Cybersecurity Firmware Engineer
Summary
Senior engineer who owns the security architecture and secure implementation of firmware on indie's automotive SoCs: performing threat analysis (TARA), writing testable security requirements, and developing embedded C applications in RTOS environments. Core stack includes applied cryptography (secure boot, key management), hardware security blocks (HSMs, OTP), plus Python and OpenSSL tooling for p
Imagine being part of a team that’s redefining the future of mobility—where your ideas don’t just sit in a lab but power next-generation technology. At indie, we are developing cutting-edge semiconductors, photonics, and radar sensors and systems for automotive, industrial, and adjacent markets. Our innovations are at the heart of advanced intelligent sensing and user experience applications, pushing the boundaries of what’s possible.
If you're passionate about groundbreaking technology and want to make a real impact alongside a fast-paced team that thrives on creativity and collaboration, we’d love to have you on board!
The Senior Cybersecurity Firmware Engineer is responsible for the security architecture and secure implementation of firmware running on indie’s SoCs. In this role, you will partner with firmware, hardware, and architecture teams to reduce risk, threats, and vulnerabilities, and to drive new security features into products that ship in millions of vehicles.
This role requires a self-motivated engineer with strong problem-solving skills who is equally comfortable in a threat model review and in a debugger, thrives in a collaborative team environment, and can provide technical leadership and mentorship across engineering teams.
Responsibilities
- Design, implement, and test the cybersecurity architecture of indie’s firmware
- Perform security threat analysis and risk assessment (TARA) of firmware and embedded subsystems across indie’s product lines
- Convert analysis findings into written, testable security requirements, and review designs and implementations against them
- Develop and maintain embedded applications on SoCs
- Support system bring-up and debug customer systems and issues
- Respond to customer cybersecurity requirements and questionnaires, and author cybersecurity architecture documents and application notes
- Participate in code reviews and ensure compliance with automotive software quality standards, including MISRA guidelines
Requirements
At indie, we value Creativity, Ownership, and Excellence. We believe everyone contributes to our success, and we recognize that no candidate is perfect—this role is designed to challenge you and support your growth.
- Bachelor’s degree in electrical engineering, computer engineering, computer science, or a related technical field
- Minimum 5 years of experience in product security, cybersecurity firmware, or cybersecurity research, including hands-on work with embedded firmware codebases
- Strong C programming and debugging skills in RTOS environments
- Familiarity with applied cryptography — secure boot, code signing, key derivation and management — together with threat modeling, common attack vectors, and mitigation techniques
- Hands-on experience with hardware security building blocks: hardware roots of trust, HSMs or crypto accelerators, secure key storage, and fuse/OTP-based provisioning in SoCs or ASICs
- Working knowledge of Python for scripting and tooling, and hands-on experience with OpenSSL
- Ability to work independently and collaboratively in a constantly evolving environment
- Excellent verbal and written communication, documentation, and presentation skills in English
Note: indie does not require Canadian work experience as a condition of employment.
Preferred / Differentiating Skills
- M.Sc. or PhD in computer science, electrical engineering, or a related technical field
- Experience applying ISO/SAE 21434 cybersecurity engineering in a production automotive program, including TARA and cybersecurity work products
- Familiarity with automotive security standards and frameworks such as EVITA, SHE, AUTOSAR SecOC and Crypto Stack, UNECE R155/R156, and MISRA C coding guidelines
- Experience in safety-critical development and awareness of where ISO 26262 requirements interact with security
- Familiarity with camera technologies, image and video processing pipelines, or computer vision applications
- Understanding of I2C, UART, SPI, and Ethernet protocols
- Experience with vulnerability handling and incident response for shipped embedded products
- Ability to travel internationally without restriction
indie Semiconductor and its subsidiaries are equal opportunity, inclusive employers and will consider all applicants without regard to age, ancestry, color, marital status, medical condition, mental or physical disability, national origin, race, religion, political and/or third-party affiliation, sex, pregnancy, sexual orientation, gender identity, military or veteran status, or any other characteristic protected by law.
We encourage applications from all qualified candidates and will accommodate applicants’ needs under the respective laws throughout all stages of the recruitment and selection process.
Concerning agencies: indie Semiconductor does not accept unsolicited resumes and will not be responsible for fees related to such.
Skills
As published by greenhouse · 18 questions
Basics
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter
Short answers (7)
- Street Address
- City
- State optional
- Country
- Zip Code / Postal Code
- LinkedIn Profile optional
- If you selected 'Other', please specify. optional
Pick from a list (11)
- Do you currently live in Canada?
- Desired office location
- Are you willing to relocate?
- How many days per week are you willing to work onsite?
- How many years of experience do you have with embedded programming?
- How many years of cybersecurity experience do you have?
- How many years of experience do you programming in Python?
- How many years of experience do you programming in C?
- Are you authorized to work in Canada?
- Where did you hear about us?
- .