← All open roles

H43 Β· Private information and trust

Hardware Security and Attestation Engineer

Give the private agent a trustworthy foundation beneath the operating system. You will connect device identity and boot integrity to usable security decisions.

Pilot expansionOffice-first9 cities

About the role

You give the private agent a trustworthy foundation beneath the operating system, connecting device identity and boot integrity to security decisions people can actually use. You will also be the person who explains what attestation does not prove, which is most of what people assume it does.

The work

Integrate supported roots of trust, protected key storage, measured boot and attestation. Evaluate TPMs, secure elements and trusted execution environments against a specific threat model. Coordinate provisioning, debug access and lifecycle changes with hardware and firmware teams.

What good looks like

In your first 90 days, demonstrate a platform-specific attestation or protected-key workflow and document the attacks it does and does not address.

Evidence we look for

Bring hardware security or low-level platform security experience. Explain why attestation does not prove that an agent's decision is correct or that all side channels are closed.

What we need to see

  • Hardware security or low-level platform security experience
  • You can explain why attestation does not prove an agent's decision is correct, nor that side channels are closed
  • Practical work with secure boot, device identity, or a trusted execution environment
  • You turn a hardware primitive into something a product decision can rest on

Nice to have

  • TPM, Secure Enclave, or TrustZone specifically
  • Side-channel research
  • Firmware security

The exercise

Design a policy for a device with a valid identity but an unexpected firmware measurement.

Where and how we work

In the office together five days a week, in any of these cities. Remote-friendly around your family, arranged one person at a time.