True Anomaly logo

True Anomaly

Principal Embedded Systems Security Engineer at True Anomaly

Denver, CO or Long Beach, CAFull-timeCybersecurityPosted 28 days ago
Apply with Pipeline

About the Role

<div class="content-intro"><p class="ms-outlook-mobile-reference-message">Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it.</p> <p class="ms-outlook-mobile-reference-message"><u>OUR MISSION</u></p> <p class="ms-outlook-mobile-reference-message">True Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors — enabling the U.S. and its Allies to secure the space environment and counter threats from the ultimate high ground.</p> <p class="ms-outlook-mobile-reference-message"><u>OUR VALUES</u></p> <ul> <li class="ms-outlook-mobile-reference-message"><strong>Be the offset.</strong><span class="Apple-converted-space">&nbsp;</span>We create asymmetric advantages with creativity and ingenuity.</li> <li class="ms-outlook-mobile-reference-message"><strong>What would it take?</strong>&nbsp;We challenge assumptions to deliver ambitious results.</li> <li class="ms-outlook-mobile-reference-message"><strong>It’s the people.</strong> Our team is our competitive advantage and we are better together.</li> </ul> <p><span style="text-decoration: underline;">BENEFITS &amp; PERKS</span>*</p> <ul> <li><strong>Best-in-class healthcare: </strong>100% company-paid medical, dental, and vision coverage for you and your dependents, with HSA/HRA options</li> <li><strong>Generous time off: </strong>Flexible Time Off (FTO) for exempt employees, accrued PTO of up to 25 days for non-exempt employees, plus 12 paid holidays; Parental Leave; Sick Leave</li> <li><strong>Fuel for your day: </strong>Daily catered lunch and unlimited snacks for in-office employees</li> <li><strong>And more: </strong>401(k) retirement plan, fitness reimbursement, and Dog Fridays</li> <li><strong>Equity participation: </strong>Equity is included as part of our total compensation package, giving you an opportunity to share in the company’s success.</li> </ul> <p>*Do not apply to fixed term and temporary roles</p></div><p><u>YOUR MISSION</u></p> <p class="p1">Embedded systems security for space operations poses unique challenges: remote systems that must operate in adversarial RF environments, resource-&nbsp;constrained hardware, and trade-offs between security and performance in real-time systems. As our Principal Embedded Systems Security Engineer,&nbsp;you'll own the security of our spacecraft, radio systems, and hardware platforms. You'll build security platforms and foundational services that enable our&nbsp;hardware and software teams to develop secure embedded systems by default.&nbsp;This role demands deep security expertise and the rigor that comes from engineering systems that cannot fail. As part of the Platform Security team, you'll&nbsp;work hands-on across C++ flight software, embedded C firmware within microcontrollers and radiation-hardened SoCs, FPGA designs, and real-time&nbsp;operating systems. Your work will impact the spacecraft's critical subsystems, from flight computer through command and control, RF, and payload. If&nbsp;you've secured systems where failure means loss of life or national security impact, you'll understand the constraints and rigor required here.&nbsp;This is a hands-on technical leadership role combining deep hardware security expertise with strong software engineering skills. You will write production&nbsp;code and build the tooling, test frameworks, and security validation platforms that harden our embedded systems at scale. You'll tackle novel security&nbsp;challenges that don't have an established playbook as we aim to set the standard for space-based security. In our AI-native environment, you'll use AI to&nbsp;accelerate your work and help solve the hard problems of embedded systems security.</p> <p class="p1"><em>This position requires the ability to obtain and maintain a security clearance.</em></p> <p class="p2"><strong>Responsibilities</strong></p> <ul> <li class="p1">Own the security architecture, threat modeling, and defensive controls for our spacecraft platform. This spans the flight computer, subsystem&nbsp;firmware, FPGA gateware, cryptographic implementations, and secure boot.</li> <li class="p1">Architect and build the security platforms, tooling, and foundational services that make secure-by-default the standard across flight software,&nbsp;firmware, and hardware configuration.</li> <li class="p1">Design and implement PKI for resource-constrained spacecraft, covering device authentication, firmware signing and verification, secure boot,&nbsp;lifecycle management, and secure key storage.</li> <li class="p1">Architect cryptographic and security implementations to meet stringent government standards, including FIPS 140-3, CNSA 2.0, and CCSDS</li> <li class="p1">Space Data Link Security (SDLS), and drive the migration to post-quantum cryptography across the platform.</li> <li class="p1">Secure the flight software build and deployment pipeline by hardening the tooling itself and protecting the supply-chain integrity of build outputs,&nbsp;dependencies, and third-party components.</li> <li class="p1">Secure our test environments against supply-chain attacks while keeping them representative of the flight security posture, so we can exercise on&nbsp;the ground the controls used to protect the spacecraft in orbit.</li> <li class="p1">Lead security assessments and penetration testing against our spacecraft, RF systems, and test environments.</li> <li class="p1">Drive the adoption of secure design practices across the organization, partnering with flight software, hardware, and test engineering teams to&nbsp;embed security into the full development and validation lifecycle.</li> <li class="p1">Tackle novel security challenges in space-based systems where established solutions don't exist, and stay ahead of emerging embedded and RF&nbsp;threats to proactively harden our systems.</li> <li class="p1">Use AI to move faster — accelerating development, analyzing security data, and closing technical knowledge gaps.</li> </ul> <p class="p2"><strong>Required Qualifications</strong></p> <ul> <li class="p1">Active security clearance, or the ability to obtain and maintain one.