1X logo1X logo

Product Security Engineer - Cryptography & PKI

1XPalo Alto, California, United States
On-site Full-time $137.9K/yr - $240K/yr

Clicking Apply Now takes you to AutoApply where you can tailor your resume and apply.


Experience Level

Mid to Senior

Qualifications

Essential QualificationsExtensive experience in cryptography, PKI design, and key management. Proficient in working with hardware security modules (HSMs), including vendor selection, integration, and establishing a root of trust. Familiarity with remote device attestation frameworks (e.g., fTPM, OP-TEE, or similar technologies). Proven ability to design and scale secure firmware signing and code signing pipelines. Demonstrated experience in defining and enforcing trust policies (key generation, rotation, destruction) and provisioning mechanisms. Experience in securing build/artifact pipelines and developing secure communication protocols. Strong cross-functional collaboration skills with hardware, software, security operations, and infrastructure teams. Meticulous attention to detail, strong problem-solving skills, and a proactive approach to identifying vulnerabilities and designing resilient systems. Preferred QualificationsVendor-specific HSM credentials or labs (Thales, Utimaco, AWS CloudHSM). Experience with NVIDIA Orin or similar SoC platforms.

About the job

Product Security Engineer - Cryptography & PKI

Palo Alto, CA (on-site)

About 1X
At 1X, we are pioneering the development of humanoid robots that seamlessly collaborate with humans to address labor shortages and foster abundance in various industries.

The Role
As a Product Security Engineer with a focus on cryptography and PKI, you will be instrumental in creating and expanding the cryptographic framework that safeguards 1X's robots and their communications. Your expertise will play a critical role in ensuring trust, integrity, and sustained security throughout the company's hardware and software environments.

Your Responsibilities

  • Design and oversee comprehensive cryptographic services, including PKI and key lifecycle management.

  • Establish a robust HSM infrastructure to serve as the root of trust for firmware signing and IoT authentication.

  • Lead the assessment, selection, configuration, and integration of HSM vendor solutions.

  • Architect scalable key management systems to accommodate future needs.

  • Design remote device attestation solutions utilizing technologies such as fTPM or OP-TEE.

  • Create and automate secure pipelines for firmware and bootloader signing.

  • Define policies and infrastructure for author key provisioning, rotation, and destruction.

  • Secure build systems and implement code-signing workflows.

  • Develop architecture for factory provisioning, enabling mass key and certificate distribution.

  • Support the development of secure communication protocols.

  • Collaborate effectively with cross-functional teams, including Product Security, Cloud Infrastructure, Device Engineering, and SecOps.

About 1X

1X is at the forefront of robotics innovation, dedicated to creating humanoid robots that enhance productivity and address labor shortages, ultimately leading to a more abundant future for all.

Similar jobs

Browse all companies, explore by city & role, or SEO search pages.

Tailoring 0 resumes

We'll move completed jobs to Ready to Apply automatically.