1

Firmware Security Engineer Jobs (NOW HIRING)

Proficiency in low-level programming (C, Rust, Assembly) and systems programming * Knowledge of firmware vulnerability assessment and threat modeling * Track record of designing security ...

Vertiv's Thermal business unit is seeking an Embedded Product Security Engineer to help protect the security and integrity of our embedded thermal firmware platforms and exposed system interfaces ...

You'll help create next-generation connected security solutions that will be installed in millions ... Work closely with lead engineers to develop firmware solutions for New Product Introductions (NPI ...

Showing results 21-40

Firmware Security Engineer information

See salary details

$75K

$167.4K

$205K

How much do firmware security engineer jobs pay per year?

As of Sep 10, 2026, the average yearly pay for firmware security engineer in the United States is $167,438.00, according to ZipRecruiter salary data. Most workers in this role earn between $143,000.00 and $205,000.00 per year, depending on experience, location, and employer.

What is a firmware security engineer?

Firmware Security Engineers are specialized professionals who focus on ensuring the security of firmware, which is the low-level software that controls hardware devices such as computers, embedded systems, and IoT devices. Their responsibilities include identifying vulnerabilities, developing security measures, conducting risk assessments, and implementing protective solutions to prevent unauthorized access or tampering. They work closely with hardware and software teams to integrate security features into the firmware development lifecycle. Their expertise is crucial in industries where device integrity and data protection are critical, such as automotive, telecommunications, and consumer electronics.

What are the key skills and qualifications needed to thrive as a firmware security engineer?

To thrive as a Firmware Security Engineer, you need a strong background in embedded systems, low-level programming (C, C++, Assembly), and a solid understanding of cybersecurity principles, typically supported by a degree in computer engineering or a related field. Familiarity with tools such as IDA Pro, Ghidra, JTAG debuggers, and certifications like CISSP or CEH are commonly required. Analytical thinking, attention to detail, and effective communication are standout soft skills for this role. These skills are crucial for identifying vulnerabilities, securing devices at the hardware-software interface, and collaborating with cross-functional teams to protect products from evolving threats.

What are some typical challenges firmware security engineers face when working with cross-functional teams?

Firmware Security Engineers often collaborate with hardware designers, software developers, and IT security teams, which can present challenges in aligning different technical priorities and communication styles. For instance, balancing the need for robust security with hardware performance constraints requires strong negotiation and problem-solving skills. Additionally, firmware security issues may not always be immediately apparent to other teams, so educating colleagues and advocating for secure practices is a key part of the role. Building strong relationships across departments is essential for implementing effective security solutions throughout the product lifecycle.

What cities are hiring for Firmware Security Engineer jobs?

Cities with the most Firmware Security Engineer job openings:

What states have the most Firmware Security Engineer jobs?

States with the most job openings for Firmware Security Engineer jobs include:

What are popular job titles related to Firmware Security Engineer jobs?

For Firmware Security Engineer jobs, the most frequently searched job titles are:

Infographic showing various Firmware Security Engineer job openings in the United States as of September 2026, with employment types broken down into 78% Full Time, and 22% Contract. Highlights an 100% In-person job distribution, with an average salary of $167,438 per year, or $80.5 per hour.

Staff Firmware Engineer, Platform Security

Palo Alto, CA • On-site

ALSO
201 - 500 employees

$200K - $240K/yr

Full-time

Medical, Dental, Vision, Retirement

Posted 26 days ago


Key responsibilities

  • Define and implement secure boot architecture, including image signing, verification, anti-rollback, and debug/JTAG lockdown for production.

  • Own the on-device and fleet key management strategy, including key hierarchy design and integration with signing and PKI services.

  • Lead the design of network and bus security, including CAN/CAN-FD authentication, integrity, encryption, and policies for protected diagnostics and secure UDS access.


Job description

About ALSO.

