OnLogic

industrial computing

FirmwareSecurityEngineer

$100–120k Cary, North Carolina, United States; South Burlington, Vermont, United States FULL TIME
The Brief

“Firmware Security Engineer at OnLogic. Skills: Firmware Security Engineering, vulnerability management, UEFI security standards, embedded systems security. lead vulnerability management and firmware/software coding tasks for various UEFIIOS, BMC, and microcontroller (MCU) applications. collaborate with external partners performing BIOS customization”

What You'll Achieve.

help us securely scale; holding teams accountable to outcomes

Industry & Context.

industrial computing
Problems you'll solve

creative problem solver; innovative ideas

What They're Looking For.

Must Have

Bachelor's degree or higher in Computer Science, Cybersecurity, Software Engineering, or Electrical Engineering, 5+ years of firmware security management experience, preferably in the industrial PC industry working with BIOS/UEFIs, Proven expertise in embedded systems security, with a focus on threat modeling, risk assessment, and security implementation, command of UEFI security standards (e. g. , TPM 2. 0, Secure Updates, Capsule updates, Secure/Trusted/Measured Boot, Intel BIOSoot Guard, Intel PTT, Intel TXT), Experience collaborating in a leadership capacity across multiple engineering disciplines, such as mechanical, electrical, firmware, and security, Hands-on experience in embedded firmware debugging using JTAG-based debuggers and logic analyzers, Deep understanding of the vulnerability lifecycle, including scanning, CVE management, and risk mitigation strategies, Ability to collaborate with teammates on the Cybersecurity, Component Engineering, and other engineering teams to implement secure and compliant development processes, Capability to contribute to the Firmware Security Development Lifecycle by supporting its development at various stages, including design, threat analysis, implementation, validation, vulnerability testing, certification, and audit, background in software development, including proficiency in Python, Experience with version control systems (such as Git) and standard software development processes, Solid understanding of PC hardware architectures, BIOS, and Linux operating systems, Extensive experience with microcontrollers, including their core architecture and operation

Nice to Have

Familiarity with common security standards and certifications (e. g. , Common Criteria, MITRE, FIPS, ISO 27001: 2022, IEC 62443)

What You'll Do.

lead vulnerability management and firmware/software coding tasks for various UEFIIOS

and microcontroller (MCU) applications

collaborate with external partners performing BIOS customization

Engaging in end-to-end projects—from vulnerability identification to risk mitigation and validation testing

identify and mitigate firmware vulnerabilities

Executing firmware development tasks focused on vulnerability mitigation

Partnering with the firmware development team to define precise BIOS specifications

Collaborating with external parties throughout the vulnerability management lifecycle

Validating the function of firmware and BIOS on hardware prototypes

Actively participating in the continuous improvement of the company’s hardware and firmware development processes

Driving comprehensive vulnerability lifecycle management

Supporting product security initiatives and managing customer communications regarding related issues

How You'll Work.

Team & Collaboration

Collaborating with the security team; Partnering with the firmware development team; Collaborating with external parties; collaborate with teammates on the Cybersecurity, Component Engineering, and other engineering teams; collaborating cross-functionally

Communication Scope

clear communicator; setting expectations; holding teams accountable; effective communicator; deliver critical feedback constructively

Free ATS check

Applying for this Firmware Security Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

ANONYMOUS · UNFILTERED

What do employees actually say about OnLogic?

Real rants from real employees. Read before you apply.

Read Company Rants →