> Markdown version of [/jobs/ext/2309484-principal-engineer-firmware-security](https://www.wearedevelopers.com/jobs/ext/2309484-principal-engineer-firmware-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Engineer, Firmware Security - **Company:** Micron Technology, Inc. - **Location:** Longmont, CO, United States - **Experience:** Expert - **Salary:** $161,000.0 - $318,000.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Artificial Intelligence, Static Program Analysis, Code Review, Cyber Security, Continuous Integration, Learning Management Systems, Software Debugging, Programming Tools, Embedded Software, Federal Information Processing Standards (FIPS), Firmware, Flash Memory, Field-Programmable Gate Array (FPGA), Fuzz Testing, Joint Test Action (IEEE Standards), Python (Programming Language), Key Management, PCI Express, Public Key Infrastructure, Real-Time Operating Systems, Sed (Programming Language), Software Security, Cyber Threat Analysis, Data Management, U-Boot, Software Version Control, Nvme, Vulnerability Analysis - **Published:** August 30, 2026 - **Apply:** https://www.juju.com/job/00000000gpsman ## About the Role + Bachelor's degree in Electronics Engineering, Embedded Systems, Cyber Security, or a related field + 10+ years of experience in security firmware development + Hands-on experience with applied cryptography and firmware security: data encryption (AES-XTS), Root of Trust, Secure Boot, Device Attestation, TRNG/DRBG, Key Management, and Public Key Infrastructure + Post-quantum cryptography expertise (LMS, ML-DSA, ML-KEM) and understanding of their embedded system constraints + Knowledge of enterprise storage security standards (PCIe, NVMe, OCP, TCG, IEEE 1667, DMTF SPDM) + Proficiency in C and Python for firmware development Preferred Qualifications + Master's degree or Ph.D. in Electronics Engineering, Embedded Systems, Cyber Security, or a related field + Experience debugging firmware on SoC, FPGA, and simulation platforms; ability to resolve security protocol compatibility issues using JTAG, memory dumps, and bus analyzers + Experience with Rust for firmware development + Familiarity with AI-assisted developer tools for coding, testing, and code review (with human validation) + Agile and SDL expertise including version control, code reviews, CI/CD, threat modeling, fuzz testing, and static/dynamic code analysis + Technical leadership experience in security firmware architecture and multi-functional execution + Embedded firmware experience with controller initialization, boot/update processes, RTOS, IPC, and NAND Flash management + Participation in industry standards groups (TCG, OCP, DMTF, PCI-SIG) + Experience with Caliptra Root of Trust and OCP L.O.C.K. integration ## Description As a Principal Security Firmware Engineer on Micron's enterprise SSD team, you will design and develop security features that protect next-generation storage products against evolving cybersecurity threats. You will architect and implement cryptography-based solutions - including data encryption, Root of Trust, Secure Boot, Device Attestation, and Self-Encrypting Devices (SED) - while leading the transition to post-quantum cryptography for future product generations. This role spans the full Security Development Lifecycle, from threat modeling and architecture through implementation, testing, and certification. You will work across SoC, FPGA, and simulation platforms and collaborate cross-functionally to deliver security solutions aligned with industry standards including OCP, TCG, NVMe, and PCIe. Responsibilities + Design and develop security features for Micron enterprise SSDs, protecting against cybersecurity threats across the product lifecycle + Architect, implement, and debug cryptography-based security solutions including data encryption, Root of Trust, Secure Boot and Update, Device Attestation, and Self-Encrypting Devices (SED) + Lead the transition to post-quantum cryptography algorithms (LMS, ML-DSA, ML-KEM) for next-generation products + Implement security protocols aligned with OCP, TCG, NVMe, and PCIe specifications + Debug security firmware on SoC, FPGA, and simulation platforms using tools such as JTAG, memory dumps, and bus analyzers + Drive the Security Development Lifecycle including architecture, threat modeling, security code review, fuzz testing, vulnerability testing, FIPS certification support, and OCP S.A.F.E. compliance + Collaborate cross-functionally with firmware, hardware, and product teams to ensure security requirements are met from design through production ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [When Agents Meet Legacy: Never Change a Running System](https://www.wearedevelopers.com/videos/100320-when-agents-meet-legacy-never-change-a-running-system) - [This Machine Ends Data Breaches](https://www.wearedevelopers.com/videos/574-this-machine-ends-data-breaches) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 188: CfP time, the risks of NPM and IKEA algorithms](https://www.wearedevelopers.com/magazine/635-dev-digest-188-cfp-time-the-risks-of-npm-and-ikea-algorithms) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Dev Digest 105 - Security First](https://www.wearedevelopers.com/magazine/393-dev-digest-105-security-first)