OpenAI

Software Engineer, HSM Infrastructure Security, Consumer Devices

OpenAI
Apply
8 hours ago

Base Salary

$347k - $445k/yr

Responsibilities

  • Design and implement security-critical software and firmware for HSMs, secure elements, trusted execution environments, and hardware roots of trust.
  • Build and harden policy-to-HSM boundaries that authorize certificate issuance and cryptographic signing operations.
  • Develop HSM trusted applications, firmware components, host interfaces, device drivers, SDKs, middleware, and cryptographic service integrations.
  • Implement interfaces such as PKCS#11, OpenSSL providers or engines, platform key-storage APIs, and comparable hardware-security interfaces.
  • Build systems enforcing key generation, provisioning, usage, rotation, recovery, and destruction policies.
  • Design HSM-backed certificate authority, code-signing, key-management, device-identity, attestation, secure-boot, and provisioning systems.
  • Develop cryptographic protocols spanning devices, secure hardware, policy services, and backend infrastructure.
  • Write, review, test, and audit secure embedded software for resource-constrained environments.
  • Develop test harnesses, emulators, fuzzers, and fault-injection tooling to validate security properties and failure behavior.
  • Threat-model hardware and software trust boundaries and convert findings into engineering improvements.
  • Collaborate with hardware, firmware, infrastructure, application, security, and product teams.
  • Help establish engineering standards for HSM development, applied cryptography, secure key management, and certificate infrastructure.

Requirements

  • At least 5 years of experience building secure embedded firmware for constrained environments.
  • Deep programming experience in C, C++, or Rust.
  • A strong track record designing, implementing, debugging, and shipping production systems software.
  • Hands-on experience developing security-critical software or firmware within or directly adjacent to an HSM, secure element, trusted execution environment, or hardware root of trust.
  • Strong knowledge of applied cryptography, digital signatures, key hierarchies, secure key management, and cryptographic protocol design.
  • Experience with PKI, X.509 certificates, certificate authorities, certificate issuance, and certificate lifecycle protocols.
  • Familiarity with secure boot, measured boot, device identity, remote attestation, or hardware-backed storage.
  • Experience reasoning about concurrency, memory safety, privilege separation, hardware interfaces, failure modes, side-channel considerations, or physical attack considerations.
  • Ability to evaluate security designs and personally implement the software required to realize them.
  • Clear communication and cross-functional collaboration skills.
  • Helpful experience includes ARM TrustZone, commercial or cloud HSM platforms, PKCS#11, KMIP, OpenSSL providers or engines, secure-element APIs, platform-native key-storage frameworks, device manufacturing, silicon bring-up, firmware signing, anti-rollback, authenticated updates, cryptographic accelerators, custom silicon, multi-party authorization, tamper-resistant audit mechanisms, attestable policy systems, hardware-protected storage, and high-assurance production security software.

Tech Stack

OpenAI

About OpenAI

10,000+ employees

OpenAI builds and deploys large-scale AI models and tools—including ChatGPT, GPT-4–class models, DALL·E, and Whisper—sold via APIs and enterprise subscriptions to developers and businesses. It monetizes through usage-based API pricing and ChatGPT Plus/Team/Enterprise, and also reaches customers via Microsoft’s Azure OpenAI Service. Founded in 2015 and headquartered in San Francisco, it operates as a private partnership.

Contact me