> Markdown version of [/jobs/ext/1217251-embedded-security-architect](https://www.wearedevelopers.com/jobs/ext/1217251-embedded-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Embedded Security Architect - **Company:** Enphase Energy - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** ARM Architecture, C++ (Programming Language), Cloud Computing, Communications Protocols, Cyber Security, Linux on Embedded Systems, Embedded Software, Ethernet, Firmware, Information Systems Security Architecture Professional, Key Management, Public Key Infrastructure, Real-Time Operating Systems, RSA (Cryptosystem), Wi-Fi Technology, Software Security, Information Technology, IoT Security - **Published:** July 9, 2026 - **Apply:** http://app.jobvite.com/CompanyJobs/Careers.aspx?c=qu49Vfwm&j=od5nAfwZ&k=Apply ## About the Role * BE/BTech/MS/MTech in Computer Science, Electrical Engineering, or a related field. * 8+ years of experience in embedded security or IoT security architecture * Expertise in ARM TrustZone (TEE/OP-TEE), secure bootloaders, chain-of-trust, and hardware Root-of-Trust on ARM Cortex-A/M * Experience with HSM/TPM integration, secure elements, and cryptographic key management (AES, RSA, ECC, hardware crypto accelerators) * Strong knowledge of TLS/mTLS, PKI, certificate lifecycle management, and secure communication protocol design * Familiarity with IoT protocols: BLE, Wi-Fi (802.11), Ethernet, and PLC/powerline communication * Knowledge of security standards: IEC 62443, ETSI EN 303 645, EU Cyber Resilience Act * Experience embedding security-by-design in partnership with firmware, cloud, and product security teams * Familiarity with secure firmware signing and encrypted, authenticated OTA update delivery * Strong problem-solving skills with the ability to thrive in a fast-paced, cross-functional environment * Proficiency in C/C++ and embedded development on RTOS and embedded Linux for ARM Cortex-A/M targets Nice to have: * Experience designing secure OTA update pipelines for large device fleets * Familiarity with side-channel analysis and hardware fault-injection countermeasures * Relevant certifications such as CISSP-ISSAP, GPEN, or GXPN ## Description Join Enphase Energy as an Embedded Security Architect and help secure the IQ Gateway and IQ Microinverter platforms-ARM-based IoT devices that connect millions of solar homes worldwide via Wi-Fi, Ethernet, and cellular networks with cloud-managed OTA firmware delivery. In this role, you will drive security-by-design across embedded systems, working closely with firmware, cloud, and product teams to build highly secure and scalable energy solutions. You will own critical security components such as secure boot chains, TrustZone partitioning, hardware Root-of-Trust, and cryptographic key provisioning across the fleet, ensuring robust, end-to-end device security. What you will be doing: * Architect secure boot chains with a hardware-anchored root of trust - signed, staged bootloaders, anti-rollback counters, and eFuse/OTP provisioning - using ARM TrustZone to isolate secure and non-secure worlds (TEE/OP-TEE) * Design hardware Root-of-Trust and device-identity provisioning (secure elements, PUF, eFuse) and manage the key lifecycle from manufacturing through rotation and revocation * Build and maintain mutual-TLS and PKI frameworks - per-device certificates, certificate lifecycle, and secure key storage for authenticated device-to-cloud communication * Design secure OTA update architectures: signed and encrypted images, A/B partitioning, anti-rollback, and fail-safe recovery for the embedded fleet * Lead threat modeling (STRIDE) and risk assessments, defining attack surfaces, abuse cases, and mitigations for large embedded fleets * Secure cloud-to-device trust across Enphase platforms (e.g., app and cloud ecosystems) * Drive security integration across firmware, hardware, and cloud teams * Harden IoT communication protocols across BLE, Wi-Fi (802.11), Ethernet, and PLC/powerline interfaces * Define and enforce security-by-design standards and lead security architecture reviews across the embedded fleet ## Related Videos - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [The Gashlycrumb Tinies of AI Networking You Must Know (or Languish!)](https://www.wearedevelopers.com/videos/2067-the-gashlycrumb-tinies-of-ai-networking-you-must-know-or-languish) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Building your way to a serverless powered IOT Buzzwire game](https://www.wearedevelopers.com/videos/590-building-your-way-to-a-serverless-powered-iot-buzzwire-game) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)