain one.
  • Deep, hands-on expertise in embedded, hardware, and firmware security — including hardware attack surfaces, side-channel and fault-injectionattacks, firmware security, secure boot, and hardware security modules (HSMs).
  • Strong software development skills in C and C++, plus solid engineering fundamentals (data structures, algorithms, API design, and debugging
  • production systems) and comfort working across multiple languages and at low levels (assembly, firmware).
  • Proven track record of building production security platforms, tooling, and foundational services used by hardware and embedded engineeringteams.
  • Deep, expert-level PKI knowledge with hands-on experience designing and operating PKI for embedded and resource-constrained systems —certificate-based device authentication, firmware signing certificate chains, secure boot PKI hierarchies, certificate provisioning and rotation forconstrained devices (where rotation isn't trivial, e.g., spacecraft in orbit), secure key storage, and HSM integration.
  • Expert-level applied cryptography: implementing and reasoning about cryptographic systems to stringent government standards (FIPS 140-3, andfamiliarity with CNSA 2.0 and CCSDS SDLS), and experience with the practical challenges of post-quantum cryptography migration. Strongfamiliarity with common NIST publications (e.g., the 800-series).
  • Experience applying security testing methodologies for hardware and firmware, and building the tooling and frameworks to automate that testingat scale across engineering teams.
  • Demonstrated principal-level impact: setting security strategy and technical direction across an organization, independently identifying andprioritizing the risks that matter most, driving hardening initiatives end to end, raising the security bar and mentoring other engineers, thriving onambiguous and novel problems, and influencing and aligning teams without direct authority.
Preferred Qualifications
  • Hands-on experience taking cryptographic modules through formal FIPS validation (CMVP), beyond implementing to the standard.
  • Experience with real-time or safety-critical embedded systems — timing constraints, deterministic execution, interrupt handling, and the securityimplications of hard real-time requirements.
  • Background in a regulated or high-assurance domain: aerospace, defense, avionics, medical devices, or industrial control systems.
  • Hardware reverse engineering, firmware analysis, and cryptographic implementation experience.
  • FPGA/VHDL security and RF/radio security.
  • HIL/SIL test infrastructure and embedded Linux environments.
  • Supply-chain security experience and a track record of hardening build pipelines for embedded/firmware systems.
  • Cross-domain thinking that connects hardware security requirements to cloud infrastructure, network security, and system architecture.
  • Evidence of practical, hands-on impact — published CVEs, security research or publications, conference talks, open-source contributions, orrelevant projects
  • Equity + Benefits including Health, Dental, Vision, HRA/HSA options, PTO and paid holidays, 401K, Parental Leave

To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.

True Anomaly is committed to equal employment opportunity on any basis protected by applicable state and federal laws. If you have a disability or additional need that requires accommodation, please do not hesitate to let us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Embedded Systems Security Engineer
Principal Embedded Systems Security Engineer

Socket.dev • Denver (CO)

On-site
USD 225,000 - 330,000
Staff Embedded Systems Security Engineer
Staff Embedded Systems Security Engineer

Socket.dev • Denver (CO)

On-site
USD 200,000 - 305,000
Staff Embedded Systems Security Engineer
Staff Embedded Systems Security Engineer

True Anomaly, Inc. • Denver (CO), Northern (KY)

Hybrid
USD 140,000 - 210,000
Equity & Benefits
Senior Embedded Security Engineer, Flight Software
Senior Embedded Security Engineer, Flight Software

True Anomaly • Long Beach (CA), Denver (CO)

On-site
USD 150,000 - 205,000
Health insurance
Dental insurance
Vision insurance
+2
Staff Mission COMSEC Engineer
Staff Mission COMSEC Engineer

True Anomaly • Long Beach (CA)

On-site
USD 170,000 - 280,000
Health, Dental, Vision benefits
401K
Parental Leave
Staff Platform Engineer, Security
Staff Platform Engineer, Security

True Anomaly, Inc. • Denver (CO), Northern (KY)

Hybrid
USD 180,000 - 240,000
Equity
Health plan
PTO & holidays
+1
Senior Manager, Enterprise Security
Senior Manager, Enterprise Security

Menlo Ventures • Laguna Beach (CA)

On-site
USD 165,000 - 250,000
Health benefits
PTO & holidays
401K
+2
Mission Security Engineer III
Mission Security Engineer III

True Anomaly • Long Beach (CA)

Hybrid
USD 120,000 - 190,000
Health insurance
401K
Parental Leave
+1
Staff Platform Engineer, Security
Staff Platform Engineer, Security

Menlo Ventures • San Francisco (CA)

On-site
USD 215,000 - 310,000
Health benefits
Dental benefits
Vision benefits
+2
Senior Manager, Enterprise Security
Senior Manager, Enterprise Security

True Anomaly, Inc. • Denver (CO), Northern (KY)

Hybrid
USD 150,000 - 210,000
Equity + Benefits