Platform Security Engineering - OpenBMC
Apply at source. Anthropic handles the application directly; Houtini doesn't take a fee from candidates or companies. We curate which companies appear; the listings come from yubhub.
What the team is looking for.
Job Overview
We're looking for a Platform Security Engineer to join our founding team for OpenBMC-based management firmware. You will design, build, and secure firmware for x86 and Arm platforms, focusing on production and manageability features.
Responsibilities
Production and Manageability
- Design, build, and ship OpenBMC firmware and manageability features for x86 and Arm platforms using Yocto/OpenEmbedded
- Develop the management stack on DMTF/OCP standards (MCTP, PLDM, SPDM, Redfish, RDE) and IPMI/KCS
- Implement BMC-to-BIOS/host communications, eSPI/LPC, thermal/fan/power management (PMBus)
- Work on hardware/firmware boundary: I2C/I3C, SPI, PCIe, SMBus, device trees, U-Boot, Linux
Security and Hardening
- Own the BMC security posture: secure and measured boot, root of trust, attestation (SPDM), authenticated update (PLDM FW Update), rollback protection, attack-surface reduction
- Lead threat modeling and secure design reviews; run coordinated vulnerability disclosure with vendors and the upstream community
- Build verification tooling: static analysis, fuzzing, firmware extraction, CI gating
Requirements
- 8+ years of experience in systems security, with at least 5 years focused on firmware and hardware security
- Strong technical cross-functional leadership skills
- Hands-on OpenBMC/BMC firmware experience on x86 and/or Arm
- Strong C/C++ and Python skills, deep Linux user-space/kernel fundamentals, and Yocto/OpenEmbedded proficiency
- A security mindset applied to firmware
- Upstream contributions to OpenBMC, U-Boot, DMTF, or OCP
Nice to Have
- Hardware roots of trust and attestation: Caliptra, OCP S.A.F.E., TPM/HRoT, SPDM
- Memory-safe systems code in Rust or Zig
- Firmware vulnerability research, reverse-engineering, or fuzzing
- Previous work with AI/ML infrastructure security
Logistics
- Annual salary: $405,000 - $405,000 USD
- Location: San Francisco, CA | New York City, NY | Seattle, WA
- Hybrid policy: 25% office time
- Visa sponsorship: Available
- OpenBMC
- Yocto/OpenEmbedded
- DMTF/OCP standards
- IPMI/KCS
- Linux
- C/C++
- Python
- Firmware security
- Hardware security
- Caliptra
- OCP S.A.F.E.
- TPM/HRoT
- SPDM
- Rust
- Zig
- Firmware vulnerability research
Other roles you might consider.
Filtered through the same AI-companies allowlist.
Senior Site Reliability Enigneer
Synthesia
Systems Engineer, HPC (APAC)
Mistral AI
Maintenance Planner
xAI
Staff Software Engineer, Developer Productivity (Dev Environments) - Claude Code
Anthropic
Staff Software Engineer, Developer Productivity (CI/CD) - Claude Code
Anthropic
Software Engineer, Identity & Access Controls
Anthropic
New to AI work? Start with these.
Six pieces of orientation. Most AI-company job specs assume you've done this kind of hands-on work already. If you haven't, an afternoon with one of these is the cheapest way to close the gap.
Claude Desktop, from zero.
The agentic-AI assistant most of the people you'd be working alongside use every day. Install, configure, first useful prompts.
What MCPs areThe best MCPs for Claude Desktop.
MCP servers extend an AI assistant with tools and data. The catalogue most teams use. Useful technical context for any AI-engineering role.
Code with AIClaude Code, the complete beginners' guide.
The CLI for AI-paired development. Required reading if you're applying for any engineering role that mentions agents, or any role full stop.
Run a local modelHow to set up LM Studio.
Running a model on your own machine teaches you more about how AI products work in three hours than a year of using ChatGPT will.
The hardware realityBeginner's guide to AI hardware.
What the infrastructure under the model actually looks like. Useful context for infrastructure, applied-AI and hardware roles.
Browse the stackMCP catalogue.
Eleven MCP servers Houtini maintains or recommends. Each detail page describes a real piece of working AI infrastructure.