Staff Firmware Security Architect – EV Platform, Secure OTA

ridealso

Palo Alto (CA)

On-site

USD 200,000 - 240,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health coverage
One Medical
Fertility benefits
Flexible time off
401(k) match

Job summary

ALSO is seeking a Staff Firmware Security Architect in Palo Alto to set the technical direction for vehicle firmware security. You will own end-to-end security across ECUs, guide cross‑functional teams, and architect reusable crypto libraries and trust models.

You will lead threat modeling, secure boot, OTA trust, and platform security frameworks while collaborating with cloud, manufacturing, and product teams to deliver production‑readiness security across the fleet.

Qualifications

  • 8+ years in embedded software/firmware development, with deep ownership of secure boot, crypto, or vehicle/IoT security architecture, and a proven track record setting technical direction across multiple ECUs or products, not just one component
  • BS in an engineering discipline (Computer Science or Electrical Engineering preferred; MS or equivalent depth a plus)
  • Hands‑on expertise with cryptographic primitives and embedded crypto (AES, ECC/RSA, HMAC, certificates) on constrained MCUs, including key provisioning, OTP/fuse programming, and HSM or secure element usage in production
  • Experience designing and shipping secure boot chains, bootloaders, signed firmware images, and OTA trust models in production
  • Experience securing vehicle or industrial networks (CAN/CAN‑FD, authenticated messaging, secure diagnostics) is a strong plus
  • Expert‑level C/C++ on bare‑metal or RTOS (FreeRTOS, Zephyr, ThreadX, or similar), with deep comfort with linkers, memory maps, and debugging tools (JTAG/SWD)
  • Ability to wire signing and verification into CI/release pipelines and drive platform‑wide adoption
  • Excellent communication skills — able to document security architecture, threat models, and runbooks, and mentor senior engineers; hardware‑in‑the‑loop testing and emulation experience is a plus

Responsibilities

  • Secure boot & root of trust: define secure boot architecture across MCU families (ROM → bootloader → app) — image signing, verification, anti‑rollback, and debug/JTAG lockdown for production — setting the standard other ECU teams adopt
  • Key storage & management: own the on‑device and fleet key strategy (HSM/OTP/secure element), key hierarchy design, and integration with signing and PKI services across development, manufacturing, and field
  • Network & bus integrity: lead CAN/CAN‑FD security design (authentication, integrity, encryption where required), and establish policies for protected diagnostics and secure UDS access platform‑wide
  • OTA security: own end‑to‑end trust for firmware updates — signed/encrypted payloads, on‑device verification, rollback safety, and secure handoff between cloud signing infrastructure and vehicle update flows
  • Platform security frameworks: architect reusable security libraries and APIs (crypto wrappers, secure storage, auth services) that product ECU teams adopt without reinventing trust
  • Threat modeling & hardening: lead threat models across boot, update, and network attack surfaces, and partner with product and cloud teams on security reviews and production readiness
  • Validation & cross‑functional leadership: drive security test strategy (benchtop PoCs, negative tests, HIL scenarios), integrate critical checks into CI, mentor engineers on secure design, and align firmware, cloud, manufacturing, and systems stakeholders on requirements and trade‑offs

Skills

Secure boot
Crypto primitives
Embedded C/C++
Threat modeling
CAN security
CI/CD security
OTA security
RTOS debugging

Education

BS in Engineering
MS depth preferred

Tools

JTAG
SWD
FreeRTOS
Zephyr

Job description

ALSO is seeking a Staff Firmware Security Architect in Palo Alto to set the technical direction for vehicle firmware security. You will own end-to-end security across ECUs, guide cross‑functional teams, and architect reusable crypto libraries and trust models.

You will lead threat modeling, secure boot, OTA trust, and platform security frameworks while collaborating with cloud, manufacturing, and product teams to deliver production‑readiness security across the fleet.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Firmware Architect, EV Propulsion & Battery Platform
Staff Firmware Architect, EV Propulsion & Battery Platform

Also, Inc. • Palo Alto (CA), Northern (KY)

Hybrid
USD 210,000 - 245,000
Robust health coverage
One Medical membership
Progyny fertility benefits
+2
Staff Firmware Architect: Propulsion & Battery
Staff Firmware Architect: Propulsion & Battery

ALSO. • Palo Alto (CA)

On-site
USD 210,000 - 245,000
Robust health coverage
One Medical membership
Progyny fertility benefits
+2
Staff Firmware Architect, Propulsion & Battery
Staff Firmware Architect, Propulsion & Battery

ALSO • Palo Alto (CA)

On-site
USD 210,000 - 245,000
Robust health coverage
One Medical membership
Progyny fertility benefits
+2
Staff Firmware Architect — Propulsion & Battery Platforms
Staff Firmware Architect — Propulsion & Battery Platforms

ridealso • Palo Alto (CA)

On-site
USD 210,000 - 245,000
Health coverage
One Medical
Fertility benefits
+2
Senior Firmware Architect: Secure Boot & RT Platform
Senior Firmware Architect: Secure Boot & RT Platform

42dot Inc. • Sunnyvale (CA)

On-site
USD 189,000 - 267,000
Firmware Engineering Manager - CRA Compliance & Secure OTA
Firmware Engineering Manager - CRA Compliance & Secure OTA

Copeland • Kennesaw (GA)

On-site
USD 140,000 - 180,000
Firmware Engineering Manager: CRA Security & OTA
Firmware Engineering Manager: CRA Security & OTA

Copeland • St. Louis (MO)

On-site
USD 120,000 - 190,000
Medical insurance
Dental and vision coverage
401(k)
+2
Senior Firmware Security Architect
Senior Firmware Security Architect

Micron Memory Malaysia Sdn Bhd • San Jose (CA)

Hybrid
USD 161,000 - 318,000
Medical, dental and vision plans
Paid time off
Paid holidays
+1
Senior Firmware Engineer
Senior Firmware Engineer

Tata Technologies • Mountain View (CA)

On-site
USD 100,000 - 130,000
Staff Embedded Security Engineer — Real-Time, Hybrid
Staff Embedded Security Engineer — Real-Time, Hybrid

EngineersOfAI • Sunnyvale (CA), Northern (KY)

Hybrid
USD 276,000 - 311,000