1X

Product Security Engineer, Cryptography & PKI

Remote
USD 137k - 240k
C++ Rust Go Python Bash AWS
Description

Job description

Product Security Engineer, Cryptography & PKI

San Carlos, CA (on-site)

About 1X
We build humanoid robots that work alongside people to solve labor shortages and create abundance.

The Role
As a Product Security Engineer specializing in cryptography and PKI, you will build and scale the cryptographic infrastructure that secures 1X’s robots and communications. Your work will ensure trust, integrity, and long-term security across the company’s hardware and software systems.

You Will

  • Design and manage end-to-end cryptographic services, including PKI and key lifecycle management

  • Establish HSM infrastructure as the root of trust for firmware signing and IoT authentication

  • Lead the evaluation, procurement, configuration, and integration of HSM vendor solutions

  • Architect scalable key management systems for future growth

  • Design remote device attestation mechanisms leveraging technologies such as fTPM or OP-TEE

  • Build and automate secure pipelines for firmware and bootloader signing

  • Define infrastructure and policies for author key provisioning, rotation, and destruction

  • Secure build systems and code-signing workflows

  • Develop factory provisioning architecture for mass key and certificate distribution

  • Support secure communication protocol development

  • Collaborate with cross-functional teams including Product Security, Cloud Infrastructure, Device Engineering, and SecOps

Job requirements

Must Have

  • Strong experience with cryptography, PKI design, and key management

  • Experience working with hardware security modules (HSMs), including vendor selection, integration, and root‑of‑trust establishment

  • Familiarity with remote device attestation frameworks (such as fTPM, OP‑TEE, or similar)

  • Demonstrated ability to design and scale secure firmware signing and code signing pipelines

  • Proven track record in defining and enforcing trust policies (key generation, rotation, destruction) and provisioning mechanisms

  • Experience securing build/artifact pipelines and developing secure communication protocols

  • Ability to work cross‑functionally with hardware, software, security operations, and infrastructure teams

  • High attention to detail, strong problem solving, with a mindset of anticipating vulnerabilities and designing defendable systems

Nice to Have:

  • Vendor-specific HSM credentials or labs (Thales, Utimaco, AWS CloudHSM)

  • NVIDIA Orin or similar SoC platform experience

  • Background in post-quantum crypto evaluation and migration planning

  • Familiarity with large-scale factory provisioning tools (KMIP gateways, ACME/SCEP)

  • ProdSec/supply-chain security expertise (SBOMs, CI/CD hardening)

  • Experience in C/C++/Rust/GoLang (in addition to Python / Bash)

  • GoLang preferred

  • Additional security certifications

Benefits & Compensation

  • Salary Range: $137,861 – $240,000 + Equity

  • Health, dental, and vision insurance

  • 401(k) with company match

  • Paid time off and holidays

Equal Opportunity Employer
1X is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, ancestry, citizenship, age, marital status, medical condition, genetic information, disability, military or veteran status, or any other characteristic protected under applicable federal, state, or local law.

or

1X
1X

0 applies

0 views

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 452 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say