> Markdown version of [/jobs/ext/2702624-staff-firmware-engineer-platform-security](https://www.wearedevelopers.com/jobs/ext/2702624-staff-firmware-engineer-platform-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Firmware Engineer, Platform Security - **Company:** Also, Inc. - **Location:** Palo Alto, United States - **Experience:** Expert - **Salary:** $200,000.0 - $240,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Booting (BIOS), Cloud Computing, Cyber Security, Software Debugging, Embedded Software, Firmware, FreeRTOS, Hardware-In-The-Loop Simulation, Joint Test Action (IEEE Standards), Public Key Infrastructure, Real-Time Operating Systems, RSA (Cryptosystem), Runbook, Cloud Platform System, Information Technology, Bare Metal, U-Boot, IoT Security - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/staff-firmware-engineer-platform-security-also-9001734 ## About the Role * 8+ years in embedded software/firmware development, with deep ownership of secure boot, crypto, or vehicle/IoT security architecture, and a proven track record setting technical direction across multiple ECUs or products, not just one component * BS in an engineering discipline (Computer Science or Electrical Engineering preferred; MS or equivalent depth a plus) * Hands-on expertise with cryptographic primitives and embedded crypto (AES, ECC/RSA, HMAC, certificates) on constrained MCUs, including key provisioning, OTP/fuse programming, and HSM or secure element usage in production * Experience designing and shipping secure boot chains, bootloaders, signed firmware images, and OTA trust models in production * Experience securing vehicle or industrial networks (CAN/CAN-FD, authenticated messaging, secure diagnostics) is a strong plus * Expert-level C/C++ on bare-metal or RTOS (FreeRTOS, Zephyr, ThreadX, or similar), with deep comfort with linkers, memory maps, and debugging tools (JTAG/SWD) * Ability to wire signing and verification into CI/release pipelines and drive platform-wide adoption * Excellent communication skills - able to document security architecture, threat models, and runbooks, and mentor senior engineers; hardware-in-the-loop testing and emulation experience is a plus ## Description At ALSO, we are looking for a Staff Firmware Security Architect to set the technical direction for our vehicle firmware security platform - secure boot, cryptographic key lifecycle, network integrity, and trusted OTA. You'd own the end-to-end security architecture that protects every ECU across our product portfolio, make the hard cross-cutting calls that product teams build on, and partner with cloud, manufacturing, and firmware teams to make security practical in CI, on the bench, and in production. You'd raise the bar for the entire organization through design leadership, mentorship, and hands-on delivery of the most critical trust paths in the vehicle. What You'll Do * Secure boot & root of trust: define secure boot architecture across MCU families (ROM * bootloader * app) - image signing, verification, anti-rollback, and debug/JTAG lockdown for production - setting the standard other ECU teams adopt * Key storage & management: own the on-device and fleet key strategy (HSM/OTP/secure element), key hierarchy design, and integration with signing and PKI services across development, manufacturing, and field * Network & bus integrity: lead CAN/CAN-FD security design (authentication, integrity, encryption where required), and establish policies for protected diagnostics and secure UDS access platform-wide * OTA security: own end-to-end trust for firmware updates - signed/encrypted payloads, on-device verification, rollback safety, and secure handoff between cloud signing infrastructure and vehicle update flows * Platform security frameworks: architect reusable security libraries and APIs (crypto wrappers, secure storage, auth services) that product ECU teams adopt without reinventing trust * Threat modeling & hardening: lead threat models across boot, update, and network attack surfaces, and partner with product and cloud teams on security reviews and production readiness * Validation & cross-functional leadership: drive security test strategy (benchtop PoCs, negative tests, HIL scenarios), integrate critical checks into CI, mentor engineers on secure design, and align firmware, cloud, manufacturing, and systems stakeholders on requirements and trade-offs ## Related Videos - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) - [Cybersecurity for Software Defined Vehicles](https://www.wearedevelopers.com/videos/725-cybersecurity-for-software-defined-vehicles) - [3 Key Steps for Optimizing DevOps Workflows](https://www.wearedevelopers.com/videos/962-3-key-steps-for-optimizing-devops-workflows) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology)