Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI
Go @ 4
Python @ 4
Rust @ 4
Security @ 6
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Build hardware-rooted security foundations that protect sensitive AI workloads across hardware and software boundaries. The role focuses on firmware security, hardware trust, attestation, trusted execution environments, confidential computing, and protected workload execution. You will set technical direction and partner with hardware, firmware, systems, platform, and security engineering teams to solve complex security challenges at the foundation of the computing stack.
Responsibilities
- Set technical direction and own architecture for security capabilities spanning hardware, firmware, systems software, and protected workload execution.
- Design and build architectures for hardware-rooted trust, attestation, trusted execution environments, and hardware-backed isolation.
- Architect attestation capabilities that establish and verify trust across hardware, firmware, host, and workload boundaries.
- Partner with hardware, firmware, and systems engineers on platform integrity, secure and measured boot, device identity, and hardware-rooted security capabilities.
- Design security capabilities for protected workload execution throughout the workload lifecycle.
- Design secure approaches for cryptographic key material, credentials, identity, certificates, and provisioning within trusted computing environments.
- Shape security across the trusted compute infrastructure lifecycle, including provisioning, platform initialization, operation, and decommissioning.
- Lead threat modeling and security analysis across hardware, firmware, host software, and workload execution.
- Develop systems software, security tooling, and automation for reliable operation of hardware-backed security capabilities at scale.
- Lead security-sensitive designs across organizational boundaries and translate hardware and systems risks into practical engineering decisions.
- Establish technical patterns and influence security direction across hardware, firmware, systems, platform, and security engineering.
- Communicate trust models, security architecture, technical tradeoffs, and risks to engineers, technical leaders, and security leadership.
Requirements
- 6+ years of systems, firmware, hardware, or security engineering experience.
- Deep expertise in low-level systems security and experience with hardware-rooted trust, attestation, trusted execution environments, confidential computing, or related technologies.
- Experience setting technical direction and owning complex security architecture across multiple layers of the hardware and software stack.
- Understanding of roots of trust, platform integrity, secure or measured boot, device identity, and hardware-backed attestation.
- Experience designing or implementing attestation systems and reasoning about trust across hardware, firmware, host, and workload boundaries.
- Strong understanding of firmware and low-level systems security, boot chains, platform integrity, and hardware/software security boundaries.
- Strong understanding of cryptographic systems, key management, certificate lifecycle, secure credential management, and secure provisioning.
- Systems engineering experience developing low-level systems software, security tooling, firmware, or production automation in C, C++, Rust, Go, Python, or similar languages.
- Ability to threat model complex systems and reason about attacks spanning hardware, firmware, operating systems, infrastructure, and application workloads.
- Experience leading ambiguous, cross-functional technical initiatives and influencing engineering direction across specialized engineering disciplines.
- Ability to communicate complex trust models, security architecture, and technical risks clearly.
- Experience with firmware development or security, platform initialization, device security, hardware-backed security mechanisms, bare-metal lifecycle security, or large-scale compute environments is valuable.
- Experience integrating hardware-rooted trust, attestation, or confidential computing with infrastructure, identity, key-management, or workload systems is valuable.
Compensation
The total cash salary range is $341,400–$401,600, inclusive of potential bonus value. Placement depends on geographic location, experience, skills, and internal compensation standards. The range applies to candidates located in the United States. Groq also offers a Long-Term Incentive Program and employee benefits.
Additional Information
This position may require access to technology or information subject to U.S. export control laws and regulations. Candidates must meet applicable U.S. Person citizenship or residency criteria or qualify for an applicable export license. Groq is an Equal Opportunity Employer and provides reasonable accommodations.