Product Security Engineer
Position Overview
We are seeking a Product Security Engineer to own product-level security across OKSI's hardware and software systems. You will define and maintain the policies, standards, and architectural practices that protect our systems from design through field deployment. This is a strategic role requiring both the depth to establish security standards company-wide and the hands-on technical background to assess implementation and guide engineering teams.
What You'll Do
- Lead threat modeling and security analysis across hardware, firmware, and software throughout the product lifecycle. Produce threat matrices, risk assessments, and security requirements traceable through design reviews and release gates. Own CVE tracking, vulnerability management, and security baseline compliance across the product portfolio.
- Define and implement hardening standards for embedded Linux, RTOS, and bare-metal environments. Establish code signing policies, secure boot chain integrity, and validation procedures. Partner with IT and Engineering to architect and maintain the product signing and key management infrastructure using HSMs, KMS, or equivalent systems.
- Own OKSI's anti-tamper posture aligned with DoD policy (DoDI 5200.39) and applicable Program Protection Plan requirements. Define IP protection strategy spanning software binary protection, hardware design protection, firmware confidentiality, and cryptographically bound license enforcement.
- Serve as OKSI's product security authority. Establish company-wide standards, lead design reviews, provide security sign-off at program milestones, and embed security requirements into the Systems Engineering process. Provide guidance and training to Engineering, IT, and Operations teams on secure design principles.