> Markdown version of [/jobs/ext/1467971-software-security-engineer](https://www.wearedevelopers.com/jobs/ext/1467971-software-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Security Engineer - **Company:** Castelion Corporation - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** User Authentication, C++ (Programming Language), Computer Engineering, Linux, Digital Signature, Distributed Systems, Cryptographic Protocols, Firmware, Key Management, Public Key Infrastructure, Software Engineering, Systems Architecture, Systems Integration, Real Time Systems, Software Security, Safety Critical Systems, Information Technology, U-Boot - **Published:** July 28, 2026 - **Apply:** https://www.dice.com/job-detail/134bc80d-040c-4972-aaa6-9e884ef9b175 ## About the Role * Bachelors degree in Computer Science, Computer Engineering, Electrical Engineering, or related STEM field * 3+ years of professional experience in software engineering with exposure to applied cryptography or security engineering * Experience implementing encryption, authentication, or digital signature systems in C, C++, Rust, or similar systems languages * Strong understanding of cryptographic fundamentals (PKI, TLS, key exchange, hashing, signatures) * Experience working in Linux-based or embedded environments Preferred Skills and Experience * Experience implementing secure boot or hardware root-of-trust mechanisms * Experience with code signing pipelines and artifact verification * Familiarity with TPMs, HSMs, or secure elements * Experience in embedded, aerospace, defense, or other safety-critical systems * Experience designing secure provisioning workflows in manufacturing environments * Understanding of real-time systems and resource-constrained devices * Experience with mTLS, certificate lifecycle management, and replay protection mechanisms Leadership Qualities * Bias to Action and Creative Problem Solving. Desire and experience questioning assumptions in ways that lead to break through ideas that are ultimately implemented. Successfully bring in applicable processes/concepts/materials from other industries to achieve efficiency gains. Ability to personally resolve minor issues in development without requiring significant support. * High Commitment, High Initiative. A successful candidate will have a genuine passion for Castelion's mission and consistently look for ways to contribute to the company's technical goals and prevent hardware blockers. Ability to work in a fast paced, autonomously driven, and demanding atmosphere. Strong sense of accountability and integrity. * Clear Communicator. Proactively communicates blockers. Trusted in previous roles to be voice of company with regulators, suppliers, gate keepers and customers. Capable of tactfully managing relationships with stakeholders to achieve company-desired outcomes without compromising relationships. Emails, IMs and verbal interactions are logical, drive clarity, and detailed enough to eliminate ambiguity. ## Description As a Senior Software Security Engineer at Castelion, you will architect and implement the cryptographic foundations that secure our flight systems. You will own encryption, code signing, secure boot, and key management across embedded platforms, ensuring the integrity, authenticity, and confidentiality of mission-critical systems. You will work closely with embedded, avionics, and infrastructure engineers to integrate security directly into the full software and hardware stack from manufacturing provisioning through flight operations. We seek engineers who think in systems, understand threat models deeply, and can translate cryptographic principles into practical, resilient implementations in constrained environments. Responsibilities * Secure Boot & Root of Trust: Design and implement secure boot chains, hardware-backed root of trust mechanisms, and firmware verification processes for embedded flight systems. * Cryptography & Encryption: Develop and integrate cryptographic protocols and libraries (e.g., symmetric/asymmetric encryption, key exchange, digital signatures) for embedded and distributed systems. * Code Signing & Update Security: Own software signing infrastructure and verification workflows to ensure authenticity and integrity of firmware, flight software, and field updates. * Key Management & Provisioning: Design secure key generation, storage, rotation, and provisioning systems across development, manufacturing, and deployed environments. * Secure Communications: Implement and review authenticated and encrypted communication channels between vehicle, ground systems, and internal subsystems. * Threat Modeling & Hardening: Conduct threat modeling and security reviews across the software stack. Identify vulnerabilities and implement practical mitigations aligned with mission constraints. * Cross-Functional Integration: Partner with embedded, avionics, hardware, and infrastructure teams to embed security principles into system architecture from initial design through deployment. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Securing your application software supply-chain](https://www.wearedevelopers.com/videos/468-securing-your-application-software-supply-chain) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Top Characteristics of a Software Engineer](https://www.wearedevelopers.com/magazine/166-top-characteristics-of-a-software-engineer) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [What is Software Engineering?](https://www.wearedevelopers.com/magazine/289-what-is-software-engineering)