Intelligent. Adaptive. Integrated.
Product Security Engineer
Location
Alaska + 1 moreAll locations: Alaska | California
Posted
5 days ago
Salary
$154K - $210K / year
Seniority
Lead
Job Description
Product Security Engineer
OKSI
• Lead threat modeling and security analysis across hardware, firmware, and software throughout the product lifecycle. • Produce threat matrices, risk assessments, and security requirements traceable through design reviews and release gates. • Own CVE tracking, vulnerability management, and security baseline compliance across the product portfolio. • Define and implement hardening standards for embedded Linux, RTOS, and bare-metal environments. • Establish code signing policies, secure boot chain integrity, and validation procedures. • Partner with IT and Engineering to architect and maintain the product signing and key management infrastructure using HSMs, KMS, or equivalent systems. • Own OKSI's anti-tamper posture aligned with DoD policy (DoDI 5200.39) and applicable Program Protection Plan requirements. • Define IP protection strategy spanning software binary protection, hardware design protection, firmware confidentiality, and cryptographically bound license enforcement. • Serve as OKSI's product security authority. • Establish company-wide standards, lead design reviews, provide security sign-off at program milestones, and embed security requirements into the Systems Engineering process. • Provide guidance and training to Engineering, IT, and Operations teams on secure design principles.
Job Requirements
- 7+ years of product security, embedded security, or cybersecurity systems engineering in a defense, aerospace, or advanced technology environment.
- Demonstrated expertise leading threat modeling, security risk assessments, and vulnerability analysis across hardware, firmware, and software domains — including production of threat matrices, attack surface analyses, and traceable mitigation plans.
- Hands-on experience defining and implementing security policies and standards (not just executing implementation tasks). You own the policy and architecture.
- Working knowledge of secure boot architectures, anti-tamper techniques, and embedded platform security (e.g., UEFI Secure Boot, ARM TrustZone, fuse-based root-of-trust).
- Practical experience with embedded Linux hardening: kernel configuration, module signing, RBAC/least-privilege access models, debug interface lockdown, and production credential management.
- Experience with key management infrastructure and signing pipelines (HSMs, KMS, or equivalent) for firmware, software releases, and factory provisioning workflows.
- Familiarity with DoD program protection and anti-tamper policy frameworks (DoDI 5200.39) and experience producing or reviewing Program Protection Plans (PPPs).
- Strong written and verbal communication skills for policy documentation, risk reporting, and cross-functional leadership.
Benefits
- Medical, dental, and vision coverage fully paid by the employer for employees
- Three weeks of vacation to start
- Automatic company contribution to 401K – 5% of earned wages (no matching required)
- Educational assistance and professional development opportunities
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Information Security Administrator
Nuvision Federal Credit UnionWelcome to Nuvision Credit Union. Helping our members build better lives for 90 years.
• Protect electronic information and infrastructure from external and internal threats. • Manage and configure security tools and technologies, including firewalls, intrusion detection systems, and antivirus software. • Analyze logs for suspect intrusion or attacks. • Oversee and support daily operations of security systems. • Monitor security incidents and alerts. • Conduct regular security assessments, audits, and risk analysis.
• Own and continuously improve the company’s information security and compliance program • Lead ISO 27001 implementation, certification readiness, and ongoing compliance initiatives • Conduct security assessments and risk evaluations across systems, endpoints, cloud environments, and networks • Design, implement, and maintain information security policies, procedures, and standards • Develop and lead incident response planning and coordinate security incident investigations • Manage Identity and Access Management (IAM), including access reviews and least privilege enforcement • Evaluate, implement, and maintain security technologies such as endpoint protection, SIEM, MFA, email security, and related tools • Conduct employee security awareness training and phishing simulation programs • Partner with IT leadership on infrastructure decisions while independently identifying and communicating security risks • Maintain audit readiness, compliance documentation, and security governance processes • Support ongoing improvement of regulatory compliance initiatives and security controls
• Participate in the development and implementation of information security strategies; • Conduct security assessments and provide recommendations; • Lead and support IT security audits; • Participate in penetration testing; • Develop, document, and maintain security policies and procedures; • Perform risk assessments and propose mitigation measures; • Monitor emerging threats and vulnerabilities; • Advise technology teams on security best practices; • Take part in security incident investigations and analysis; • Produce documentation, reports, and recommendations for stakeholders; • Facilitate workshops, meetings, and security awareness activities.
• Auditing key clients ranging from SMEs to Global super brands • Building great relationships with clients • Carrying out audits both on site and remotely • Auditing against ISO 27001 and ISO 22301 standards • Playing a pivotal role in improving clients' business performances




