Principal Platform Security Architect

NeurophosAustin, TX
$250,000 - $300,000Onsite

About The Position

We are seeking a Principal Platform Security Architect to own platform security across our electronic integrated circuit (EIC) and the wider T100 system. This is a product security role, not an IT or corporate security role. Hyperscale customers will not deploy an accelerator they cannot verify, so this position owns the machinery that makes our silicon verifiable: the root of trust, secure and measured boot, device attestation, signed firmware update, and security telemetry. The ideal candidate has shipped these subsystems on real silicon, can speak fluently to both RTL designers and firmware engineers, and knows the datacenter compliance landscape well enough to design toward it rather than retrofit for it. This role is the technical owner for our outsourced root-of-trust subsystem engagement.

Requirements

  • BS/MS/PhD in Computer Science, Electrical Engineering, or a related field.
  • 10+ years in hardware and firmware security architecture on silicon that shipped.
  • Hands-on experience integrating root-of-trust IP, including provisioning and fuse/OTP planning.
  • Secure boot chain design and firmware resiliency to NIST SP 800-193 class requirements.
  • Working knowledge of SPDM, DICE, MCTP (Management Component Transport Protocol), and PLDM (Platform Level Data Model).
  • Practical understanding of cryptographic primitives, key hierarchies, and secure key storage in silicon.
  • Demonstrated ability to write security specifications that digital design and firmware teams can implement against.
  • Excellent communication skills and comfort defending architectural decisions to external reviewers.

Nice To Haves

  • Familiarity with OCP Security profiles and Caliptra.
  • Side-channel and fault-injection countermeasure design.
  • FIPS or Common Criteria certification experience.
  • Experience supporting hyperscaler security review processes.
  • Background in confidential computing or trusted execution environments.
  • Post-quantum cryptography migration planning.
  • Experience with manufacturing-side provisioning flows and supply chain security.

Responsibilities

  • Own the platform threat model and the security architecture that answers it, from fab through field deployment.
  • Architect the silicon root of trust: RoT IP integration, key provisioning, fuse and one-time programmable (OTP) strategy, and debug authorization.
  • Define the secure and measured boot chain and firmware resiliency behavior.
  • Own device attestation using SPDM (Security Protocol and Data Model) with DICE (Device Identifier Composition Engine) identity.
  • Define signed over-the-air (OTA) firmware update with anti-rollback protection.
  • Specify security-relevant telemetry and its exposure to datacenter operators.
  • Drive compliance against OCP (Open Compute Project) security profiles and DMTF (Distributed Management Task Force) specifications.
  • Own the key management lifecycle and the associated manufacturing and field processes.
  • Serve as technical owner for the outsourced root-of-trust subsystem engagement.
  • Support customer and hyperscaler security reviews, and own the security narrative in those forums.
  • Partner with digital design, firmware, and systems teams to land security requirements in implementation.

Benefits

  • 100% coverage of base health plan premiums for you and your dependents, plus HSA contributions.
  • Unlimited PTO.
  • 401(k) matching and stock option opportunities.
  • Full suite of voluntary benefits, including Dental, Vision, Life, Hospital, Critical Illness, and Accident insurance.
  • Personalized Benefits. Choose the plans that fit your life and take the cash back for those that don’t.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service