Axiado-posted 4 months ago
Full-time • Senior
San Jose, CA
101-250 employees

We are seeking an experienced Sr. Staff Firmware Engineer with deep expertise in Platform Firmware Resiliency (PFR) standard to lead the design, development, and optimization of secure firmware solutions that meet the required compliance standards. The ideal candidate will have hands-on experience with TPM, Firmware Signing, Attestation, and Root of Trust, and will be responsible for designing, implementing, and maintaining robust security solutions to protect hardware, firmware, and software integrity.

  • Own PFR architecture and implementation for multiple product lines.
  • Design and develop secure firmware modules that implement protections for BIOS, FPGA, BMC, and other critical platform firmware.
  • Integrate and validate hardware root-of-trust solutions (e.g., Intel PFR, TPM, cryptographic accelerators).
  • Implement firmware recovery mechanisms to restore integrity after detection of corruption or compromise.
  • Perform threat modeling and risk assessments specific to firmware-level attacks.
  • Develop test strategies for validating PFR capabilities, including attack simulation and penetration testing.
  • Ensure compliance with NIST SP 800-193 and relevant platform security guidelines.
  • Collaborate with cross-functional teams (hardware, BIOS, security, cloud) to ensure seamless integration of PFR features.
  • Mentor engineers in firmware security principles, secure coding practices, and resiliency design patterns.
  • Bachelor’s or Master’s degree in Computer Science, Electrical Engineering, or related field.
  • 20+ years of experience in embedded software development, with a strong background in C/C++.
  • Strong understanding of Platform Firmware Resiliency concepts and NIST SP 800-193 requirements.
  • Experience with secure boot, measured boot, and cryptographic verification of firmware.
  • Familiarity with UEFI/BIOS architecture, BMC firmware, and FPGA firmware update flows.
  • Hands-on experience with hardware root-of-trust solutions (e.g., Intel PFR, TPM 2.0).
  • Strong debugging skills, including use of JTAG, logic analyzers, and protocol analyzers.
  • Experience with Intel Server Platform Services (SPS) or similar management engines is a plus.
  • Familiarity with secure firmware update protocols (e.g., capsule updates, signed images).
  • Knowledge of supply chain security for firmware components.
  • Experience with Intel Server Platform Services (SPS) or similar management engines.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service