Jobs · Information Technology · California

Senior Staff Security Engineer

Form Energy · Berkeley, CA · 2 wk ago
On-siteInformation Technology$170k–$223k/yrFull-time

Are you ready to build America’s energy future? Form Energy is an American manufacturing and energy technology company revolutionizing energy storage with cost-effective, multi-day technology designed to keep the electric grid secure and reliable, even during extended periods of stress.

About the role

As a Senior Staff Product Security Engineer, you will operate as an elite individual contributor balancing hands-on systems software development (50%) with high-assurance threat modeling, protocol verification, and security design/analysis (50%). Reporting directly to the Security/Safety Architect, your primary objective will be to design, write, and rigorously verify the secure communication middleware and OTA update plans that run on our asset edge controllers. You will build deterministic, zero-trust architectures capable of maintaining total cryptographic integrity and operational resilience under active duress from highly sophisticated, nation-state level adversaries. Relocation assistance is available.

Responsibilities

  • Secure Middleware Engineering (50%):
    • Write clean, production-grade, and memory-safe systems code (C, C++, Rust) running directly on asset edge hardware and interfacing with onboard Hardware Security Engines (HSE) and Modules (HSM).
    • Asynchronous Protocol Architecture: Evaluate, test, and adapt existing Delay-Disruption Tolerant Networking (DTN) standards; architect and implement custom transport wrapping where standard frameworks fall short under physical hardware constraints.
    • Cryptographic Disruption Handling: Build defensive state machines that maintain absolute system integrity during prolonged network blackouts—specifically solving for offline replay prevention, asynchronous certificate validity management, key expiration limits, and secure local data-at-rest queuing.
  • High-Assurance Analysis & Verification (50%):
    • Apply rigorous static analysis, threat modeling, and formal verification methodologies to mathematically analyze cryptographic handshakes and communication boundaries, ensuring software cannot be forced into unverified failure states.
    • Adversarial Threat Modeling: Design architectural and software boundaries tailored to withstand Advanced Persistent Threats (APTs) and nation-state actors targeting the bulk power system. Extend the product threat model to account for physical hardware tampering and supply-chain risk vectors.

Requirements

  • Cyber Security Qualifications:
    • Security Architecture: 10+ years of experience in Cyber Security, including positions that require architect-level decisions.
    • Demonstrated skill at architecting secure systems.
    • Applied Cryptography: Practical expertise in symmetric/asymmetric cryptographic primitives, mutual TLS, secure session state management, and designing robust API boundaries for distributed edge-to-cloud systems.
    • Application Security: 2+ years of Application Security experience (finding flaws in bespoke software).
    • Security Engineering: 2+ years experience directly related to building security tooling.
    • Embedded Hardware Security: Direct experience implementing hardware root-of-trust, secure boot protocols, firmware signing, and writing code that interacts with HSMs, HSEs, or TPMs.
    • Systems Programming: 5+ years of experience writing production-grade, optimized code in C, C++, or Rust.
    • High-Assurance Mindset: A track record of achieving security outcomes through rigorous software architecture, verification engineering, and clean code execution rather than policy compliance or automated compliance scanner management.
  • Clearance Note: No active U.S. government security clearance is required for this role.
  • This is not an IT Security Governance, Risk and Compliance (GRC) role.

Preferred Qualifications

  • Prior experience designing high-assurance systems within the Aerospace, Defense, Financial, Semiconductor Security, High-Assurance Consultancies, or the Intelligence Community (IC) sectors.
  • Embedded Programming within resource-constrained environments (embedded Linux, RTOS, or bare-metal targets).
  • Exposure to network resilience strategies, store-and-forward mechanics, mesh topologies, or formal DTN protocol definitions (e.g., Bundle Protocol).
  • Familiarity with the mathematical intent behind formal verification frameworks, protocol simulation tools, or abstract interpretation engines.
  • Experience with Go inside modern cloud-scale data ingestion and optimization environments.
  • Deep technical understanding of the engineering and defensive objectives that underlie critical infrastructure protections like NERC CIP, ISO 64423, NIST IR 7628, NIST SP 800-160v1/2.

Benefits

  • Competitive salaries and stock options.
  • 100% coverage of medical, dental, and vision premiums for full-time employees—80% for dependents (effective from day one).
  • At least 12 weeks of paid leave for new parents (up to 20 weeks for birthing parents).
  • Generous vacation policies.

Pay

Compensation Range: $170,246 - $223,455

Similar jobs

Senior Security Engineer

K&L GatesAustin, TX· 3 wk ago
Information Technology$112k–$209k/yrapply on klgates.recsolu.com