CybersecurityJobs.io
← Back to all jobs
Groq

Sr. Staff Platform Security Engineer, Confidential Computing

San Francisco Bay Area, CA $341k - $402k/yr Full time Posted 32m ago

Job Description

The Sr. Staff Platform Security Engineer for Confidential Computing will develop hardware-rooted security foundations to safeguard sensitive AI workloads across both hardware and software boundaries. This role includes ownership of security architecture and technical direction across firmware, hardware trust, attestation, trusted execution environments (TEEs), and protected workload execution.

Responsibilities

  • Set technical direction and own the architecture for security capabilities across hardware, firmware, systems software, and protected workload execution.
  • Design and build security architectures for hardware-rooted trust, attestation, trusted execution environments, and hardware-backed isolation.
  • Architect attestation capabilities that establish and verify trust across hardware, firmware, host, and workload boundaries.
  • Partner with hardware, firmware, and systems engineers to shape platform integrity, including secure and measured boot, device identity, and other hardware-rooted security capabilities.
  • Design security capabilities to support protected workload execution while maintaining trust throughout the workload lifecycle.
  • Design secure approaches for cryptographic key material, credentials, identity, certificates, and provisioning within trusted computing environments.
  • Shape trusted compute infrastructure security across provisioning and platform initialization, operation, and decommissioning.
  • Lead threat modeling and security analysis across hardware, firmware, host software, and workload execution to identify systemic risks and drive durable mitigations.
  • Develop systems software, security tooling, and automation to ensure hardware-backed security capabilities are reliable and operable at scale.
  • Lead security-sensitive designs across organizational boundaries, translating hardware and systems risk into practical engineering decisions.
  • Establish technical patterns and influence security direction across hardware, firmware, systems, platform, and security engineering.
  • Partner across engineering and security to build capabilities that strengthen customer trust, platform reliability, and support compliance requirements.
  • Communicate trust models, security architecture, technical tradeoffs, and risk clearly to engineers, technical leaders, and security leadership.

Requirements

  • 6+ years of systems, firmware, hardware, or security engineering experience with deep expertise in low-level systems security and experience with hardware-rooted trust, attestation, trusted execution environments, confidential computing, or related technologies.
  • Demonstrated experience setting technical direction and owning complex security architecture across multiple layers of the hardware and software stack.
  • Deep expertise in firmware security, hardware-rooted trust, attestation, trusted execution environments (TEEs), protected workload execution, or closely related low-level security domains.
  • Strong understanding of hardware-rooted trust, including roots of trust, platform integrity, secure or measured boot, device identity, and hardware-backed attestation.
  • Experience designing or implementing attestation systems and reasoning about trust across hardware, firmware, host, and workload boundaries.
  • Strong understanding of firmware and low-level systems security, including boot chains, platform integrity, and security boundaries between hardware and software.
  • Strong understanding of cryptographic systems, key management, certificate lifecycle, secure credential management, and secure provisioning in trusted computing environments.
  • Strong systems engineering skills, including development experience in low-level systems software, security tooling, firmware, or production automation, with languages such as C, C++, Rust, Go, Python, or similar.
  • Ability to threat model complex systems and reason about attacks spanning hardware, firmware, operating systems, infrastructure, and application workloads.
  • Experience leading ambiguous, cross-functional technical initiatives and influencing engineering direction across specialized disciplines.
  • Ability to communicate complex trust models, security architecture, and technical risk clearly to different audiences.

Technologies

  • C
  • C++
  • Rust
  • Go
  • Python
  • confidential computing
  • trusted execution environments (TEEs)

Mission

  • Build hardware-rooted security foundations that protect sensitive AI workloads across hardware and software boundaries.
  • Set technical direction and build security capabilities spanning firmware security, hardware trust, attestation, trusted execution environments, and protected workload execution.
  • As a senior technical leader, work close to the hardware layer and partner across hardware, firmware, systems, platform, and security engineering to address complex security challenges at the foundation of the computing stack.

Location and Work Arrangement

This role is based in one of the hiring hubs: the Dallas, San Francisco, or New York City area. The selected candidate must be based in one of these areas.

Remote work flexibility is available while a local Groq office is established, with an expectation that the role will transition onsite once the office opens.

Benefits

  • Long-Term Incentive (LTI) Program
  • Robust suite of employee benefits

Compensation

  • Total cash salary range: USD 341,400 - 401,600 per year, inclusive of potential bonus value.
  • The range is specific to candidates located in the United States.
  • Compensation for international candidates will vary based on local market dynamics.
  • Groq provides competitive compensation through a Total Cash philosophy that incorporates potential bonus value directly into base pay.

Additional Notes

U.S. Job Posting: This position may require access to technology and/or information subject to U.S. export control laws and regulations, including the Export Administration Regulations (EAR). Candidates must qualify as U.S. Persons for export control purposes, or otherwise be eligible for an applicable export license.

Non-U.S. Job Postings: This position may require access to technology and/or information subject to U.S. export control laws and regulations, as well as applicable local laws and regulations, including the EAR. Candidates must meet all relevant export control eligibility criteria.

Groq is an Equal Opportunity Employer committed to inclusion and nondiscrimination, and it provides reasonable accommodations to qualified individuals with physical or mental disabilities ([email protected] for accommodation requests only). All offers are contingent upon verification of identity and employment authorization in accordance with federal law.

Groq encourages applicants with criminal record histories to apply in accordance with applicable fair chance act ordinances. Groq may use AI tools or automated systems to assist with reviewing applications, evaluating qualifications, scheduling interviews, analyzing assessment responses, or supporting recruiting operations. Hiring decisions are subject to human review. Candidates may request reasonable accommodations, an alternative evaluation process, additional information about AI use in hiring, or review of certain automated decisions by contacting [email protected].

Hiring Hub / Transition Expectation

  • Based in Dallas, San Francisco, or New York City area.
  • Flexible remote work while local office is established.
  • Transition to onsite expected once the office opens.

Similar Jobs