Lead Principal Security Engineer
Job Description
Lead Principal Security Engineer for Oracle OCI, focusing on consulting for hardware security to ensure compute platforms meet security requirements and strengthen operational security posture.
Responsibilities
- Define hardware security requirements that align business needs and technology trends to support OCI security posture
- Provide independent design consulting for complex compute systems to balance business objectives with security risks and implement requirements from the hardware security team
- Advise on implementing features required to meet the security bar for complex compute systems
- Consult on secure operations for compute systems, including provisioning, re-use, and decommissioning aligned with the security posture
- Perform security assessments of complex compute systems to verify requirements are met
- Conduct adversarial assessments to confirm systems cannot be compromised
- Break down complex systems for analysis, assign parts to other team members, and collaborate to synthesize inputs into a holistic assessment contextualized to cloud environments
- Review business objectives and requirements, assess risk from findings and threat models, and identify appropriate risk mitigation controls
- Partner across teams to ensure requirements, findings, and recommendations are implemented inline with expected outcomes
- Communicate risks and mitigation options to senior leadership while balancing security, technology, and business goals
- Identify opportunities for security and process improvements and drive adoption across the organization
- Contribute individual research to advance state-of-industry security knowledge
- Track security subject-matter developments and educate both the business and security organizations
- Mentor junior engineers
Requirements
- Bachelor’s degree in Electrical Engineering, Computer Science, or related field (or equivalent experience)
- 10+ years of experience in hardware security architecture, engineering, validation, planning, or related work
- Demonstrated competency in hardware/firmware security
- Competency with computer architecture
- Subject matter expertise in two or more areas:
- Root Of Trust (TCG SRTM, DRTM)
- x86 (Intel, AMD)
- ARM server platform architecture
- UEFI
- GPU platforms, rackscale systems, clustering
- Baseboard Management Controllers
- SmartNICs (DPUs)
- Storage devices
- Security concepts and standards related to Attestation (example: SPDM), cryptography, Secureboot, DICE, etc.
- Ability to work with common programming languages: C, C++, Java, Python, Ruby, Go, Rust
- Ability to read and review complex hardware system and platform-level schematics for security concerns
- Experience using reversing tools and ability to reverse engineer
- Extensive research or experience with multiple classes of security bugs
- Experience specifying and/or designing hardware security features
Technologies
- TCG SRTM, TCG DRTM
- x86, Intel, AMD
- ARM server platform architecture, UEFI
- GPU platforms, rackscale systems, clustering
- Baseboard Management Controllers
- SmartNICs (DPUs)
- Storage devices
- Attestation, SPDM
- cryptography, Secureboot, DICE
- C, C++, Java, Python, Ruby, Go, Rust
- Intel SGX
- SPI, I2C, RS232-style serial
Preferred Qualifications
- Ability to read and understand x86 and/or ARM assembly language
- Knowledge of vendor-specific TEE technologies such as Intel SGX
- Familiarity with embedded communications interfaces: SPI, I2C, RS232-style serial
- Knowledge of host and network virtualization technologies and how to use them securely
- Knowledge of enterprise and/or datacenter networking architecture
- Experience operating in a large-scale DevOps or CI/CD environment
- Ability to write clear and concise product security requirements
- Ability to assess risk from findings and threat models and identify proper risk mitigation controls
- Ability to succeed individually or collaboratively, internally or with external organizations and individuals
- Significant experience working effectively in a large and distributed company
- Excellent organizational, verbal, and written communication skills
- Experience conducting training, thought leadership, conference talks, and publications