</li> <li class="p1">Deep, hands-on expertise in embedded, hardware, and firmware security — including hardware attack surfaces, side-channel and fault-injection&nbsp;attacks, firmware security, secure boot, and hardware security modules (HSMs).</li> <li class="p1">Strong software development skills in C and C++, plus solid engineering fundamentals (data structures, algorithms, API design, and debugging</li> <li class="p1">production systems) and comfort working across multiple languages and at low levels (assembly, firmware).</li> <li class="p1">Proven track record of building production security platforms, tooling, and foundational services used by hardware and embedded engineering&nbsp;teams.</li> <li class="p1">Deep, expert-level PKI knowledge with hands-on experience designing and operating PKI for embedded and resource-constrained systems —certificate-based device authentication, firmware signing certificate chains, secure boot PKI hierarchies, certificate provisioning and rotation for&nbsp;constrained devices (where rotation isn't trivial, e.g., spacecraft in orbit), secure key storage, and HSM integration.</li> <li class="p1">Expert-level applied cryptography: implementing and reasoning about cryptographic systems to stringent government standards (FIPS 140-3, and&nbsp;familiarity with CNSA 2.0 and CCSDS SDLS), and experience with the practical challenges of post-quantum cryptography migration. Strong&nbsp;familiarity with common NIST publications (e.g., the 800-series).</li> <li class="p1">Experience applying security testing methodologies for hardware and firmware, and building the tooling and frameworks to automate that testing&nbsp;at scale across engineering teams.</li> <li class="p1">Demonstrated principal-level impact: setting security strategy and technical direction across an organization, independently identifying and&nbsp;prioritizing the risks that matter most, driving hardening initiatives end to end, raising the security bar and mentoring other engineers, thriving on&nbsp;ambiguous and novel problems, and influencing and aligning teams without direct authority.</li> </ul> <p class="p2"><strong>Preferred Qualifications</strong></p> <ul> <li class="p1">Hands-on experience taking cryptographic modules through formal FIPS validation (CMVP), beyond implementing to the standard.</li> <li class="p1">Experience with real-time or safety-critical embedded systems — timing constraints, deterministic execution, interrupt handling, and the security&nbsp;implications of hard real-time requirements.</li> <li class="p1">Background in a regulated or high-assurance domain: aerospace, defense, avionics, medical devices, or industrial control systems.</li> <li class="p1">Hardware reverse engineering, firmware analysis, and cryptographic implementation experience.</li> <li class="p1">FPGA/VHDL security and RF/radio security.</li> <li class="p1">HIL/SIL test infrastructure and embedded Linux environments.</li> <li class="p1">Supply-chain security experience and a track record of hardening build pipelines for embedded/firmware systems.</li> <li class="p1">Cross-domain thinking that connects hardware security requirements to cloud infrastructure, network security, and system architecture.</li> <li class="p1">Evidence of practical, hands-on impact — published CVEs, security research or publications, conference talks, open-source contributions, or&nbsp;relevant projects</li> </ul> <p>&nbsp;</p> <ul> <li data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><strong><span data-contrast="none">Base Salary:&nbsp;</span></strong><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"> $225,000-$330,000</span></li> </ul> <ul> <li data-leveltext="" data-font="Symbol" data-listid="2" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><strong><span data-contrast="none">Equity + Benefits</span></strong><span data-contrast="none"> including Health, Dental, Vision, HRA/HSA options, PTO and paid holidays, 401K, Parental Leave</span><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:240}">&nbsp;</span></li> </ul> <p><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:240}"><em><span class="TextRun SCXW83253800 BCX0" lang="EN-US" data-contrast="none"><span class="NormalTextRun SCXW83253800 BCX0">Your actual level and base salary will be&nbsp;</span><span class="NormalTextRun SCXW83253800 BCX0">determined</span><span class="NormalTextRun SCXW83253800 BCX0"> on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education, location, and experience.</span></span></em><span class="EOP SCXW83253800 BCX0" data-ccp-props="{&quot;335559739&quot;:0}">&nbsp;</span></span></p> <p><strong>ADDITIONAL REQUIREMENTS</strong></p> <ul> <li><strong>Work Location</strong>—this role will be onsite at our Denver, CO or Long Beach, CA offices. The expectation is a minimum of 3 days per week in the office.</li> <li><strong>Work environment</strong>—the work environment; temperature, noise level, inside or outside, or other factors that will affect the person's working conditions while performing the job.</li> <li><strong>Physical demands</strong>—the physical demands of the job, including bending, sitting, lifting and driving.</li> </ul> <p><span class="TextRun SCXW267002851 BCX0" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW267002851 BCX0">This position will be open until it is successfully filled. To </span><span class="NormalTextRun SCXW267002851 BCX0">submit</span><span class="NormalTextRun SCXW267002851 BCX0"> your application, please follow the directions below.</span></span><span class="TextRun MacChromeBold SCXW267002851 BCX0" lang="EN-US" data-contrast="none"> <span style="color: rgb(0, 0, 0);"><strong><span class="NormalTextRun SCXW267002851 BCX0">#LI-Onsite</span></strong></span></span></p><div class="content-conclusion"><p>To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.</p> <p>True Anomaly is committed to equal employment opportunity on any basis protected by applicable state and federal laws. If you have a disability or additional need that requires accommodation, please do not hesitate to let us know.</p></div>