
Senior Staff Security Engineer
Form Energy, Inc7 hours ago
Base Salary
$170k - $223k/yr
Responsibilities
- Write production-grade, memory-safe C, C++, or Rust systems code for asset edge hardware.
- Design and implement secure communication middleware, OTA update plans, and custom transport wrappers for constrained hardware.
- Build defensive state machines for offline replay prevention, certificate validity management, key expiration, and secure local data-at-rest queuing.
- Apply static analysis, threat modeling, formal verification, and protocol analysis to cryptographic handshakes and communication boundaries.
- Develop security architectures addressing advanced persistent threats, physical tampering, and supply-chain risks.
- Evaluate and adapt Delay-Tolerant Networking standards and resilience strategies for energy infrastructure.
Requirements
- 10+ years of cybersecurity experience, including architect-level decision-making.
- Demonstrated ability to architect secure systems.
- Practical expertise with symmetric and asymmetric cryptography, mutual TLS, secure session state management, and distributed edge-to-cloud API boundaries.
- At least 2 years of application security experience and 2 years of experience building security tooling.
- Experience implementing hardware roots of trust, secure boot, firmware signing, and integrations with HSMs, HSEs, or TPMs.
- At least 5 years of production systems programming experience in C, C++, or Rust.
- Preferred experience with high-assurance systems in aerospace, defense, financial, semiconductor security, consulting, or intelligence environments.
- Preferred embedded programming experience with embedded Linux, RTOS, or bare-metal targets.
- Preferred familiarity with DTN, store-and-forward mechanics, mesh topologies, formal verification, protocol simulation, or abstract interpretation.
- Preferred experience with Go in cloud-scale data ingestion and optimization environments.
- Preferred understanding of NERC CIP, ISO/IEC 62443, NIST IR 7628, and NIST SP 800-160 security objectives.
- An active U.S. government security clearance is not required; this is not an IT Security GRC role.
Benefits
- Relocation assistance is available.
- The role is onsite.
- Full-time employees receive 100% coverage of medical, dental, and vision premiums, with 80% coverage for dependents, starting on day one.
- At least 12 weeks of paid leave is provided for new parents, up to 20 weeks for birthing parents.
- Generous vacation policies, stock options, and a holistic benefits package are offered.