SoC Security & Root-of-Trust Architect
IT
Portland, OR, USA · Austin, TX, USA
Posted on Sep 24, 2026
Responsibilities
- Select and justify the root-of-trust architecture for our compute chiplet, evaluating open-source silicon roots of trust against commercial alternatives, and deciding the integration mode and its gate-count and area consequences.
- Specify everything the SoC must supply to support it: fuse and one-time-programmable infrastructure, unique device secret and identity derivation, security state and lifecycle signals, reset and power sequencing, mailbox interfaces, and streaming-boot transport.
- Define the measured boot flow and the attestation model the device presents to a host.
- Own secure debug: lock and authenticated unlock, lifecycle gating, and debug access across a multi-die package.
- Write the security sections of the system architecture specification and hold them through design reviews.
- Define manufacturing security provisioning — fuse programming, key injection and identity provisioning at the assembly and test house — and the audit evidence customers will ask for.
- Work with our security IP vendors on integration requirements, and with our design-services partner on what the RTL must expose.
- Define the verification collateral that proves the integration is correct, in partnership with the SoC verification team.
- Answer customer security architecture questions directly, with authority.
- Track and participate in the relevant open standards and consortium work.
- Translate evolving customer and regulatory security requirements into roadmap input.
Qualifications & Skills
- Bachelor's or Master's degree in Electrical Engineering, Computer Engineering, Computer Science, or a related field.
- 10+ years in silicon security architecture, hardware roots of trust, or secure SoC design.
- Demonstrated ownership of a hardware root-of-trust integration that reached silicon.
- Deep working knowledge of measured boot, device identity and attestation — DICE or equivalent — and of the difference between a specification and what it actually costs to integrate.
- Practical experience with fuse and OTP infrastructure, physically unclonable functions or equivalent secret storage, entropy sources, and lifecycle state management.
- Secure debug architecture: lock, authenticated unlock, and lifecycle gating.
- Ability to hold a technical security conversation with a sophisticated customer and be believed.
Preferred Qualifications & Skills
- Direct experience integrating an open-source silicon root of trust into a high-performance SoC.
- Familiarity with attestation and device-identity standards, and with the consortium bodies that define them.
- Post-quantum cryptography in hardware — signature and key-encapsulation accelerators, and side-channel countermeasures.
- Multi-die and chiplet security: package-granular attestation, cross-die debug authorisation, known-good-die identity.
- Confidential computing and multi-tenant isolation on RISC-V or Arm.
- Experience defining manufacturing provisioning flows with an assembly and test partner.
- RISC-V security extensions and privileged architecture.
What We Offer
- Own the security architecture of a clean-sheet high-performance RISC-V product
- Competitive compensation & benefits package
- Collaboration with talented engineers passionate about cutting-edge CPU technologies.
- Opportunities for professional growth in an innovative, fast-paced environment
- A flexible and inclusive work culture