Product Security Engineer

OKSI

Los Angeles (CA)

On-site

USD 154,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, vision coverage
Three weeks vacation
401K with employer contribution
Educational assistance

Job summary

OKSI is seeking a Product Security Engineer to own product-level security across our hardware and software systems. You will define and maintain the policies, standards, and architectural practices that protect our systems from design through field deployment.

This is a strategic role requiring both the depth to establish security standards company-wide and the hands-on technical background to assess implementation and guide engineering teams.

Qualifications

  • 7+ years in product/embedded security or cybersecurity systems engineering in defense/advanced tech environments.
  • Proven ability to lead threat modeling, risk assessments, and vulnerability analyses across hardware, firmware, and software.
  • Hands-on experience defining security policies and standards and owning policy/architecture.

Responsibilities

  • Lead threat modeling and security analysis across hardware, firmware, and software throughout the product lifecycle.
  • Define and implement hardening standards for embedded Linux, RTOS, and bare-metal environments; manage signing policies and secure boot.
  • Own anti-tamper posture per DoD policy and ensure PPP alignment and implementation across product lines.
  • Serve as product security authority; establish standards, lead design reviews, and embed security into Systems Engineering.

Skills

Threat modeling
Security risk assessments
Vulnerability analysis
Security policies & standards
Secure boot architectures
Embedded Linux hardening
Key management infrastructure
Program Protection Plans
Policy documentation

Tools

HSMs
KMS

Job description

We are seeking a Product Security Engineer to own product-level security across OKSI's hardware and software systems. You will define and maintain the policies, standards, and architectural practices that protect our systems from design through field deployment. This is a strategic role requiring both the depth to establish security standards company-wide and the hands-on technical background to assess implementation and guide engineering teams.

What You'll Do
  • Lead threat modeling and security analysis across hardware, firmware, and software throughout the product lifecycle. Produce threat matrices, risk assessments, and security requirements traceable through design reviews and release gates. Own CVE tracking, vulnerability management, and security baseline compliance across the product portfolio.
  • Define and implement hardening standards for embedded Linux, RTOS, and bare-metal environments. Establish code signing policies, secure boot chain integrity, and validation procedures. Partner with IT and Engineering to architect and maintain the product signing and key management infrastructure using HSMs, KMS, or equivalent systems.
  • Own OKSI's anti-tamper posture aligned with DoD policy (DoDI 5200.39) and applicable Program Protection Plan requirements. Define IP protection strategy spanning software binary protection, hardware design protection, firmware confidentiality, and cryptographically bound license enforcement.
  • Serve as OKSI's product security authority. Establish company-wide standards, lead design reviews, provide security sign-off at program milestones, and embed security requirements into the Systems Engineering process. Provide guidance and training to Engineering, IT, and Operations teams on secure design principles.
Requirements
  • 7+ years of product security, embedded security, or cybersecurity systems engineering in a defense, aerospace, or advanced technology environment.
  • Demonstrated expertise leading threat modeling, security risk assessments, and vulnerability analysis across hardware, firmware, and software domains - including production of threat matrices, attack surface analyses, and traceable mitigation plans.
  • Hands-on experience defining and implementing security policies and standards (not just executing implementation tasks). You own the policy and architecture.
  • Working knowledge of secure boot architectures, anti-tamper techniques, and embedded platform security (e.g., UEFI Secure Boot, ARM TrustZone, fuse-based root-of-trust).
  • Practical experience with embedded Linux hardening: kernel configuration, module signing, RBAC/least-privilege access models, debug interface lockdown, and production credential management.
  • Experience with key management infrastructure and signing pipelines (HSMs, KMS, or equivalent) for firmware, software releases, and factory provisioning workflows.
  • Familiarity with DoD program protection and anti-tamper policy frameworks (DoDI 5200.39) and experience producing or reviewing Program Protection Plans (PPPs).
  • Strong written and verbal communication skills for policy documentation, risk reporting, and cross-functional leadership.
Preferred
  • Active DoD Secret or Top Secret clearance.
  • Experience establishing a secure product development lifecycle (SPDLC) or embedding security checkpoints into an engineering development process.
  • Familiarity with secure CI/CD pipeline design, software supply chain security, and artifact integrity controls.
  • Background in ITAR/EAR technology protection controls and export-controlled program environments.
  • Familiarity with CMMC, RMF, IEC 62443, or NIST SP 800-193/800-147 frameworks.
  • Experience with EO/IR, UAS, autonomous systems, or other embedded defense technology programs.
  • Relevant certifications: CISSP, CSSLP, CEH, or equivalent.
  • DoD SkillBridge participants with relevant MOS/AFSC experience (e.g., 17A, 25D, 1B4, or program protection/acquisition roles) are strongly encouraged to apply.
Compensation and Benefits
  • Salary range: $154,000 - $210,000 annually
  • Medical, dental, and vision coverage fully paid by the employer for employees
  • Three weeks of vacation to start
  • Automatic company contribution to 401K - 5% of earned wages (no matching required)
  • Educational assistance and professional development opportunities
  • In-office (Jacksonville, AK or Los Angeles, CA) or remote work (United States) available (position dependent)
Additional Requirements:
  • You must have, or be eligible to obtain, a U.S. Department of Defense Secret security clearance. You will be subject to government security investigations and must be able to access classified information. The inability to obtain a security clearance will result in you being ineligible for the position.

