Senior Product Security Engineer
About the role
We're looking for a senior/staff security engineer who is a genuine PKI expert, comfortable owning certificate lifecycle management end-to-end and who also brings solid platform/infrastructure experience. You'll help us run and modernize the systems that issue, provision, and manage digital identity for our products, with particular depth needed in charging standards (e.g., ISO 15118, OCPP) and authN/authZ standards (e.g., X.509, mTLS, OAuth2, OIDC).
Responsibilities
- Own PKI and certificate lifecycle management: design, issue, provision, renew, and revoke certificates across the systems you support; maintain trust stores and certificate authorities.
- Apply charging-standard expertise: work with EV charging PKI and protocols (e.g., ISO 15118 Plug & Charge, OCPP) to support certificate provisioning and interoperability for charging use cases.
- Design and implement authN/authZ: apply standards such as X.509, mTLS, OAuth2, and OIDC to secure service-to-service and client-facing authentication and authorization flows.
- Build and operate platform infrastructure: work with Kubernetes, service mesh, and workload identity technologies to move cert issuance and auth off bespoke one-off solutions and onto shared, reusable infrastructure.
- Support secure boot and key management: contribute to signature validation, key revocation, and related secure-provisioning workflows.
- Operate what you build: deploy, monitor, and support production services (GitOps deployment, observability/tracing), and be a responsive point of contact when certificate or auth issues arise.
- Document and mentor: write clear design docs and runbooks, and help other engineers ramp up on PKI and platform concepts.
Qualifications
- Core (must-have): 5+ years in security engineering with hands-on, production experience in PKI and certificate lifecycle management (issuance, provisioning, renewal, revocation).
- Strong grasp of public-key cryptography fundamentals: X.509 certificates, TLS/mTLS, HSM/TPM-backed key storage.
- Working knowledge of authN/authZ standards (X.509, mTLS, OAuth2, OIDC) and experience implementing them in production systems.
- Familiarity with EV charging PKI or charging communication standards (e.g., ISO 15118, OCPP), or comparable domain-specific PKI experience.
- Proficiency in at least one backend language (Go, Python, or similar) and experience building/operating production services.
- Strongly Preferred: Experience with service mesh and workload identity technologies (e.g., Istio, SPIRE/SPIFFE, Cilium/eBPF).
- Experience designing API gateway/ingress patterns for external or partner-facing traffic, including mTLS termination and identity-provider integration.
- Experience operating cloud infrastructure with strong observability practices (metrics, tracing, logging).
Benefits
We build the exceptional — and we believe the people doing that work should be rewarded accordingly. In addition to a competitive base salary, full-time positions may be is eligible to participate in our annual company performance bonus program. Payments are discretionary and not guaranteed; actual amounts depend on company results and the terms of the plan in effect, and require active employment at the time of payout. This role is also eligible for equity in the form of Restricted Stock Units (RSUs), subject to board approval and the terms of our equity incentive plans, including applicable vesting requirements. In addition to our compensation programs, we invest in our people with a comprehensive benefits package designed to support the health, wellbeing, and financial future for full-time employees — including health coverage, retirement savings, time off, and family planning programs. Offerings vary by country.