Senior / Principal RTL & Embedded Security Firmware Engineer
The Senior/Principal RTL & Embedded Security Firmware Engineer is responsible for the hardware design and low-level firmware of a secure FPGA-based programming and HSM platform built on PolarFire SoC devices. The role spans FPGA fabric RTL design, IP core integration, and the bare-metal / RTOS firmware that drives that hardware.
The engineer owns the security-critical hardware mechanisms of the product — tamper detection and response, zeroization, secure boot, secure field update of fabric and firmware images, and the encrypted inter-device communication link — and is expected to define, specify, implement, and defend these designs against FIPS 140-3 Level 3 / ISO 19790 requirements.
This is a system-level role that combines RTL design, embedded firmware development, hardware bring-up and debug, and security architecture. The engineer provides technical leadership, drives design decisions, produces certification-grade specifications, and works closely with software, validation, SQA, and certification teams.
FPGA Design and RTL Ownership
Design, implement, and maintain FPGA fabric RTL for a multi-device secure platform, including device configuration, core separation, and security-monitor logic.
Integrate third-party and internal IP cores (post-quantum crypto accelerators, SHA-3 / Keccak, JTAG and SPI programming cores) and bring them up on real hardware.
Own the high-speed serial link between devices, including the hardware layer and its authenticated, encrypted full-duplex data path.
Drive synthesis, place-and-route, timing closure, and resource optimization.
Define and evolve RTL coding standards, review practices, and design methodology.
Security Hardware Mechanisms
Define and implement physical attack detection (tamper) mechanisms and the corresponding response actions.
Design and implement zeroization logic and its verification, per ISO 19790 requirements.
Define and implement the secure, certifiable update scheme for FPGA fabric, bootloader, and firmware images, including self-programming / in-application programming flows.
Implement secure key storage in on-chip non-volatile memory and external flash.
Implement status and error indication mechanisms required by certification.
Apply side-channel-aware design practices; support DPA/SCA assessment activities.
Low-Level Firmware Development
Develop and maintain bare-metal and RTOS-based firmware in C (Zephyr or equivalent) on embedded RISC-V cores, including multi-core and core-isolation configurations.
Develop bootloaders and image authentication/decryption paths, including post-quantum-signed images.
Develop drivers and hardware abstraction for fabric IP, crypto accelerators, external flash, and inter-device communication.
Implement power-on self-tests, integrity tests, and fault/error state handling.
Optimize firmware footprint and boot time for constrained on-chip memory.
Architecture, Research, and Specification
Research and evaluate design alternatives; run feasibility studies and proof-of-concept implementations.
Analyze trade-offs across performance, resource utilization, security, certifiability, maintainability, and cost.
Produce architecture proposals, design specifications, and certification-grade documentation, including design rationale and traceability to requirements.
Drive technical decisions using data, measurement, and experimentation.
Hardware Bring-Up, Validation, and Debug
Bring up new board revisions and debug hardware/firmware interaction at the signal level using lab equipment.
Debug board interfaces including JTAG, SPI, USB, Ethernet, DDR, and external flash.
Define board change requirements for subsequent hardware revisions.
Provide unit tests and test instructions to validation and SQA teams; support regression and system-level test development.
Support certification lab activities and respond to certification findings.
Bachelor's, Master's, or PhD in Electrical Engineering, Computer Engineering, Computer Science, or a related discipline.
7+ years of experience in FPGA/RTL design and embedded firmware development for production hardware products.
Strong RTL design skills in Verilog/SystemVerilog or VHDL, with demonstrated experience taking designs through synthesis, timing closure, and hardware bring-up.
Strong embedded C development experience on bare-metal and/or RTOS targets.
Hands-on hardware debug experience: lab instrumentation, signal-level troubleshooting, board bring-up.
Working knowledge of security concepts in hardware: secure boot, key storage, tamper response, zeroization, and authenticated/encrypted communication.
Demonstrated ability to own a technical area end to end — specification through implementation to validation — with minimal direction.
Ability to produce clear, rigorous written specifications.
Preferred Qualifications
Experience with Microchip PolarFire / PolarFire SoC and the Libero SoC design flow.
Experience with RISC-V multi-core SoCs and Zephyr RTOS.
Experience with products certified to FIPS 140-2/140-3, ISO 19790, or Common Criteria, including preparation of certification evidence.
Familiarity with side-channel analysis and countermeasures (ISO 17825, DPA).
Familiarity with post-quantum cryptography primitives (ML-KEM, ML-DSA) and hybrid hardware/firmware crypto implementations.
Experience with high-speed SerDes links and AEAD-protected data paths.
Scripting in Python, Tcl, or Bash; CI/CD and automated hardware-in-the-loop testing.
Experience integrating commercial crypto IP and working directly with IP vendors.
Principal Engineer Expectations
Serve as the technical authority for the platform's hardware and low-level firmware.
Own the security-critical design areas and their defensibility under certification.
Lead architectural investigations and drive major technical decisions.
Influence product direction through technical expertise and innovation.
Mentor engineers and establish engineering best practices.
Balance near-term delivery commitments against long-term platform health.
Identify and mitigate technical risk before it impacts delivery.