We’re ALSO, an electric mobility company originally conceived as a part of Rivian. We’re a passionate team of builders, dreamers, doers and innovators, focused on creating entirely new (not to mention, innovative and delightful) vertically integrated, small EVs designed to meet the global mobility challenges of today and tomorrow. Our mission is to inspire everyone to ride ALSO—replacing many local car, truck and SUV miles with ones on vehicles that are more affordable, more enjoyable and 10-50x more efficient.

At ALSO, we are looking for a Staff Firmware Security Architect to set the technical direction for our vehicle firmware security platform — secure boot, cryptographic key lifecycle, network integrity, and trusted OTA.

You'd own the end-to-end security architecture that protects every ECU across our product portfolio, make the hard cross-cutting calls that product teams build on, and partner with cloud, manufacturing, and firmware teams to make security practical in CI, on the bench, and in production. You'd raise the bar for the entire organization through design leadership, mentorship, and hands-on delivery of the most critical trust paths in the vehicle.

What You'll Do

  • Secure boot & root of trust: define secure boot architecture across MCU families (ROM → bootloader → app) — image signing, verification, anti-rollback, and debug/JTAG lockdown for production — setting the standard other ECU teams adopt

  • Key storage & management: own the on-device and fleet key strategy (HSM/OTP/secure element), key hierarchy design, and integration with signing and PKI services across development, manufacturing, and field

  • Network & bus integrity: lead CAN/CAN-FD security design (authentication, integrity, encryption where required), and establish policies for protected diagnostics and secure UDS access platform-wide

  • OTA security: own end-to-end trust for firmware updates — signed/encrypted payloads, on-device verification, rollback safety, and secure handoff between cloud signing infrastructure and vehicle update flows

  • Platform security frameworks: architect reusable security libraries and APIs (crypto wrappers, secure storage, auth services) that product ECU teams adopt without reinventing trust

  • Threat modeling & hardening: lead threat models across boot, update, and network attack surfaces, and partner with product and cloud teams on security reviews and production readiness

  • Validation & cross-functional leadership: drive security test strategy (benchtop PoCs, negative tests, HIL scenarios), integrate critical checks into CI, mentor engineers on secure design, and align firmware, cloud, manufacturing, and systems stakeholders on requirements and trade-offs

What You'll Bring

  • 8+ years in embedded software/firmware development, with deep ownership of secure boot, crypto, or vehicle/IoT security architecture, and a proven track record setting technical direction across multiple ECUs or products, not just one component

  • BS in an engineering discipline (Computer Science or Electrical Engineering preferred; MS or equivalent depth a plus)

  • Hands-on expertise with cryptographic primitives and embedded crypto (AES, ECC/RSA, HMAC, certificates) on constrained MCUs, including key provisioning, OTP/fuse programming, and HSM or secure element usage in production

  • Experience designing and shipping secure boot chains, bootloaders, signed firmware images, and OTA trust models in production

  • Experience securing vehicle or industrial networks (CAN/CAN-FD, authenticated messaging, secure diagnostics) is a strong plus

  • Expert-level C/C++ on bare-metal or RTOS (FreeRTOS, Zephyr, ThreadX, or similar), with deep comfort with linkers, memory maps, and debugging tools (JTAG/SWD)

  • Ability to wire signing and verification into CI/release pipelines and drive platform-wide adoption

  • Excellent communication skills — able to document security architecture, threat models, and runbooks, and mentor senior engineers; hardware-in-the-loop testing and emulation experience is a plus

The salary for this position ranges from $200,000 - $240,000 per year, depending on experience, qualifications, and location.

Perks & Benefits

  • Robust health coverage — excellent health, dental and vision insurance covered up to 100% by ALSO with FSA & HSA options

  • One Medical membership and dedicated insurance advocates

  • Rich fertility and family building benefits with Progyny

  • Flexible time off

  • 401(k) match

Why ALSO.

We’re passionate about helping the world find a better way to get there—wherever it is you’re headed.

We’re located in the heart of Silicon Valley and have brought together a world-class team from some of the biggest brands in the technology, automotive, cycling, outdoor recreation and retail spaces. 

Together we’re working hands-on to imagine, design and build an entirely new solution to a global set of transportation challenges.