Senior Platform Security Engineer – Device Trust, Attestation and Secure Browser

NVIDIA Gruppe

Santa Clara (CA)

On-site

USD 196,000 - 311,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Equity
Benefits

Job summary

NVIDIA is seeking a Senior Security Engineer to lead device attestation and the enterprise secure browser program across cloud, on‑premises, and managed devices. You will define trust across endpoints, workloads, and browsing sessions, and write production code to automate security operations.

You will collaborate with device management, identity governance, network security, and platform engineering to set technical strategy and own operational responsibilities.

Qualifications

  • Bachelor’s or Master’s degree in CS or related field.
  • 12+ years in platform, infrastructure, or security engineering.
  • Strong software development skills and track record of shipping production services.
  • Experience designing and owning large-scale distributed security platforms.
  • Automating operations at scale: self-healing, low toil, SLO-driven.
  • Solid understanding of Zero Trust, device trust, and posture models.

Responsibilities

  • Design and implement a device attestation service with hardware roots of trust.
  • Lead enterprise rollout of secure browser platform and related controls.
  • Build SRE agents for automation and telemetry across attestation, endpoint, and browser services.
  • Define architectures binding device trust to session trust for consistent evaluation.
  • Integrate device and browser trust signals into identity and access workflows.
  • Scale platform-security capabilities across large heterogeneous endpoints; ensure reliability and compliance.
  • Establish SLOs, observability, capacity planning, and incident response readiness.
  • Partner with cross-functional teams to align on build strategy and ownership.

Skills

Platform security
Endpoint security
Security engineering
Software development
Automation at scale
Zero Trust

Education

Bachelor's degree or higher

Tools

TPM
Secure Enclave
Measured boot
TEEs

Job description

NVIDIA’s Enterprise Security organization is looking for a Senior Security Engineer passionate about platform and device security! This role includes leading device attestation and our enterprise secure browser program’s technical direction. You will define how NVIDIA establishes and continuously verifies trust in every endpoint, workload, and browsing session that touches our worldwide infrastructure across cloud, on-premises, and managed device environments.

This role offers a hands-on, high-impact engineering opportunity at the intersection of platform security, endpoint and browser trust, and AI infrastructure. In addition to architecture, you will write production code. A core part of the charter is building SRE agents. These are automation tools powered by intelligent systems. They monitor, diagnose, and fix the security platforms we operate. This work turns manual response playbooks into self-healing systems. You will partner closely with device management, identity governance, network security, and platform engineering to set technical strategy and carry operational ownership.

What You’ll Be Doing:
  • Design and implement a device attestation service that produces verifiable, cryptographically backed device posture signals from hardware roots of trust (TPM 2.0, Secure Enclave, measured boot) and makes them consumable as a first-class input to access decisions.
  • Lead the engineering and enterprise rollout of our secure browser platform (Prisma Access Browser), including access policies, data-loss prevention controls, browser-extension governance, telemetry, and integrations with identity, Conditional Access, SASE, and ZTNA platforms.
  • Build SRE agents for security platforms, design, code, and operate agentic automation that detects degradation, triages alerts, correlates telemetry, executes safe remediation, and reduces toil across attestation, endpoint, and browser services.
  • Define reference architectures that bind device trust to session trust, so that browser, CLI, and agentic workflows are all evaluated against consistent, continuously reevaluated posture.
  • Integrate device and browser trust signals into identity and access workflows, enabling access decisions based on user identity, device integrity, browser posture, session risk, and application sensitivity.
  • Scale platform-security capabilities across large and heterogeneous endpoint environments while maintaining reliability, performance, security, compliance, and a positive user experience.
  • Establish service-level objectives, observability, capacity planning, and operational readiness for device-trust and secure-browser services. Lead incident response, post-incident reviews, and implementation of durable corrective actions.
  • Partner with multi-functional collaborators across security, IT and product teams to align on architecture, build strategy, and long-term operational ownership.
What We Need to See:
  • Bachelor’s degree or Master’s degree or equivalent experience in Computer Science or a related field.
  • 12+ years of experience in platform, infrastructure, or security engineering, including significant depth in endpoint or platform security.
  • Strong, current software development skills with a track record of shipping and operating production services.
  • Experience designing, building, and owning large-scale distributed services or security platforms, including the operational responsibility that comes with them.
  • Demonstrated experience automating operations at scale: reducing toil, building self-healing or closed-loop remediation, and running services against defined SLOs.
  • Solid understanding of Zero Trust architecture, device trust and posture models, and endpoint attack techniques, plus how identity, device, and network signals combine into access decisions.
  • Working knowledge of at least one hardware or platform trust primitive (TPM, Secure Enclave, measured boot, TEEs, hardware-bound credentials) and the ability to go deep quickly on attestation.
  • Excellent written and verbal communication skills; comfortable driving architecture decisions across senior and executive audiences.
Ways To Stand Out From The Crowd:
  • Hands-on experience building attestation or device posture services that run at enterprise scale with high availability and low latency.
  • Deep understanding of TPM and measured boot internals, remote attestation protocols, and device-bound credentials and tokens (DPoP, mTLS, WebAuthn). Familiarity with securing non-human and machine identities, and with how attestation underpins service-to-service and agentic access patterns.
  • Experience deploying or operating an enterprise browser or secure web access stack (Prisma Access Browser, Island, Chrome Enterprise, SASE/ZTNA, CASB, DLP), especially across a large developer population. Familiarity with browser security internals such as extension models, isolation boundaries, and policy enforcement.
  • Experience building AI agents or ML-assisted automation for reliability or security operations, including guardrails, evaluation, and safe-action design or a demonstrated track record of picking up emerging tooling and shipping with it fast.
  • Experience leading enterprise endpoint or device trust transformations, including migration off legacy agents and posture models at scale.

