Sr. Staff Platform Security Engineer, Confidential Computing

Groq, Inc.

United States

Hybrid

USD 341,000 - 402,000

Full time

22 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Groq, Inc. is seeking a senior security leader to define technical direction for hardware-rooted security frameworks.

You will architect security capabilities spanning firmware, hardware trust, and protected workloads while collaborating with hardware, firmware, and systems teams. The role emphasizes threat modeling, secure boot, device identity, and secure provisioning, with a focus on trust across hardware and software boundaries.

Qualifications

  • 6+ years in systems, firmware, hardware, or security engineering.
  • Experience with hardware-rooted trust, attestation, TEEs, or confidential computing.
  • Ability to communicate trust models and security architecture clearly.

Responsibilities

  • Set technical direction and own architecture for security across hardware and software.
  • Design security architectures for hardware-rooted trust, attestation, TEEs, and protected workload execution.
  • Lead threat modeling and security analysis across hardware, firmware, host software, and workloads.
  • Develop security tooling and automation to enable scale and operability of hardware-backed security.
  • Translate complex hardware and software risks into practical engineering decisions.

Skills

Systems security
Firmware security
Attestation
TEEs
Cryptography
C/C++/Rust
Threat modeling
Cross-functional
Security tooling

Job description

Mission

Build the hardware-rooted security foundations that protect sensitive AI workloads across hardware and software boundaries. You will set technical direction and build security capabilities spanning firmware security, hardware trust, attestation, trusted execution environments, and protected workload execution. As a senior technical leader, you will work close to the hardware layer and partner across hardware, firmware, systems, platform, and security engineering to solve complex security challenges at the foundation of the computing stack.

Location

Location: This role will be based in one of our three hiring hubs: the Dallas, San Francisco, or New York City area. The person hired for this role must be based in one of these three areas. You’ll have the flexibility to work remotely while we establish our local Groq office, with the expectation that this role will transition to onsite once the office opens.

Responsibilities & Opportunities In This Role
  • Set technical direction and own architecture for security capabilities spanning hardware, firmware, systems software, and protected workload execution.
  • Design and build security architectures for hardware-rooted trust, attestation, trusted execution environments, and hardware-backed isolation.
  • Architect attestation capabilities that establish and verify trust across hardware, firmware, host, and workload boundaries.
  • Partner deeply with hardware, firmware, and systems engineers to shape platform integrity, secure and measured boot, device identity, and other hardware-rooted security capabilities.
  • Design security capabilities that enable protected workload execution while maintaining trust throughout the workload lifecycle.
  • Design secure approaches for cryptographic key material, credentials, identity, certificates, and provisioning within trusted computing environments.
  • Shape security for the lifecycle of trusted compute infrastructure, from provisioning and platform initialization through operation and decommissioning.
  • Lead threat modeling and security analysis across hardware, firmware, host software, and workload execution, identifying systemic risks and driving durable mitigations.
  • Develop systems software, security tooling, and automation that make hardware-backed security capabilities reliable and operable at scale.
  • Lead security-sensitive designs across organizational boundaries, translating complex hardware and systems risks into practical engineering decisions.
  • Establish technical patterns and influence security direction across hardware, firmware, systems, platform, and security engineering.
  • Partner across engineering and security to build capabilities that strengthen customer trust, platform reliability, and support compliance requirements.
  • Clearly communicate trust models, security architecture, technical tradeoffs, and risk to engineers, technical leaders, and security leadership.
Ideal Candidates Have/are
  • 6+ years of systems, firmware, hardware, or security engineering experience, with deep expertise in low-level systems security and experience with hardware-rooted trust, attestation, trusted execution environments, confidential computing, or related technologies.
  • Demonstrated experience setting technical direction and owning complex security architecture spanning multiple layers of the hardware and software stack.
  • Deep expertise in firmware security, hardware-rooted trust, attestation, trusted execution environments (TEEs), protected workload execution, or closely related low-level security domains.
  • Deep understanding of hardware-rooted trust, including roots of trust, platform integrity, secure or measured boot, device identity, and hardware-backed attestation.
  • Experience designing or implementing attestation systems and reasoning about trust across hardware, firmware, host, and workload boundaries.
  • Strong understanding of firmware and low-level systems security, including boot chains, platform integrity, and security boundaries between hardware and software.
  • Strong understanding of cryptographic systems, key management, certificate lifecycle, secure credential management, and secure provisioning in trusted computing environments.
  • Strong systems engineering skills, with experience developing low-level systems software, security tooling, firmware, or production automation in languages such as C, C++, Rust, Go, Python, or similar languages.
  • Ability to threat model complex systems and reason about attacks spanning hardware, firmware, operating systems, infrastructure, and application workloads.
  • Experience leading ambiguous, cross-functional technical initiatives and influencing engineering direction across highly specialized engineering disciplines.
  • Ability to communicate complex trust models, security architecture, and technical risk clearly to different audiences.
  • Experience developing or securing firmware, platform initialization, device security, or hardware-backed security mechanisms is valuable.
  • Experience integrating hardware-rooted trust, attestation, or confidential computing capabilities with higher-level infrastructure, identity, key-management, or workload systems is valuable.
  • Experience with bare-metal lifecycle security or securing large-scale compute environments is valuable.
Why Join Us
  • Purposeful Hiring: You’re not here by accident, and neither is anyone else. Every teammate is handpicked with intention because who we build with matters.
  • Builders Wanted: You’re not just riding the rocket ship, you’re building it. Your work directly shapes the trajectory of our company.
  • Mission-Driven Work: We’re here to make a real impact. Our mission fuels everything we do.
  • Tackling Hard Problems: If easy isn’t your thing, you’re in the right place. We solve some of the most complex and exciting challenges in our space.
  • Excellence Is The Standard: High performance isn’t just encouraged, it’s the baseline. And it’s contagious.

