Principal ASIC Design Engineer — SOC Security, Amazon Leo
Amazon San Diego, California, United States · $189K–$256K/yr
Software Development · 10,001+ employees
About the role
The Principal ASIC Design Engineer will define and own the end-to-end SOC security architecture for Project Kuiper's satellite communications. This includes architecting hardware root of trust, cryptographic subsystems, and secure manufacturing provisioning flows.
What they look for
Requirements
Candidates must have a bachelor's degree and over 15 years of experience in digital/SOC design or hardware security architecture. A deep understanding of cryptographic fundamentals and experience with high-volume production SOC security are required.
Benefits
Full description
Project Kuiper is an initiative to launch a constellation of Low Earth Orbit satellites that will provide low-latency, high-speed broadband connectivity to unserved and underserved communities around the world. Come work at Amazon! The Role Be part of Project Kuiper's sub-team responsible for defining and implementing the security architecture of digital chip SOCs for communications via Low Earth Orbit satellites and Amazon gateways. This is a unique opportunity to define a groundbreaking security solution for satellite communications with few legacy constraints. The team works with customer requirements, wireless system teams, and software teams to define SOC security architecture encompassing hardware root of trust, secure boot, cryptographic engines, key management, secure debug, and runtime protection—all in latest CMOS generation technologies. In this role, you will:
- Define and own the end-to-end SOC security architecture, producing a detailed security architecture document covering threat models, trust boundaries, and security requirements.
- Architect hardware root of trust (RoT) solutions including secure boot chain, hardware unique keys (HUK), and device identity/attestation.
- Define cryptographic subsystem requirements including symmetric/asymmetric engines, hash accelerators, true random number generators (TRNG), and key storage/management.
- Define ATE (Automatic Test Equipment) provisioning architecture, including secure key injection flows during manufacturing test, wafer-sort and final-test provisioning sequences, fuse/OTP programming procedures, and production-line security protocols to ensure device identity and credentials are securely programmed at scale.
- Specify secure debug and lifecycle management architecture (secure JTAG, device lifecycle states, provisioning flows).
- Define memory protection and isolation architectures (TrustZone, memory encryption, secure enclaves, firewall/access control policies).
- Drive firmware and software security requirements in collaboration with embedded software and systems teams, including secure firmware update (OTA) and anti-rollback mechanisms.
- Lead vendor selection and evaluation for security IPs (crypto cores, PUFs, secure elements, security subsystem IPs) and manage integration into the SOC.
- Conduct threat modeling and security risk assessments; define mitigations for side-channel attacks, fault injection, and other physical/logical attack vectors.
- Drive security certification and compliance activities (e.g., Common Criteria, FIPS 140-3) and ensure architecture meets relevant standards.
- Work with external vendors, IP providers, and certification bodies to ensure security targets are met.
- Drive trade-off analysis balancing security posture against performance, power, area, and cost constraints.
- Collaborate cross-functionally with SOC architects, RTL designers, firmware/software teams, and system-level security teams.
Export Control Requirement Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.
Basic Qualifications:
- Bachelor's degree in Electrical Engineering, Computer Engineering, Computer Science, or related field.
- 15+ years of experience in digital/SOC design or hardware security architecture.
- 5+ years of direct experience in SOC security architecture, hardware root of trust design, or security IP integration.
- Experience defining security architectures for high-volume production SOCs (communications, automotive, mobile, or computing domains).
- Deep understanding of cryptographic fundamentals (AES, RSA/ECC, SHA, HMAC, key derivation) and their hardware implementations.
- Experience with secure manufacturing provisioning flows, including ATE key injection, fuse/OTP programming, and production-line HSM integration.
- Experience with secure boot, secure debug, and device lifecycle management architectures.
Preferred Qualifications:
- Master's or Ph.D. degree in Electrical Engineering, Computer Engineering, or a security-focused discipline.
- Experience with security certification programs (Common Criteria, FIPS 140-3).
- Familiarity with Arm TrustZone, RISC-V security extensions, or equivalent TEE architectures.
- Experience with side-channel attack analysis and countermeasure implementation.
- Experience leading or contributing to SOC tapeout, with understanding of security integration milestones across the full chip development lifecycle (RTL freeze, netlist signoff, GDS).
- Familiarity with ATE provisioning tools and flows (e.g., Teradyne, Advantest), HSM-based key injection systems, and secure manufacturing audit/traceability requirements.
- Experience with PUF (Physically Unclonable Function) technology and hardware-bound key generation.
- Familiarity with Post-Quantum Cryptography (PQC) algorithms (e.g., ML-KEM, ML-DSA, SLH-DSA) and their hardware implementation considerations, including crypto-agility architecture for future algorithm migration.
- Experience leading security reviews, threat modeling (STRIDE/DREAD), and red-team exercises for silicon.
- Strong written and verbal communication skills; ability to produce clear security architecture documents for cross-functional audiences.
- Proven track record of innovation in hardware security; patents or publications in the security domain a plus.
- Ability to work effectively with cross-functional teams, including external vendors, IP providers, and certification bodies.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, CA, San Diego - 189,400.00 - 256,200.00 USD annually USA, TX, Austin - 189,400.00 - 256,200.00 USD annually