Senior Staff Security Engineer at Form Energy — Berkeley, CA
Full job description
Role Description
As a Senior Product Security Engineer, you will operate as an elite individual contributor balancing hands-on systems software development (50%) with high-assurance threat modeling, protocol verification, and security design/analysis (50%). Reporting directly to the Security/Safety Architect, your primary objective will be to design, write, and rigorously verify the secure communication middleware and OTA update plans that run on our asset edge controllers. You will build deterministic, zero-trust architectures capable of maintaining total cryptographic integrity and operational resilience under active duress from highly sophisticated, nation-state level adversaries. You will be designing systems that have to remain secure for operational lifetimes of decades.
Relocation assistance is available.
What you'll do
- Secure Middleware Engineering (50%): Write clean, production-grade, and memory-safe systems code (C, C++, Rust) running directly on asset edge hardware and interfacing with onboard Hardware Security Engines (HSE) and Modules (HSM).
- Asynchronous Protocol Architecture: Evaluate, test, and adapt existing Delay-Disruption Tolerant Networking (DTN) standards; architect and implement custom transport wrapping where standard frameworks fall short under physical hardware constraints.
- Cryptographic Disruption Handling: Build defensive state machines that maintain absolute system integrity during prolonged network blackouts—specifically solving for offline replay prevention, asynchronous certificate validity management, key expiration limits, and secure local data-at-rest queuing.
- High-Assurance Analysis & Verification (50%): Apply rigorous static analysis, threat modeling, and formal verification methodologies to mathematically analyze cryptographic handshakes and communication boundaries, ensuring software cannot be forced into unverified failure states.
- Adversarial Threat Modeling: Design architectural and software boundaries tailored to withstand Advanced Persistent Threats (APTs) and nation-state actors targeting the bulk power system. Extend the product threat model to account for physical hardware tampering and supply-chain risk vectors.
What you'll bring:
- Cyber Security Qualifications:
- Security Architecture:
- 10+ years of experience in Cyber Security, including positions that require architect-level decisions.
- Demonstrated skill at architecting secure systems.
- Applied Cryptography: Practical expertise in symmetric/asymmetric cryptographic primitives, mutual TLS, secure session state management, and designing robust API boundaries for distributed edge-to-cloud systems.
- Application Security: 2+ years of Application Security experience (finding flaws in bespoke software)
- Security Engineering: 2+ years experience directly related to building security tooling
- Embedded Hardware Security: Direct experience implementing hardware root-of-trust, secure boot protocols, firmware signing, and writing code that interacts with HSMs, HSEs, or TPMs.
- Systems Programming: 5+ years of experience writing production-grade, optimized code in C, C++, or Rust
- High-Assurance Mindset: A track record of achieving security outcomes through rigorous software architecture, verification engineering, and clean code execution rather than policy compliance or automated compliance scanner management.
- Clearance Note: No active U.S. government security clearance is required for this role.
- Note: This is not an IT Security Governance, Risk and Compliance (GRC) role.
Preferred Qualifications:
- Prior experience designing high-assurance systems within the Aerospace, Defense, Financial, Semiconductor Security, High-Assurance Consultancies, or the Intelligence Community (IC) sectors.
- Embedded Programming within resource-constrained environments (embedded Linux, RTOS, or bare-metal targets).
- Exposure to network resilience strategies, store-and-forward mechanics, mesh topologies, or formal DTN protocol definitions (e.g., Bundle Protocol).
- Familiarity with the mathematical intent behind formal verification frameworks, protocol simulation tools, or abstract interpretation engines.
- Experience with Go inside modern cloud-scale data ingestion and optimization environments.
- Deep technical understanding of the engineering and defensive objectives that underlie critical infrastructure protections like NERC CIP, ISO 64423, NIST IR 7628, NIST SP 800-160v1/2
#LI-Onsite
Required skills
- next.js
- c++
- communication
- safe
- rust
- rest
- linux
- golang