Principal Platform Security Architect

Neurophos

San Mateo (CA)

On-site

USD 230,000 - 320,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

100% health plan premiums for you and/
Unlimited PTO
401(k) matching and stock options
Voluntary benefits: Dental, Vision, LI
Personalized benefits

Job summary

Neurophos is seeking a Principal Platform Security Architect to own platform security across our EIC and T100 system. You will lead the root-of-trust, secure boot, device attestation, and signed firmware updates for hyperscale deployments.

The role requires fluent collaboration with RTL designers, firmware engineers, and datacenter teams, including security reviews and governance with customers. This onsite position reports to the VP of Architecture.

Qualifications

  • 10+ years in hardware and firmware security architecture on silicon that shipped.
  • Experience integrating root-of-trust IP, provisioning and fuse/OTP planning.
  • Secure boot chain design and firmware resiliency to NIST SP 800-193 class requirements.

Responsibilities

  • Own the platform threat model and security architecture from fab through field deployment.
  • Architect the silicon root of trust: RoT IP integration, key provisioning, fuse/OTP strategy, and debug authorization.
  • Define the secure and measured boot chain and firmware resiliency behavior.
  • Own device attestation using SPDM with DICE identity.
  • Define signed OTA firmware update with anti-rollback protection.
  • Specify security-relevant telemetry to datacenter operators.
  • Drive compliance against OCP security profiles and DMTF specs.
  • Own the key management lifecycle and manufacturing/field processes.
  • Serve as technical owner for outsourced RoT subsystem engagement.
  • Support hyperscaler security reviews and defend architectural decisions.

Skills

Hardware security architecture
Root-of-trust integration
Secure boot design
SPDM/DICE/MCTP/PLDM knowledge
Cryptographic primitives & key storage
Security specifications writing
Excellent communication

Education

BS/MS/PhD in CS or EE

Tools

SPDM
DICE
MCTP
PLDM

Job description

About Neurophos

The demand for new data centers and AI compute is rapidly outpacing the planet’s energy capacity. Digital solutions are hitting a power wall as we approach the physical limits of traditional silicon. Conquering this bottleneck means rethinking the fundamental architecture of inference compute. The industry’s current path can’t meet the need, so we’re taking a different approach.

Instead of traditional electronic circuits, we use silicon photonics and an active, programmable metasurface to perform matrix multiplications at the speed of light. Our optical cells are 10,000x smaller than traditional photonic components, enabling unprecedented density. By using photonics instead of electricity, our chips become more efficient as they scale. This architecture will deliver up to 100 times the energy efficiency of existing solutions while significantly improving performance for large-scale AI inference.

We’ve assembled a world-class team of industry veterans and recently raised a $110M Series A led by Gates Frontier. Participants include M12 (Microsoft’s Venture Fund), Carbon Direct Capital, Aramco Ventures, Bosch Ventures, Tectonic Ventures, Space Capital, and others.

Join us and shape the future of computing!

Location: Austin, TX or Sunnyvale, CA. Full-time onsite position.

Reports To : VP of Architecture

FLSA Status : Exempt

Position Overview

We are seeking a Principal Platform Security Architect to own platform security across our electronic integrated circuit (EIC) and the wider T100 system. This is a product security role, not an IT or corporate security role. Hyperscale customers will not deploy an accelerator they cannot verify, so this position owns the machinery that makes our silicon verifiable: the root of trust, secure and measured boot, device attestation, signed firmware update, and security telemetry. The ideal candidate has shipped these subsystems on real silicon, can speak fluently to both RTL designers and firmware engineers, and knows the datacenter compliance landscape well enough to design toward it rather than retrofit for it. This role is the technical owner for our outsourced root-of-trust subsystem engagement.

