Groq is seeking a Sr. Staff Platform Security Engineer to build hardware-rooted security foundations that protect sensitive AI workloads across hardware and software boundaries. This role focuses on security architecture spanning firmware security, hardware trust, attestation, trusted execution environments, and protected workload execution.
Key Responsibilities
- Set technical direction and own architecture for security capabilities across hardware, firmware, systems software, and protected workload execution.
- Design and build security architectures for hardware-rooted trust, attestation, trusted execution environments (TEEs), and hardware-backed isolation.
- Architect attestation capabilities that establish and verify trust across hardware, firmware, host, and workload boundaries.
- Partner with hardware, firmware, and systems engineers to shape platform integrity, secure and measured boot, device identity, and other hardware-rooted security capabilities.
- Design security capabilities that enable protected workload execution while maintaining trust throughout the workload lifecycle.
- Design secure approaches for cryptographic key material, credentials, identity, certificates, and provisioning within trusted computing environments.
- Shape security for the lifecycle of trusted compute infrastructure, from provisioning and platform initialization through operation and decommissioning.
- Lead threat modeling and security analysis across hardware, firmware, host software, and workload execution to identify systemic risks and drive durable mitigations.
- Develop systems software, security tooling, and automation that make hardware-backed security capabilities reliable and operable at scale.
- Lead security-sensitive designs across organizational boundaries, translating complex hardware and systems risks into practical engineering decisions.
- Establish technical patterns and influence security direction across hardware, firmware, systems, platform, and security engineering.
- Partner across engineering and security to strengthen customer trust, platform reliability, and support compliance requirements.
- Communicate trust models, security architecture, technical tradeoffs, and risk to engineers, technical leaders, and security leadership.
Required Qualifications
- 6+ years of systems, firmware, hardware, or security engineering experience, with deep expertise in low-level systems security and experience with hardware-rooted trust, attestation, trusted execution environments, confidential computing, or related technologies.
- Demonstrated experience setting technical direction and owning complex security architecture spanning multiple layers of the hardware and software stack.
- Deep expertise in firmware security, hardware-rooted trust, attestation, trusted execution environments (TEEs), protected workload execution, or closely related low-level security domains.
- Deep understanding of hardware-rooted trust, including roots of trust, platform integrity, secure or measured boot, device identity, and hardware-backed attestation.
- Experience designing or implementing attestation systems and reasoning about trust across hardware, firmware, host, and workload boundaries.
- Strong understanding of firmware and low-level systems security, including boot chains, platform integrity, and security boundaries between hardware and software.
- Strong understanding of cryptographic systems, key management, certificate lifecycle, secure credential management, and secure provisioning in trusted computing environments.
- Strong systems engineering skills, including experience developing low-level systems software, security tooling, firmware, or production automation in languages such as C, C++, Rust, Go, Python, or similar languages.
- Ability to threat model complex systems and reason about attacks spanning hardware, firmware, operating systems, infrastructure, and application workloads.
- Experience leading ambiguous, cross-functional technical initiatives and influencing engineering direction across highly specialized engineering disciplines.
- Ability to communicate complex trust models, security architecture, and technical risk clearly to different audiences.
Valuable Experience
- Experience developing or securing firmware, platform initialization, device security, or hardware-backed security mechanisms.
- Experience integrating hardware-rooted trust, attestation, or confidential computing capabilities with higher-level infrastructure, identity, key-management, or workload systems.
- Experience with bare-metal lifecycle security or securing large-scale compute environments.
Mission
Build the hardware-rooted security foundations that protect sensitive AI workloads across hardware and software boundaries. Set technical direction and build security capabilities spanning firmware security, hardware trust, attestation, trusted execution environments, and protected workload execution.
Technologies
- C, C++, Rust, Go, Python
- Firmware security
- Hardware-rooted trust
- Attestation
- Trusted execution environments (TEEs)
- Protected workload execution
- Confidential computing
- Cryptographic key material
- Certificates
- Secure or measured boot
Location and Work Model
This role will be based in one of Groq’s three hiring hubs: the Dallas, San Francisco, or New York City area. The person hired for this role must be based in one of these three areas. There is flexibility to work remotely while the local Groq office is established, with the expectation that the role will transition to onsite once the office opens.
Compensation
Groq provides competitive compensation through a Total Cash philosophy, which incorporates potential bonus value directly into base pay. The total cash salary range for this position, inclusive of the potential bonus value, is $341,400 - $401,600 (United States only). Compensation for international candidates will vary based on local market dynamics. Beyond cash compensation, Groq offers a Long-Term Incentive (LTI) Program and a robust suite of employee benefits.
U.S. Export Control Notice
This position may require access to technology and/or information subject to U.S. export control laws and regulations, including the Export Administration Regulations (EAR). Candidates must qualify as U.S. Persons for export control purposes (U.S. citizen, U.S. lawful permanent resident (Green Card holder), or a protected individual under 8 U.S.C. § 1324b(a)(3) such as a refugee or asylee), or otherwise be eligible for an applicable export license.
Non-U.S. Export Control Notice
This position may require access to technology and/or information subject to U.S. export control laws and regulations, as well as applicable local laws and regulations, including the Export Administration Regulations (EAR). Candidates must meet all relevant export control eligibility criteria.