Staff Firmware Engineer, Platform Security

ALSO.

Palo Alto (CA)

On-site

USD 200,000 - 240,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Robust health coverage
One Medical membership
Progyny fertility benefits
Flexible time off
401(k) match

Job summary

ALSO. is seeking a Staff Firmware Security Architect to define the security direction for vehicle firmware, including secure boot, key lifecycle, network integrity, and OTA trust.

You will own end-to-end security across ECUs, collaborating with cloud, manufacturing, and firmware teams to make secure design practical in CI and production. You’ll lead threat modeling, drive security test strategy, and mentor engineers to raise the bar for trust across the product portfolio, with cross-functional

Qualifications

  • 8+ years in embedded software/firmware with security ownership.
  • Strong engineering degree; MS preferred is a plus.
  • Hands-on crypto with AES, ECC, RSA, HMAC in constrained MCUs.
  • Proven secure boot chain design and OTA trust experience.
  • Experience with CAN/CAN-FD security is a plus.

Responsibilities

  • Define secure boot architecture across MCU families with image signing and anti-rollback.
  • Own on-device and fleet key strategy and PKI integration.
  • Lead CAN/CAN-FD security design and protected diagnostics policies.
  • Own end-to-end OTA security, signatures, encryption, and update flow trust.
  • Architect reusable security libraries and CI integration.
  • Lead threat modeling across boot, update, and network attack surfaces.
  • Mentor engineers and align cross-functional stakeholders on security requirements.

Skills

Embedded security ownership
C/C++ proficiency
Threat modeling
CI/CD integration
Cryptographic primitives
Hardware security modules
Secure boot architecture
Debug/JTAG tooling

Education

BS in engineering (CS/EE preferred)
MS or equivalent depth a plus

Tools

JTAG/SWD
FreeRTOS
Zephyr
ThreadX

Job description

About ALSO.

We’re ALSO, an electric mobility company originally conceived as a part of Rivian. We’re a passionate team of builders, dreamers, doers and innovators, focused on creating entirely new (not to mention, innovative and delightful) vertically integrated, small EVs designed to meet the global mobility challenges of today and tomorrow. Our mission is to inspire everyone to ride ALSO-replacing many local car, truck and SUV miles with ones on vehicles that are more affordable, more enjoyable and 10-50x more efficient.

At ALSO, we are looking for a Staff Firmware Security Architect to set the technical direction for our vehicle firmware security platform - secure boot, cryptographic key lifecycle, network integrity, and trusted OTA. You'd own the end-to-end security architecture that protects every ECU across our product portfolio, make the hard cross-cutting calls that product teams build on, and partner with cloud, manufacturing, and firmware teams to make security practical in CI, on the bench, and in production. You'd raise the bar for the entire organization through design leadership, mentorship, and hands‑on delivery of the most critical trust paths in the vehicle.

What You'll Do
  • Secure boot & root of trust: define secure boot architecture across MCU families (ROM -> bootloader -> app) - image signing, verification, anti-rollback, and debug/JTAG lockdown for production - setting the standard other ECU teams adopt
  • Key storage & management: own the on-device and fleet key strategy (HSM/OTP/secure element), key hierarchy design, and integration with signing and PKI services across development, manufacturing, and field
  • Network & bus integrity: lead CAN/CAN-FD security design (authentication, integrity, encryption where required), and establish policies for protected diagnostics and secure UDS access platform-wide
  • OTA security: own end-to-end trust for firmware updates - signed/encrypted payloads, on-device verification, rollback safety, and secure handoff between cloud signing infrastructure and vehicle update flows
  • Platform security frameworks: architect reusable security libraries and APIs (crypto wrappers, secure storage, auth services) that product ECU teams adopt without reinventing trust
  • Threat modeling & hardening: lead threat models across boot, update, and network attack surfaces, and partner with product and cloud teams on security reviews and production readiness
  • Validation & cross‑functional leadership: drive security test strategy (benchtop PoCs, negative tests, HIL scenarios), integrate critical checks into CI, mentor engineers on secure design, and align firmware, cloud, manufacturing, and systems stakeholders on requirements and trade‑offs
What You'll Bring
  • 8+ years in embedded software/firmware development, with deep ownership of secure boot, crypto, or vehicle/IoT security architecture, and a proven track record setting technical direction across multiple ECUs or products, not just one component
  • BS in an engineering discipline (Computer Science or Electrical Engineering preferred; MS or equivalent depth a plus)
  • Hands‑on expertise with cryptographic primitives and embedded crypto (AES, ECC/RSA, HMAC, certificates) on constrained MCUs, including key provisioning, OTP/fuse programming, and HSM or secure element usage in production
  • Experience designing and shipping secure boot chains, bootloaders, signed firmware images, and OTA trust models in production
  • Experience securing vehicle or industrial networks (CAN/CAN-FD, authenticated messaging, secure diagnostics) is a strong plus
  • Expert‑level C/C++ on bare-metal or RTOS (FreeRTOS, Zephyr, ThreadX, or similar), with deep comfort with linkers, memory maps, and debugging tools (JTAG/SWD)
  • Ability to wire signing and verification into CI/release pipelines and drive platform-wide adoption
  • Excellent communication skills - able to document security architecture, threat models, and runbooks, and mentor senior engineers; hardware‑in‑the‑loop testing and emulation experience is a plus

