Job Summary
As a Principal Security Engineer and the designated Security Subject Matter Expert (SME), you will define the security architecture and strategy for our next-generation server platforms.
You will serve as the technical authority on Platform Root of Trust (RoT), firmware security, and supply chain integrity. In this high-impact role, you will look beyond individual components to orchestrate a comprehensive "Security-by-Design" approach, guiding engineering teams to implement industry-leading standards (NIST, OCP, TCG) and ensuring our platforms are resilient against advanced cyber threats,including future quantum computing risks.
Job Responsibilities
Security Architecture & Strategy
- Architectural Authority: Define the end-to-end secure boot flow and chain of trust hierarchy across BMC, BIOS, RoT, and peripheral devices.
- PQC Migration Strategy: Lead the strategic roadmap for Post-Quantum Cryptography (PQC)migration. Assess the impact of PQC algorithms (e.g., ML-KEM, ML-DSA) on boot time, memory constraints, and hardware accelerators in embedded environments.
- Protocol Governance: Mandate and guide the correct implementation of security protocols, specifically SPDM (Security Protocol and Data Model), MCTP, and PLDMfor device attestation and secure communication.
Risk Management & Compliance
- Threat Modeling: Lead detailed threat modeling sessions for new platforms to identify attack surfaces and prescribe mitigations.
- Vulnerability Management: Act as the lead for Product Security, assessing CVEs affecting OpenBMC/Linux kernel and driving remediation plans.
- Standards Alignment: Ensure product architecture aligns with TCG (Trusted Computing Group), OCP Security, and FIPS 140-3 requirements.
Leadership & Innovation
- Security Advocacy: Champion the adoption of memory-safe languages (e.g., Rust) and modern security practices within the firmware development lifecycle.
- Open Source Engagement: Represent the company in OpenBMC Security Working Groupsor OCP Security projects; drive upstream contributions for security enhancements.
- Mentorship: Provide expert consultation to Lead and Senior engineers in the BMC and RoT teams, reviewing critical security designs and code implementations.
Job Qualifications
Education & Experience
- Bachelor’s or Master’s degree in Computer Science, Electrical Engineering or related field.
- 10+ years of experience in embedded security, platform security, or firmware architecture.
- Proven track record of designing secure server platforms or embedded devices from concept to certification.
Technical Mastery (Principal Level)
- Cryptographic Expertise: Deep understanding of cryptographic algorithms (ECC, RSA, SHA, AES) and their application in hardware (TPM, HSM, Hardware RoT).
- Protocol Expert: Authoritative knowledge of SPDM (1.0/1.1/1.2), MCTP, Cerberus architectures, and TCGspecifications.
- Hardware Security: Strong knowledge of hardware security primitives: Physical Unclonable Functions (PUF), TrustZone, SGX, and side-channel attack mitigations.
Jabil, including its subsidiaries, is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, national origin, sex, sexual orientation, gender identity, age, disability, genetic information, veteran status, or any other characteristic protected by law.

