Denver, COremote

Salary
$106,300–$234,600from the description
Posted
Jun 30, 2026
Location
Denver, CO
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior individual-contributor role focused on hardware security within a large-scale cloud infrastructure. The work centers on defining security requirements for compute hardware, conducting hands-on and adversarial assessments of devices, and collaborating with internal teams and external vendors to shape supply-chain and operational security practices. Suits engineers with deep hardware/firmware security backgrounds and familiarity with areas such as root-of-trust, platform attestation, BMCs, or SmartNICs.

Senior level · 8+ years · Remote · Full-time

Advertised as Principal, but the requirements read as Senior.

Must have (12)
firmware securityRoot of TrustUEFIBaseboard Management ControllersSmartNICsGPU platformsSPDMcryptographySecure BootDICEC, C++, Java, Python, Ruby, Go or Rusthardware schematic review
Nice to have (4)
x86 assembly or Arm AssemblyIntel SGXSPI, I2c or Rs232CI/CD

“or” means any one of them counts — you don't need all of them.

Posted 9 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
C51%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

The posting lists no specific work location — it references 'US' only in the compensation disclosure. No CBSA or state could be determined; the role may be remote or multi-site within the US.

The 'Subject Matter Expertise in ONE of the following areas' requirement covers Root of Trust, x86/ARM platform architecture, UEFI, GPU/rackscale, BMCs, SmartNICs, and storage devices — the JD requires depth in at least one, not all. All are marked required to reflect that the candidate pool must hold at least one; hiring managers should treat these as a group from which one is the hard gate.

The programming language requirement ('ability to work with most common programming languages') lists C, C++, Java, Python, Ruby, Go, and Rust as examples — these are treated as interchangeable alternatives for a single general coding competency requirement.

The 'hardware schematic review' and 'reverse engineering' skills are derived from explicit required-section statements ('Ability to read and review hardware schematics for security concerns' and 'Experience with reversing tools and ability to reverse engineer') — these name capabilities rather than specific named tools, but are concrete enough to retain.

The advertised title is 'Principal Hardware Security Engineer' (IC4 per Oracle's career ladder), but the scope and 8-10+ years requirement align more closely with a Senior-level role on a standard market ladder; Principal at Oracle maps closer to Staff/Senior externally.

The alt SOC (15-1299) reflects that this role is a specialized hardware/firmware security engineering position that sits at the boundary of information security analysis and hardware engineering — neither code is a perfect fit.

Compensation range is very wide ($106,300–$234,600/year), which Oracle explicitly attributes to variations in experience, location, and internal equity.

Ignored 3 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): hardware security architecture, x86 platform architecture, reverse engineering.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