At NVIDIA, we operate at the core of enterprise security, architecting and protecting the platforms that support some of the most advanced computing systems in the world. This role offers the opportunity to influence strategy, build the automation that runs our security platforms, engage with executives, and leave a lasting security impact, working alongside outstanding engineers and security leaders!

NVIDIA is widely considered to be one of the technology world’s most desirable employers. We have some of the most intelligent and hardworking people in the world working for us. If you’re creative and autonomous, we want to hear from you!

Your base salary will be determined based on your location, experience, and the pay of employees in similar positions. The base salary range is 196,000 USD - 310,500 USD.

You will also be eligible for equity and benefits.

Applications for this job will be accepted at least until September 14, 2026.

This posting is for an existing vacancy.

NVIDIA uses AI tools in its recruiting processes.

NVIDIA is committed to fostering an inclusive work environment and proud to be an equal opportunity employer. As we highly value diversity in our current and future employees, we do not discriminate (including in our hiring and promotion practices) on the basis of race, religion, color, national origin, gender, gender expression, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Platform Security Engineer – Device Trust, Attestation and Secure Browser
Senior Platform Security Engineer – Device Trust, Attestation and Secure Browser

NVIDIA Corporation • Santa Clara (CA)

On-site
USD 196,000 - 311,000
Senior Platform Security Engineer - Device Trust, Attestation and Secure Browser
Senior Platform Security Engineer - Device Trust, Attestation and Secure Browser

Nvidia Corporation in • Santa Clara (CA)

On-site
USD 196,000 - 311,000
Equity
Benefits
Senior Cybersecurity Engineer – Identity Platform and Access Management
Senior Cybersecurity Engineer – Identity Platform and Access Management

NVIDIA • Santa Clara (CA)

On-site
USD 196,000 - 311,000
Equity
Benefits
Senior Cybersecurity Engineer – Identity Platform and Access Management
Senior Cybersecurity Engineer – Identity Platform and Access Management

NVIDIA Gruppe • Santa Clara (CA)

On-site
USD 196,000 - 311,000
Equity
Benefits
Senior Security Software Engineer
Senior Security Software Engineer

NVIDIA Gruppe • Santa Clara (CA)

On-site
USD 152,000 - 288,000
Equity
Benefits
Senior Software Engineer, Security
Senior Software Engineer, Security

NVIDIA Gruppe • Santa Clara (CA)

On-site
USD 184,000 - 287,500
Equity options
Comprehensive benefits package
Senior Security Software Engineer
Senior Security Software Engineer

NVIDIA • Santa Clara (CA)

On-site
USD 152,000 - 288,000
Equity
Benefits
Senior Software Engineer, Security
Senior Software Engineer, Security

NVIDIA • California (MO)

On-site
USD 184,000 - 357,000
Equity
Benefits
Senior Security Architect - AI/HPC Infra (Equity Eligible)
Senior Security Architect - AI/HPC Infra (Equity Eligible)

NVIDIA • California (MO)

On-site
USD 184,000 - 357,000
Intellectual Property Security Engineer
Intellectual Property Security Engineer

NVIDIA • Durham (NC)

On-site
USD 184,000 - 357,000
Equity
Benefits