True Anomaly

Principal Embedded Systems Security Engineer

True Anomaly
Apply
6 hours ago
Denver, CO, USAStaff+

Base Salary

$225k - $330k/yr

Responsibilities

  • Own security architecture, threat modeling, and defensive controls for spacecraft, flight computers, subsystem firmware, FPGA gateware, cryptographic implementations, and secure boot.
  • Build security platforms, tooling, and foundational services that establish secure-by-default practices across flight software, firmware, and hardware configuration.
  • Design and implement PKI for device authentication, firmware signing and verification, secure boot, certificate lifecycle management, secure key storage, and constrained spacecraft devices.
  • Architect cryptographic and security implementations aligned with FIPS 140-3, CNSA 2.0, CCSDS Space Data Link Security, and post-quantum cryptography migration requirements.
  • Harden flight software build and deployment tooling and protect the supply-chain integrity of build outputs, dependencies, and third-party components.
  • Secure representative test environments and build automated hardware and firmware security testing frameworks at scale.
  • Lead security assessments and penetration testing for spacecraft, RF systems, and test environments.
  • Drive secure design practices across flight software, hardware, and test engineering teams throughout development and validation.
  • Set security strategy and technical direction, prioritize risks, lead hardening initiatives, mentor engineers, and influence teams without direct authority.
  • Use AI to accelerate development, analyze security data, and address embedded systems security challenges.

Requirements

  • Active security clearance or the ability to obtain and maintain one.
  • Deep hands-on expertise in embedded, hardware, firmware, hardware attack surfaces, side-channel attacks, fault-injection attacks, firmware security, secure boot, and hardware security modules.
  • Strong C and C++ development skills, with low-level programming experience including assembly and firmware.
  • Proven experience building production security platforms, tooling, and foundational services for hardware and embedded engineering teams.
  • Expert PKI experience for embedded and resource-constrained systems, including device authentication, firmware signing certificate chains, secure boot PKI hierarchies, certificate provisioning and rotation, secure key storage, and HSM integration.
  • Expert applied cryptography experience involving FIPS 140-3, CNSA 2.0, CCSDS SDLS, post-quantum cryptography migration, and NIST 800-series publications.
  • Experience applying hardware and firmware security testing methodologies and automating security testing across engineering teams.
  • Principal-level impact in setting security strategy, driving hardening initiatives, prioritizing risks, mentoring engineers, and solving ambiguous problems.
  • Preferred experience with formal FIPS validation through CMVP.
  • Preferred experience with real-time or safety-critical embedded systems and regulated or high-assurance domains such as aerospace, defense, avionics, medical devices, or industrial control systems.
  • Preferred experience in hardware reverse engineering, firmware analysis, FPGA/VHDL security, RF/radio security, HIL/SIL test infrastructure, embedded Linux, and embedded supply-chain security.
  • Preferred evidence of practical security impact such as published CVEs, security research, publications, conference talks, open-source contributions, or relevant projects.

Benefits

  • Base salary of $225,000-$330,000.
  • Equity and benefits including health, dental, vision, HRA/HSA options, PTO, paid holidays, 401K, and parental leave.
  • Hybrid work environment with some onsite work required; candidates must be located near Denver or Colorado Springs.
  • The position is open until successfully filled.
  • U.S. citizenship, lawful permanent residence, protected-individual status, or eligibility for required Department of State authorizations is required under ITAR regulations.

Tech Stack

AssemblyCC++
True Anomaly

About True Anomaly

201-500 employees

True Anomaly builds spacecraft and software for space defense, including autonomous satellites, precision-sensing payloads, mission command-and-control software, and space-based interceptors for national security and commercial operators. Founded in 2022 by former U.S. Space Force members, it is privately held and headquartered in Englewood, Colorado. The company sells hardware, AI-enabled flight software, and mission operations services to U.S. and allied defense programs and space infrastructure providers.

Contact me