> Markdown version of [/jobs/ext/1802483-lead-principal-security-engineer](https://www.wearedevelopers.com/jobs/ext/1802483-lead-principal-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Principal Security Engineer - **Company:** Oracle - **Location:** Washington, DC, United States (Remote available) - **Experience:** Expert - **Salary:** $130,000.0 - $306,400.0 - **Contract:** Permanent contract - **Skills:** C (Programming Language), Java (Programming Language), Computing Platforms, Assembly Language, C++ (Programming Language), Cloud Computing, Cluster Analysis, Continuous Integration, DevOps, Firmware, Hardware Platform Interface, Hardware Security Module, Python (Programming Language), Network Architecture, Network Virtualization, Oracle (Applications), Cloud Services, Ruby, Reverse Engineering, RS-232, Rust (Programming Language), Storage Devices, Extensible Firmware Interface, Serial Peripheral Interface, Information Technology, Oracle Cloud Infrastructure, Golang, Programming Languages - **Published:** July 1, 2026 - **Apply:** https://dejobs.org/x/x/FB64471560D0418087725658F46B9A12/job/ ## About the Role * Bachelor's degree in Electrical Engineering, Computer Science or related field or equivalent experience * 10+ years of experience in hardware security architecture / engineering / validation / planning or related area * Demonstrated competency in hardware/firmware with a focus on security * Competency with computer architecture * Subject Matter Expertise in two or more of the following areas: * Root Of Trust (TCG SRTM, DRTM) * x86 (Intel, AMD), ARM server platform architecture, UEFI * GPU platforms, rackscale systems, clustering * Baseboard Management Controllers * SmartNICs (DPUs) * Storage devices * Security concepts and standards associated Attestation (Ex: SPDM), cryptography, Secureboot, DICE etc. * Ability to work with most common programming languages (C, C++, Java, Python, Ruby, Go, Rust) * Ability to read and review complex hardware system/platform level schematics for security concerns * Experience with reversing tools and ability to reverse engineer * Extensive research or experience with multiple classes of security bugs * Specification and/or design of hardware security features Preferred Qualifications * Ability to read and understand x86 and/or ARM assembly language * Knowledge of vendor-specific TEE technologies such as Intel SGX * Familiarity with common embedded communications interfaces (SPI, I2C, RS232-style serial) * Knowledge of host and network virtualization technologies and how to use them securely * Knowledge of enterprise and/or datacenter networking architecture * Experience operating in a large-scale DevOps or CICD environment * Ability to write clear and concise product security requirements * Ability to effectively assess risk from findings and threat models and identify proper risk mitigation controls * Ability to succeed individually or collaboratively, whether working internally or with external organizations and individuals * Significant experience working effectively in a large and distributed company * Excellent organizational, verbal and written communication skills * Conducting training / thought leadership / conference talks / publications ## Description The Oracle Cloud Infrastructure (OCI) team can provide you the opportunity to build and operate a suite of massive scale, integrated cloud services in a broadly distributed, multi-tenant cloud environment. OCI is committed to providing the best in cloud products that meet the needs of our customers who are tackling some of the world's biggest challenges. As a Consulting Hardware Security Engineer you will be involved in ensuring that the compute hardware that is used in the Oracle Cloud Infrastructure meets the security bar to ensure compliance with our security posture. You will define security requirements for hardware ensuring hardware does not preclude inclusion of security controls essential to meet or exceed our posture. You will work closely across Oracle, with third party vendors, and with standards organization to influence the next generation of hardware platform security. You will also works closely with OCI's operations and engineering teams, constantly striving to improve Oracle Cloud's overall operational security posture by defining the supply chain and operational requirements to establish best practices for managing security for devices in our cloud infrastructure. Our consulting hardware security engineers have a blend of hardware, firmware and security skills, enabling them to help design and assess our most complex compute systems. Responsibilities Key Responsibilities * Definition of security requirements for hardware enabling OCI security posture aligning business needs and technology trends * Provide independent design consulting for complex compute systems, balancing business objective and security risks to implement: * requirements specified by the hardware security team * features required to achieve security bar * operations (provisioning, re-use, decommissioning) inline with security posture * Hands on * security assessments of complex compute systems to ensure they meets requirements. * adversarial assessments to ensure they can't be compromised. * Breakdown complex systems for analysis, assign parts to other members of the team, collaborate on synthesizing the inputs and forming a holistic assessment, contextualized to cloud environments * Understand business objectives/requirements and assess risk from findings/threat models and identify proper risk mitigation controls * Work across to teams to ensure requirements, findings and recommendations are implemented inline with expected outcomes * Communicate risks and options to mitigate to senior leadership, balancing security, technology and business goals * Identify opportunities for security and process improvements and drive them across the organization * Advance state of the industry security knowledge through individual research contribution * Follow developments and trends in their area of subject matter expertise and educate the business and security organization of the developments * Mentor junior engineers ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [An alternative approach to digital sovereignty: Confidential Computing](https://www.wearedevelopers.com/videos/100043-an-alternative-approach-to-digital-sovereignty-confidential-computing) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)