Senior Security Engineer, CPU and Platform Security Validation
SiFive Hsinchu, Taiwan
Semiconductor Manufacturing · 501-1,000 employees
About the role
The Senior Security Engineer will translate security architecture requirements into test plans and develop validation tests for CPU, firmware, and system-level security features. They will execute these tests across emulation, FPGA, and hardware platforms while driving root cause analysis for identified security issues.
What they look for
Requirements
Candidates must have a bachelor's or master's degree in a relevant engineering field and at least 5 years of experience in CPU, SoC, or platform security validation. Proficiency in Python, C/C++, and deep knowledge of hardware-assisted security features like Secure Boot and Root of Trust are required.
Full description
About SiFive
As the pioneers who introduced RISC-V to the world, SiFive is transforming the future of compute by bringing the limitless potential of RISC-V to the highest performance and most data-intensive applications in the world. SiFive’s unrivaled compute platforms are continuing to enable leading technology companies around the world to innovate, optimize and deliver the most advanced solutions of tomorrow across every market segment of chip design, including artificial intelligence, machine learning, automotive, data center, mobile, and consumer. With SiFive, the future of RISC-V has no limits.
At SiFive, we are always excited to connect with talented individuals, who are just as passionate about driving innovation and changing the world as we are.
Our constant innovation and ongoing success is down to our amazing teams of incredibly talented people, who collaborate and support each other to come up with truly groundbreaking ideas and solutions. Solutions that will have a huge impact on people's lives; making the world a better place, one processor at a time.
Are you ready?
To learn more about SiFive’s phenomenal success and to see why we have won the GSA’s prestigious Most Respected Private Company Award (for the fourth time!), check out our website and Glassdoor pages.
Job Description:
The Role We are seeking a Senior Security Engineer to validate CPU, firmware, and operating-system security across pre-silicon emulation platforms and post-silicon hardware. You will work directly with security architects and designers in France and collaborate with CPU design, firmware, software, and system validation teams.
Responsibilities
- Translate security architecture requirements into test plans, threat models, and coverage goals for system level validation purposes.
- Develop tests for CPU security features such as SVUKTE, TRNG, CFI, privilege separation, isolation, and memory protection.
- Validate Secure Boot, measured boot, TPMs, hardware Root of Trust, secure firmware update, key handling, and debug security.
- Execute tests on emulation, FPGA, and virtual platforms, or reproduce and debug issues on real chips.
- Localize failures across tests, firmware, operating systems, hardware, and architecture; drive issues to root cause.
- Develop automated validation tools and regression suites using scripting languages.
- Document evidence and communicate security risks, coverage, and debug results to global stakeholders.
Requirements Must Have
- Bachelor’s or master’s degree in computer engineering, electrical engineering, computer science, or equivalent experience.
- 5+ years of experience in CPU, SoC, firmware, platform security, or silicon validation.
- Strong CPU security knowledge, including SVUKTE, TRNG, CFI, privilege, isolation, and hardware-assisted security.
- Hands-on experience with Secure Boot, Root of Trust, TPMs, measured boot, secure firmware, or debug security.
- Strong Linux security and kernel-hardening knowledge.
- Experience developing security tests and debugging hardware/software failures.
- Proficiency in Python and C/C++; ability to read low-level code or assembly.
- Experience with pre-silicon emulation or FPGA platforms and post-silicon validation.
- Strong English communication skills and experience working across international teams.
Nice to Have
- RISC-V architecture and privilege-specification experience.
- Experience with Ghostwriter attacks, threat modeling, vulnerability analysis, fuzzing, fault injection, or side-channel testing.
- Experience with UEFI, Trusted Firmware-A, OpenSBI, U-Boot, or trusted execution environments.
Additional Information:
This position requires a successful background and reference checks and satisfactory proof of your right to work in:
Taiwan
Any offer of employment for this position is also contingent on the Company verifying that you are a authorized for access to export-controlled technology under applicable export control laws or, if you are not already authorized, our ability to successfully obtain any necessary export license(s) or other approvals.
SiFive is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
Similar roles
-
Application Security & IAM Engineer
Onwelo Kielce, Holy Cross Voivodeship, Poland
-
Senior Infrastructure & Network Security Engineer
Coopers Group AG Switzerland
-
Cybersecurity Business Development Manager (100 % remote) (m/f/d)
EWOR GmbH Karlsruhe, Baden-Württemberg, Germany
-
Application Security Engineer
Sitoo Stockholm, Stockholm County, Sweden
-
Junior Cybersecurity Architect - Categoria protetta L.68/99
BIP Consulting Rome, Lazio, Italy · €28K–€34K/yr
-
[EJV] Lead AI Safety & Security Engineer
Bosch Group Ho Chi Minh City, Ho Chi Minh, Vietnam