
Principal Security Firmware Architect
ZT Systems2 hours ago
Taipei, TaiwanStaff+
Responsibilities
- Lead the architecture and design of secure embedded firmware solutions.
- Develop security microarchitectures using cryptographic techniques and protocols.
- Integrate security features into embedded systems and ensure alignment with industry standards.
- Conduct security assessments and threat modeling to identify and mitigate firmware vulnerabilities.
- Mentor junior engineers in secure firmware development and cryptographic implementation practices.
- Drive adoption of secure coding practices and static and dynamic code analysis tools.
- Collaborate with hardware teams to interpret board schematics and data sheets.
- Lead systems-management and security initiatives for data-center server components and management protocols.
- Implement Secure Boot, SPDM, Root of Trust, TCG DICE, and NIST 800-193 standards.
- Advance security features in BMCs and associated protocols with industry partners and stakeholders.
Requirements
- Bachelor's degree in Electrical Engineering, Computer Science, Computer Engineering, or a related technical discipline.
- 12+ years of BMC development experience, or 10+ years with a master's degree.
- Extensive embedded firmware development experience focused on security and cryptography.
- Deep knowledge of embedded protocols including I2C, I3C, SPI, USB, and PCIe.
- Experience developing both bare-metal and OS-based embedded firmware, including RTOS, embedded Linux, and U-Boot.
- Strong expertise in security microarchitecture, cryptographic algorithms, and protocols including PKI, SHA, ECC, HMAC, and AES.
- Experience identifying and addressing security vulnerabilities in embedded systems.
- Familiarity with static and dynamic code analysis tools such as Coverity.
- Knowledge of code composition tools such as Black Duck or equivalent is preferred.
- Ability to interpret complex board schematics and data sheets.
- Experience with data-center systems management, server components, and management protocols.
- Familiarity with Secure Boot, SPDM, Root of Trust, TCG DICE, and NIST 800-193.
- Experience with BMC, Redfish, PLDM, Yocto, and OpenBMC.
- Knowledge of FPGA security features is preferred.
- Strong communication, leadership, independent execution, and project-completion abilities.
Benefits
- Competitive base salary and performance-based annual bonus eligibility.
- 401(k) retirement savings plan and tuition reimbursement for eligible education programs.
- Medical, dental, and vision coverage, mental health resources, wellness support, and company-paid life and disability insurance.
- Paid time off, company-paid holidays, parental leave, and family-care support programs.
- Structured training, on-the-job learning, matching gifts, and volunteer programs.
- Benefits and eligibility vary by work location.