If this sounds like you, we’d love to hear from you!

Compensation

Groq is committed to providing competitive compensation through our Total Cash philosophy, which incorporates potential bonus value directly into base pay. The total cash salary range for this position, which is inclusive of the potential bonus value, is $341,400 - $401,600, with individual placement determined by your geographic location, experience, skills, and alignment with internal compensation standards. This range is specific to candidates located in the United States. Compensation for international candidates will vary based on local market dynamics. Beyond cash compensation, Groq also offers a Long-Term Incentive (LTI) Program and a robust suite of employee benefits.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Staff Platform Security Engineer, Confidential Computing
Sr. Staff Platform Security Engineer, Confidential Computing

Groq, Inc. • Texas

Hybrid
USD 341,000 - 402,000
Sr. Staff Platform Security Engineer, Confidential Computing
Sr. Staff Platform Security Engineer, Confidential Computing

Groq, Inc. • San Francisco (CA)

On-site
USD 341,000 - 402,000
Sr. Staff Platform Security Engineer, Confidential Computing
Sr. Staff Platform Security Engineer, Confidential Computing

Groq, Inc. • New York (NY)

Hybrid
USD 341,000 - 402,000
Sr. Staff Platform Security Engineer, Cloud Infrastructure
Sr. Staff Platform Security Engineer, Cloud Infrastructure

Groq, Inc. • New York (NY)

Remote
USD 341,000 - 402,000
Sr. Staff Platform Security Engineer, Cloud Infrastructure
Sr. Staff Platform Security Engineer, Cloud Infrastructure

Groq, Inc. • San Francisco (CA)

On-site
USD 341,000 - 402,000
Sr. Staff Platform Security Engineer, Cloud Infrastructure
Sr. Staff Platform Security Engineer, Cloud Infrastructure

Groq, Inc. • Texas

Remote
USD 341,000 - 402,000
Sr./Staff Forward Deployed Engineer
Sr./Staff Forward Deployed Engineer

Groq, Inc. • Town of Texas (WI)

Hybrid
USD 270,000 - 402,000
Sr./Staff Forward Deployed Engineer
Sr./Staff Forward Deployed Engineer

Groq, Inc. • San Francisco (CA)

Hybrid
USD 270,000 - 402,000
Sr./Staff Network Design Engineer, AI/HPC
Sr./Staff Network Design Engineer, AI/HPC

Groq, Inc. • Town of Texas (WI)

Hybrid
USD 270,000 - 402,000
Remote work flexibility
Bonus and LTI by Groq
Total Cash compensation
Cloud Platform Software Engineer
Cloud Platform Software Engineer

Groq, Inc. • New York (NY)

Hybrid
USD 224,000 - 366,000