SlipstreamJobsFresh Startup & VC-Backed Jobs

Software Engineer, HSM Infrastructure Security, Consumer Devices

OpenAI - San Francisco, CA, United States - In-office - posted 2026-09-04

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

OpenAI is hiring a Security Software Engineer to design and implement hardware-backed security foundations for its device ecosystem. This role focuses on hardening the boundary between policy systems and HSMs (Hardware Security Modules) that protect sensitive cryptographic keys, determining which operations may be performed, what may be signed, and how policy changes are authorized. You will develop security-critical software and firmware within or adjacent to HSM trust boundaries. Depending on your background, this may include HSM trusted applications, firmware services, cryptographic mechanisms, device drivers, PKCS#11 components, secure-provisioning protocols, or signing-policy enforcement systems. This is a hands-on software-engineering role requiring you to design systems, write and review production code, debug across hardware and software boundaries, and carry projects from initial requirements through deployment. Key responsibilities include: - Design and implement security-critical software and firmware for HSMs, secure elements, trusted execution environments, and hardware roots of trust - Build and harden the policy-to-HSM boundary for certificate issuance and cryptographic signing operations - Develop HSM trusted applications, firmware components, host interfaces, device drivers, SDKs, or cryptographic service integrations - Implement cryptographic interfaces such as PKCS#11, OpenSSL providers, or platform key-storage APIs - Build firmware enforcing key generation, provisioning, usage, rotation, recovery, and destruction policies - Design HSM-backed certificate authority, code-signing, key-management, and device-identity systems - Develop end-to-end cryptographic protocols spanning devices, secure hardware, policy services, and backend infrastructure - Build security capabilities supporting device attestation, secure boot, factory provisioning, user registration, and authentication - Design controls making trusted software and policy changes verifiable, auditable, and subject to multi-party authorization - Write, review, test, and audit secure embedded software for resource-constrained environments - Develop test harnesses, emulators, fuzzers, and fault-injection tooling - Threat-model hardware and software trust boundaries - Partner with hardware, firmware, infrastructure, application, and security teams - Help establish engineering standards for HSM development, applied cryptography, and certificate infrastructure Minimum qualifications: 5+ years building secure embedded firmware for constrained environments; deep programming experience in C, C++, or Rust. Ideal candidates have strong track records designing, implementing, debugging, and shipping production systems software; hands-on experience developing security-critical software within HSMs, secure elements, TEEs, or hardware roots of trust; and expertise in applied cryptography, digital signatures, key hierarchies, and PKI.

Similar roles