Key Responsibilities
  • Own the platform threat model and the security architecture that answers it, from fab through field deployment.
  • Architect the silicon root of trust: RoT IP integration, key provisioning, fuse and one-time programmable (OTP) strategy, and debug authorization.
  • Define the secure and measured boot chain and firmware resiliency behavior.
  • Own device attestation using SPDM (Security Protocol and Data Model) with DICE (Device Identifier Composition Engine) identity.
  • Define signed over-the-air (OTA) firmware update with anti-rollback protection.
  • Specify security-relevant telemetry and its exposure to datacenter operators.
  • Drive compliance against OCP (Open Compute Project) security profiles and DMTF (Distributed Management Task Force) specifications.
  • Own the key management lifecycle and the associated manufacturing and field processes.
  • Serve as technical owner for the outsourced root-of-trust subsystem engagement.
  • Support customer and hyperscaler security reviews, and own the security narrative in those forums.
  • Partner with digital design, firmware, and systems teams to land security requirements in implementation.
Qualifications
  • BS/MS/PhD in Computer Science, Electrical Engineering, or a related field.
  • 10+ years in hardware and firmware security architecture on silicon that shipped.
  • Hands-on experience integrating root-of-trust IP, including provisioning and fuse/OTP planning.
  • Secure boot chain design and firmware resiliency to NIST SP 800-193 class requirements.
  • Working knowledge of SPDM, DICE, MCTP (Management Component Transport Protocol), and PLDM (Platform Level Data Model).
  • Practical understanding of cryptographic primitives, key hierarchies, and secure key storage in silicon.
  • Demonstrated ability to write security specifications that digital design and firmware teams can implement against.
  • Excellent communication skills and comfort defending architectural decisions to external reviewers.
Preferred Skills
  • Familiarity with OCP Security profiles and Caliptra.
  • Side-channel and fault-injection countermeasure design.
  • FIPS or Common Criteria certification experience.
  • Experience supporting hyperscaler security review processes.
  • Background in confidential computing or trusted execution environments.
  • Post-quantum cryptography migration planning.
  • Experience with manufacturing-side provisioning flows and supply chain security.
What We Offer

This is an opportunity to play a pivotal role in an innovative startup redefining the future of AI hardware. Work on game-changing technology at the intersection of photonics and AI as part of a collaborative, brilliant team. You’ll contribute to a platform that redefines computational performance and accelerates the future of artificial intelligence. Come help us bring this transformative technology to the world.

Benefits

Join a team that invests in your future and your well-being. At Neurophos, we offer:

  • 100% coverage of base health plan premiums for you and your dependents, plus HSA contributions.
  • Unlimited PTO. No rigid vacation banks, just a focus on delivery.
  • 401(k) matching and stock option opportunities to ensure our success is your success.
  • Full suite of voluntary benefits, including Dental, Vision, Life, Hospital, Critical Illness, and Accident insurance.
  • Personalized Benefits. Choose the plans that fit your life and take the cash back for those that don’t.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Platform Security Architect
Principal Platform Security Architect

Neurophos • Austin (TX)

On-site
USD 150,000 - 210,000
Health plan premiums covered
HSA contributions
Unlimited PTO
+2
Principal Platform Security Architect
Principal Platform Security Architect

Socket.dev • Sunnyvale (CA)

On-site
USD 180,000 - 240,000
Principal Platform Security Architect
Principal Platform Security Architect

Neurophos • Sunnyvale (CA)

On-site
USD 180,000 - 280,000
Health coverage
Unlimited PTO
401(k) with stock options
+1
Lead Security Engineer
Lead Security Engineer

Neurophos Inc. • Sunnyvale (TX), Northern (KY)

Hybrid
USD 180,000 - 240,000
100% health plan premiums coverage
HSA contributions
Unlimited PTO
+3
Lead Security Engineer
Lead Security Engineer

Neurophos • Sunnyvale (CA), Austin (TX)

On-site
USD 170,000 - 250,000
Health coverage
Unlimited PTO
401(k) matching
+2
Lead Security Engineer
Lead Security Engineer

Socket.dev • Austin (TX)

On-site
USD 180,000 - 280,000
Health coverage
Unlimited PTO
401(k) matching
+3
Lead Security Engineer
Lead Security Engineer

Neurophos • San Mateo (CA)

On-site
USD 180,000 - 280,000
100% health premium coverage
HSA contributions
Unlimited PTO
+3
Principal SoC Design Engineer / SoC Lead
Principal SoC Design Engineer / SoC Lead

Neurophos, Inc. • Austin (TX), Northern (KY)

Hybrid
USD 180,000 - 240,000
Health insurance
HSA contributions
Unlimited PTO
+4
Principal SoC Design Engineer / SoC Lead
Principal SoC Design Engineer / SoC Lead

Neurophos • Austin (TX), Sunnyvale (CA)

On-site
USD 180,000 - 240,000
100% coverage of base health plan for你
Unlimited PTO
401(k) matching and stock options
+1
Principal SoC Design Engineer / SoC Lead
Principal SoC Design Engineer / SoC Lead

Neurophos • San Mateo (CA)

On-site
USD 180,000 - 280,000
Health benefits
Unlimited PTO
401(k) + stock options
+1