We are an equal employment opportunity and affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, protected veteran status, or any other status protected by law. We provide reasonable accommodations for qualified individuals with disabilities in the application and hiring process. The person hired will have access to information and items subject to U.S. export controls, and therefore, must either be a 'U.S. person' as defined by 22 C.F.R.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

OKSI • Torrance (CA)

Hybrid
USD 154,000 - 210,000
Medical, dental, vision coverage fully
401(k) contribution
Product Security Engineer
Product Security Engineer

Overland AI • Seattle (WA)

On-site
USD 170,000 - 200,000
Equity compensation
Best-in-class healthcare, dental and vision plans
Unlimited PTO
+2
Security Engineer (Embedded & Networking)
Security Engineer (Embedded & Networking)

United States Digital Space LLC • Hawthorne (CA)

On-site
USD 130,000 - 180,000
Comprehensive medical, vision, and dental coverage
401(k) retirement plan
Paid vacation and holidays
Security Engineer (Embedded OT)
Security Engineer (Embedded OT)

United States Digital Space LLC • Hawthorne (CA)

On-site
USD 130,000 - 155,000
Comprehensive medical, vision, and dental coverage
401(k) retirement plan
Paid parental leave
+1
Security Engineer (Embedded OT)
Security Engineer (Embedded OT)

United States Digital Space LLC • Town of Florida (NY)

On-site
USD 130,000 - 180,000
Comprehensive medical, vision, and dental coverage
401(k) retirement plan
Paid parental leave
+2
IT Engineer (DevOps Engineer)
IT Engineer (DevOps Engineer)

OKSI • Torrance (CA)

On-site
USD 59,000 - 79,000
Medical insurance
3 weeks vacation
401K with 5% contribution
Sr. Security Engineer
Sr. Security Engineer

United States Digital Space LLC • Hawthorne (CA)

On-site
USD 170,000 - 265,000
Stock options
Medical coverage
Dental coverage
+5
Sales/Solutions Engineer
Sales/Solutions Engineer

OKSI • Torrance (CA)

On-site
USD 100,000 - 135,000
Medical, dental, and vision fully paid
Three weeks vacation
Automatic 401K contribution (5%)
+2
Cybersecurity Engineer (Product Security)
Cybersecurity Engineer (Product Security)

CHAOS Industries • El Segundo (CA)

On-site
USD 110,000 - 190,000
Health benefits (100% paid)
401(k) with company match
Free daily lunch
+2
Security Engineer (Embedded & Networking)
Security Engineer (Embedded & Networking)

United States Digital Space LLC • Town of Florida (NY)

On-site
USD 90,000 - 120,000