The salary for this position ranges from $200,000 - $240,000 per year, depending on experience, qualifications, and location.

Perks & Benefits
  • Robust health coverage - excellent health, dental and vision insurance covered up to 100% by ALSO with FSA & HSA options
  • One Medical membership and dedicated insurance advocates
  • Rich fertility and family building benefits with Progyny
  • Flexible time off
  • 401(k) match
Why ALSO.

We’re passionate about helping the world find a better way to get there-wherever it is you’re headed. We’re located in the heart of Silicon Valley and have brought together a world‑class team from some of the biggest brands in the technology, automotive, cycling, outdoor recreation and retail spaces. Together we’re working hands‑on to imagine, design and build an entirely new solution to a global set of transportation challenges.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Firmware Engineer, Platform Security
Staff Firmware Engineer, Platform Security

Also, Inc. • Palo Alto (CA), Northern (KY)

Hybrid
USD 200,000 - 240,000
Health insurance
One Medical
Fertility benefits
+2
Staff Firmware Engineer, Platform Security
Staff Firmware Engineer, Platform Security

Also • Palo Alto (CA)

On-site
USD 200,000 - 240,000
Health/dental/vision
One Medical
Fertility benefits
+2
Staff Firmware Architecture Engineer, Propulsion and Battery
Staff Firmware Architecture Engineer, Propulsion and Battery

Also, Inc. • Palo Alto (CA), Northern (KY)

Hybrid
USD 210,000 - 245,000
Robust health coverage
One Medical membership
Progyny fertility benefits
+2
Staff Firmware Architecture Engineer, Propulsion and Battery
Staff Firmware Architecture Engineer, Propulsion and Battery

ALSO. • Palo Alto (CA)

On-site
USD 210,000 - 245,000
Robust health coverage
One Medical membership
Progyny fertility benefits
+2
Staff Firmware Architecture Engineer, Propulsion and Battery
Staff Firmware Architecture Engineer, Propulsion and Battery

Socket.dev • Palo Alto (CA)

On-site
USD 210,000 - 245,000
Robust health coverage
One Medical membership
Progyny fertility benefits
+2
Staff Firmware Architecture Engineer, Propulsion and Battery
Staff Firmware Architecture Engineer, Propulsion and Battery

ALSO • Palo Alto (CA)

On-site
USD 210,000 - 245,000
Robust health coverage
One Medical membership
Progyny fertility benefits
+2
Staff Security Engineer, Cloud
Staff Security Engineer, Cloud

Also, Inc. • Palo Alto (CA), Northern (KY)

Hybrid
USD 205,000 - 240,000
Health coverage
One Medical membership
Fertility and family benefits
+2
Staff Security Engineer, Cloud
Staff Security Engineer, Cloud

ALSO. • Palo Alto (CA)

On-site
USD 205,000 - 240,000
Robust health coverage
One Medical membership
Progyny fertility benefits
+2
Staff Security Engineer, Cloud
Staff Security Engineer, Cloud

ALSO • Palo Alto (CA)

On-site
USD 205,000 - 240,000
Health insurance
Dental & Vision coverage
401(k) matching
+2
Engineering Technical Lead – Engineering Triage
Engineering Technical Lead – Engineering Triage

ALSO • Palo Alto (CA)

On-site
USD 170,000 - 210,000
Health insurance
401(k) match
One Medical membership
+2