Software Engineer, HSM Infrastructure Security, Consumer Devices
OpenAI · San Francisco
About this role
**Software Engineer, HSM Infrastructure Security, Consumer Devices** **About the Role** Design and implement hardware-backed security foundations across OpenAI's device ecosystem. You'll develop security-critical software and firmware within HSM trust boundaries, hardening the policy-to-HSM boundary that authorizes cryptographic operations and policy changes. **Key Responsibilities** • Design and implement security-critical software/firmware for HSMs, secure elements, TEEs, and hardware roots of trust • Build and harden policy-to-HSM boundaries for certificate issuance and signing operations • Develop HSM trusted applications, firmware components, device drivers, SDKs, and cryptographic integrations • Implement cryptographic interfaces (PKCS#11, OpenSSL providers, platform key-storage APIs) • Build firmware enforcing key generation, provisioning, usage, rotation, and destruction policies • Design HSM-backed certificate authority and code-signing systems • Develop end-to-end cryptographic protocols spanning devices, hardware, and infrastructure • Build security capabilities for device attestation, secure boot, and authentication • Write, review, test, and audit secure embedded software • Develop test harnesses, emulators, and fuzzers to validate security properties • Threat-model trust boundaries and translate findings into engineering improvements • Partner across hardware, firmware, and security teams **Minimum Qualifications** • 5+ years building secure embedded firmware for constrained environments • Deep programming experience in C, C++, or Rust **Preferred Experience** • Track record designing, implementing, and shipping production systems software • HSM, secure element, TEE, or hardware root of trust development • HSM firmware, cryptographic mechanisms, device drivers, or PKCS#11 work • Applied cryptography, digital signatures, and key management expertise • PKI, X.509 certificates, and certificate lifecycle knowledge • Secure boot, device identity, or remote attestation experience • ARM TrustZone or commercial HSM platform experience (Thales, Entrust, AWS CloudHSM, etc.) • Device manufacturing, secure provisioning, or silicon bring-up background **About OpenAI** An AI research and deployment company dedicated to ensuring general-purpose AI benefits all of humanity. We are an equal opportunity employer.
Listing freshness
CronJobs last confirmed this listing 11h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.