Product Security Architect

Enphase Energy•Fremont, CA
•$160,000 - $226,000•Hybrid

About The Position

Enphase Energy is seeking a Product Security Architect to lead product security initiatives across its entire hardware portfolio, from silicon to cloud. This senior, hands-on role involves architecting and implementing security controls, ensuring compliance with regulations like the EU Cyber Resilience Act (CRA) and RED Delegated Act (2022/30), managing product security testing and certification, overseeing vulnerability management, and acting as the main technical contact for external penetration testers and security researchers. The role reports to the Head of Security and involves working cross-functionally with firmware, hardware, cloud, and product management teams. While not initially a management role, there is potential for growth to include direct reports as the program matures. The position requires a hybrid work model, with 3 days onsite per week, transitioning to a full 5-day in-office schedule over time.

Requirements

  • BE/BTech/MS/MTech in Computer Science, Electrical Engineering, Computer Engineering, or a related field
  • 12+ years of experience in product/embedded security, IoT security architecture, or security engineering for hardware products
  • Deep expertise in ARM security architecture: TrustZone (Cortex-A TEE/OP-TEE), TrustZone-M (Cortex-M), secure boot, chain-of-trust design, and hardware Root-of-Trust implementation
  • Hands-on experience with HSM/TPM/secure element integration, cryptographic key management (AES-128/256, RSA, ECC P-256/P-384), and hardware crypto accelerators
  • Strong knowledge of TLS 1.2/1.3, mutual TLS, X.509 PKI, certificate lifecycle management, and secure communication protocol design for constrained devices
  • Production experience with secure OTA update architectures: firmware signing, encrypted delivery, A/B partitioning, anti-rollback, and fleet-scale deployment
  • Direct experience driving product-level compliance with the EU Cyber Resilience Act and/or RED Delegated Act (2022/30) — technical files, conformity assessment, and engagement with notified bodies/test labs
  • Experience owning a vulnerability management/PSIRT function: CVSS scoring, CVE handling, coordinated disclosure, and remediation SLA management
  • Experience managing third-party penetration testing engagements end to end, and engaging directly with external security researchers
  • Proficiency in C/C++ for embedded systems — ARM Cortex-A (embedded Linux) and Cortex-M / 8051-class (bare-metal / RTOS) targets
  • Experience with compiler and binary hardening: stack protectors, PIE/ASLR, RELRO, CFI, and static/dynamic analysis tooling
  • Demonstrated ability to lead threat modeling exercises (STRIDE, attack trees) and translate findings into actionable architecture decisions
  • Working knowledge of IoT/embedded security standards: IEC 62443, ETSI EN 303 645, EU Cyber Resilience Act (Regulation 2024/2847), NIST SP 800-183
  • Strong cross-functional collaboration skills — ability to drive security outcomes across firmware, hardware, cloud, and product teams without direct authority

Nice To Haves

  • Experience securing powerline communication (PLC) protocols — HomePlug, G3-PLC, or proprietary PLC stacks
  • Experience with CAN bus security, automotive-grade secure boot, or BMS/battery management system security
  • Experience with manufacturing security provisioning: secure key injection, device identity enrollment, and factory line security at scale
  • Knowledge of side-channel analysis, fault injection, and hardware tamper resistance countermeasures
  • Experience with SBOM generation tooling (CycloneDX, SPDX) and software composition analysis for firmware
  • Familiarity with energy-sector regulations: NEK/IEC standards for energy equipment
  • Prior experience with security architecture for solar inverters, battery energy storage systems, or grid-edge devices
  • Prior people-management or team-lead experience, or demonstrated readiness to build and lead a small product security team
  • Relevant certifications: CISSP-ISSAP, GICSP (ICS security), OSCP, CCSP, or equivalent

Responsibilities

  • Architect and harden secure boot chains across the product portfolio, including signed bootloaders, anti-rollback counters, eFuse/OTP provisioning, and verified boot.
  • Design ARM TrustZone partitioning (TEE/OP-TEE) to isolate security-critical operations and firmware.
  • Audit and remediate JTAG/SWD debug interface exposure, ensuring fuse-based disable on production units and defining debug authentication policies.
  • Define the hardware Root-of-Trust architecture for future products, including secure elements, PUF-based device identity, and hardware crypto accelerators.
  • Own the end-to-end key lifecycle, from manufacturing provisioning to field rotation, revocation, and decommissioning for over 80 million devices.
  • Redesign PLC encryption key management for microinverters, migrating from hardcoded keys to per-site or per-device derivation and evaluating cipher replacements.
  • Build and maintain the mutual-TLS and PKI infrastructure for device-to-cloud authentication, including automated enrollment and lifecycle management.
  • Design key storage architecture using hardware-backed keystores to prevent software-only key storage.
  • Architect the secure OTA pipeline for the Enphase fleet, ensuring signed and encrypted firmware, A/B partitioning, anti-rollback enforcement, and fail-safe recovery.
  • Drive compiler-level hardening across the firmware build system, integrating into the CMake/Clang toolchain.
  • Establish firmware binary analysis as a release gate, including static analysis, SBOM generation, and known-vulnerability scanning.
  • Own end-to-end compliance with the EU Cyber Resilience Act, mapping requirements to controls, producing evidence, and managing technical files and CE-marking documentation.
  • Own compliance with the RED Delegated Act (2022/30) cybersecurity requirements, coordinating with notified bodies and test labs.
  • Plan and drive product security certification programs, including scoping, evidence packages, remediation, and audit readiness.
  • Track evolving global IoT/embedded security regulations and translate new requirements into engineering roadmaps.
  • Define and drive the product security test strategy across hardware, firmware, and protocol layers.
  • Build repeatable, release-gating security test suites in partnership with QA and firmware engineering.
  • Maintain a security test and certification calendar aligned with product release schedules.
  • Own the product vulnerability management program (PSIRT), including intake, scoring, CVE handling, remediation SLAs, and patch rollout.
  • Establish and run a coordinated vulnerability disclosure process.
  • Report on vulnerability posture and remediation status to leadership.
  • Serve as the primary technical point of contact for third-party penetration testing firms.
  • Manage relationships with independent security researchers and bug bounty channels.
  • Translate pentest and researcher findings into architecture and process improvements.
  • Lead product-level threat modeling (STRIDE/PASTA) for each hardware product family.
  • Define and maintain security architecture standards and design patterns for the embedded fleet.
  • Conduct security design reviews for all new product and feature development.
  • Harden the PLC (powerline communication) protocol stack, focusing on authentication, encryption, replay protection, and key exchange.
  • Secure all network interfaces on the IQ Gateway, eliminating unnecessary services and enforcing authenticated access.
  • Define security requirements for CAN bus communication and for BLE/Wi-Fi provisioning flows.

Benefits

  • Ownership of product security — architecture, testing, certification, and vulnerability management — for one of the world's largest deployed IoT energy fleets (80M+ devices)
  • Direct impact on global energy infrastructure security — your work protects millions of homes
  • Competitive compensation package with equity participation
  • Opportunity to shape Enphase's regulatory compliance posture for the EU CRA, RED Delegated Act, and emerging global IoT security regulations
  • Direct engagement with external researchers and pen test partners, with real influence over remediation priorities
  • Collaborative engineering culture with deep technical expertise in power electronics, embedded systems, and cloud platforms
  • Career growth in a high-visibility role reporting to the Head of Product Security, with potential to grow into a team-lead capacity
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service