Form Energy

Senior Staff Security Engineer

Form Energy$130K — $180K *
Aerospace & Defense
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of experience in Cyber Security with architect-level decision-making.
  • Proficiency in architecting secure systems.
  • Applied cryptography expertise in symmetric/asymmetric methods and secure API boundaries.
  • 2+ years in Application Security, identifying bespoke software flaws.
  • 2+ years directly building security tooling.
  • Experience implementing hardware root-of-trust protocols and interacting with HSMs.
  • 5+ years of systems programming in production-grade C, C++, or Rust.
  • Proven high-assurance mindset focused on security outcomes over compliance.

Responsibilities

  • Secure middleware engineering with production-grade, memory-safe systems code.
  • Evaluate and adapt Delay-Disruption Tolerant Networking standards for hardware constraints.
  • Build defensive state machines addressing online integrity during network outages.
  • Apply static analysis and threat modeling for rigorous software verification.
  • Design software and architectural boundaries to withstand Advanced Persistent Threats.

Benefits

  • 100% coverage of medical, dental, and vision premiums for full-time employees.
  • 80% coverage of healthcare premiums for dependents.
  • At least 12 weeks of paid leave for new parents, up to 20 weeks for birthing parents.
  • Generous vacation policies for work-life balance.
  • Stock options and a holistic benefits package.
Full Job Description
Role Description

As a Senior Product Security Engineer, you will operate as an elite individual contributor balancing hands-on systems software development (50%) with high-assurance threat modeling, protocol verification, and security design/analysis (50%). Reporting directly to the Security/Safety Architect, your primary objective will be to design, write, and rigorously verify the secure communication middleware and OTA update plans that run on our asset edge controllers. You will build deterministic, zero-trust architectures capable of maintaining total cryptographic integrity and operational resilience under active duress from highly sophisticated, nation-state level adversaries. You will be designing systems that have to remain secure for operational lifetimes of decades.

Relocation assistance is available.

What you'll do:
  • Secure Middleware Engineering (50%): Write clean, production-grade, and memory-safe systems code (C, C++, Rust) running directly on asset edge hardware and interfacing with onboard Hardware Security Engines (HSE) and Modules (HSM).
  • Asynchronous Protocol Architecture: Evaluate, test, and adapt existing Delay-Disruption Tolerant Networking (DTN) standards; architect and implement custom transport wrapping where standard frameworks fall short under physical hardware constraints.
  • Cryptographic Disruption Handling: Build defensive state machines that maintain absolute system integrity during prolonged network blackouts-specifically solving for offline replay prevention, asynchronous certificate validity management, key expiration limits, and secure local data-at-rest queuing.
  • High-Assurance Analysis & Verification (50%): Apply rigorous static analysis, threat modeling, and formal verification methodologies to mathematically analyze cryptographic handshakes and communication boundaries, ensuring software cannot be forced into unverified failure states.
  • Adversarial Threat Modeling: Design architectural and software boundaries tailored to withstand Advanced Persistent Threats (APTs) and nation-state actors targeting the bulk power system. Extend the product threat model to account for physical hardware tampering and supply-chain risk vectors.


What you'll bring:
  • Cyber Security Qualifications:
    • Security Architecture:
      • 10+ years of experience in Cyber Security, including positions that require architect-level decisions.
      • Demonstrated skill at architecting secure systems.
    • Applied Cryptography: Practical expertise in symmetric/asymmetric cryptographic primitives, mutual TLS, secure session state management, and designing robust API boundaries for distributed edge-to-cloud systems.
    • Application Security: 2+ years of Application Security experience (finding flaws in bespoke software)
    • Security Engineering: 2+ years experience directly related to building security tooling
    • Embedded Hardware Security: Direct experience implementing hardware root-of-trust, secure boot protocols, firmware signing, and writing code that interacts with HSMs, HSEs, or TPMs.
  • Systems Programming: 5+ years of experience writing production-grade, optimized code in C, C++, or Rust
  • High-Assurance Mindset: A track record of achieving security outcomes through rigorous software architecture, verification engineering, and clean code execution rather than policy compliance or automated compliance scanner management.
  • Clearance Note: No active U.S. government security clearance is required for this role.
  • Note: This is not an IT Security Governance, Risk and Compliance (GRC) role.
Preferred Qualifications:
  • Prior experience designing high-assurance systems within the Aerospace, Defense, Financial, Semiconductor Security, High-Assurance Consultancies, or the Intelligence Community (IC) sectors.
  • Embedded Programming within resource-constrained environments (embedded Linux, RTOS, or bare-metal targets).
  • Exposure to network resilience strategies, store-and-forward mechanics, mesh topologies, or formal DTN protocol definitions (e.g., Bundle Protocol).
  • Familiarity with the mathematical intent behind formal verification frameworks, protocol simulation tools, or abstract interpretation engines.
  • Experience with Go inside modern cloud-scale data ingestion and optimization environments.
  • Deep technical understanding of the engineering and defensive objectives that underlie critical infrastructure protections like NERC CIP, ISO 64423,NIST IR 7628, NIST SP 800-160v1/2


#LI-Onsite

Humanity is a cornerstone of Form Energy's culture, and we make sure our compensation and benefits reflect that. Form Energy offers competitive salaries, stock options, and a holistic benefits package to ensure all employees have what they need to thrive while working here.

When it comes to you and your family's health, we cover 100% of medical, dental, and vision premiums for full-time employees - and 80% of healthcare premiums for dependents. This starts from day one. We also offer at least 12 weeks of paid leave for new parents (up to 20 weeks for birthing parents), and generous vacation policies to give employees time to recharge when needed.

To build America's energy future, we need everyone at the table.

About Form Energy

Form Energy is an American energy storage technology and manufacturing company that is developing and commercializing a pioneering iron-air battery capable of storing electricity for 100 hours at system costs competitive with legacy power plants. Form’s multi-day battery will reform the global electricity system to reliably run on 100% low-cost renewable energy, every day of the year. Form Energy was founded by energy storage veterans who came together in 2017 with a unified mission to reshape the global electric system by creating a new class of low-cost multi-day energy storage systems. Driven every day by Form’s interlocking core values of humanity, excellence, and creativity, our team is deeply motivated and inspired to transform the energy landscape and create a better world.
Learn more about Form Energy
Size
50 employees
Industry
Founded
2017

Similar Jobs

More Jobs at Form Energy

More Aerospace & Defense Jobs

Find similar Senior Staff Security Engineer jobs: