Select and justify the root-of-trust architecture for our compute chiplet, evaluating open-source silicon roots of trust against commercial alternatives, and deciding the integration mode and its gate-count and area consequences.
Specify everything the SoC must supply to support it: fuse and one-time-programmable infrastructure, unique device secret and identity derivation, security state and lifecycle signals, reset and power sequencing, mailbox interfaces, and streaming-boot transport.
Define the measured boot flow and the attestation model the device presents to a host.
Own secure debug: lock and authenticated unlock, lifecycle gating, and debug access across a multi-die package.
Write the security sections of the system architecture specification and hold them through design reviews.
Define manufacturing security provisioning — fuse programming, key injection and identity provisioning at the assembly and test house — and the audit evidence customers will ask for.
Work with our security IP vendors on integration requirements, and with our design-services partner on what the RTL must expose.
Define the verification collateral that proves the integration is correct, in partnership with the SoC verification team.
Answer customer security architecture questions directly, with authority.
Track and participate in the relevant open standards and consortium work.
Translate evolving customer and regulatory security requirements into roadmap input.
Qualifications & Skills
Bachelor's or Master's degree in Electrical Engineering, Computer Engineering, Computer Science, or a related field.
10+ years in silicon security architecture, hardware roots of trust, or secure SoC design.
Demonstrated ownership of a hardware root-of-trust integration that reached silicon.
Deep working knowledge of measured boot, device identity and attestation — DICE or equivalent — and of the difference between a specification and what it actually costs to integrate.
Practical experience with fuse and OTP infrastructure, physically unclonable functions or equivalent secret storage, entropy sources, and lifecycle state management.
Secure debug architecture: lock, authenticated unlock, and lifecycle gating.
Ability to hold a technical security conversation with a sophisticated customer and be believed.
Preferred Qualifications & Skills
Direct experience integrating an open-source silicon root of trust into a high-performance SoC.
Familiarity with attestation and device-identity standards, and with the consortium bodies that define them.
Post-quantum cryptography in hardware — signature and key-encapsulation accelerators, and side-channel countermeasures.