Principal Security Engineer
Job Description
Build stronger security foundations for cloud compute. As a Principal Hardware Security Engineer on Oracle Cloud Infrastructure, you will define and implement hardware security requirements that help ensure OCI compute hardware aligns with security posture and compliance needs. You will collaborate with Oracle teams, third-party vendors, and standards organizations to shape next-generation hardware platform security and strengthen operational security through both supply chain and operational requirements.
Onsite role in Nashville, TN with an emphasis on independent technical leadership, security validation, and cross-team execution.
Responsibilities
- Define hardware security requirements that align OCI security posture with business needs and evolving technology trends
- Provide independent design consulting to implement hardware security requirements within your area of expertise
- Provide independent design consulting to implement features needed to achieve the security bar
- Advise on security-aligned operations for provisioning, re-use, and decommissioning
- Perform security assessments of compute devices to verify requirements are met
- Conduct adversarial assessments to help ensure devices cannot be compromised
- Assess risk from findings and threat models, and identify appropriate risk mitigation controls
- Coordinate across teams to ensure requirements, findings, and recommendations are implemented
- Mentor junior engineers
Requirements
- Bachelor’s degree in Electrical Engineering, Computer Science, or a related field (or equivalent experience)
- 8-10+ years of experience in hardware security architecture, engineering, validation, planning, or a related area
- Demonstrated competency in hardware and firmware with a focus on security
- Competency with computer architecture
- Subject matter expertise in at least one area: Root Of Trust (TCG SRTM, DRTM), x86 (Intel, AMD), ARM server platform architecture, UEFI, GPU platforms, rackscale systems, clustering, Baseboard Management Controllers, SmartNICs (DPUs), or Storage devices
- Security concepts and standards related to Attestation (for example SPDM) and measurements, cryptography, Secureboot, and DICE
- Ability to work with common programming languages: C, C++, Java, Python, Ruby, Go, Rust
- Ability to read and review hardware schematics for security concerns
- Experience using reversing tools and ability to reverse engineer
Technologies
- TCG SRTM, TCG DRTM
- UEFI, SPDM, Secureboot, DICE
- C, C++, Java, Python, Ruby, Go, Rust
- Intel SGX
- SPI, I2C, RS232-style serial
Preferred Qualifications
- Ability to read and understand x86 and/or ARM assembly language
- Knowledge of vendor-specific TEE technologies such as Intel SGX
- Familiarity with embedded communications interfaces including SPI, I2C, and RS232-style serial
- Basic knowledge of enterprise and/or datacenter networking architecture
- Experience operating in a large-scale DevOps or CI/CD environment
- Ability to write clear and concise product security requirements
- Ability to assess risk from findings and threat models and identify risk mitigation controls
- Ability to succeed both independently and collaboratively with internal and external partners
- Experience working effectively in a large and distributed company
- Excellent organizational, verbal, and written communication skills