ForgeApply · Job listing
Senior Staff Security Engineer
Formenergy
Apply in about a minute — without sacrificing quality.
ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.
About this role
Are you ready to build America’s energy future? Form Energy is an American manufacturing and energy technology company. We’re revolutionizing energy storage with cost-effective, multi-day technology designed to keep the electric grid secure and reliable, even during extended periods of stress. By strengthening the electric system and reimagining what’s possible, we’re giving clean energy a whole new form!
In recent years, Form Energy has earned a number of accolades, including being named by TIME as a “Best Invention”, MIT Technology Review as a “Top Climate Tech Company To Watch”, and Fast Company as “One of the Next Big Things In Tech”. We are making rapid progress on our mission of delivering energy storage for a better world, and our team is growing just as rapidly to meet demand. We have signed contracts with leading electric utilities across the United States and production of our iron-air batteries is underway at our first high-volume manufacturing facility in West Virginia.
Working for Form Energy is more than just a job, it’s a chance to be part of something extraordinary. And now - right as we significantly scale up battery manufacturing - might be the most exciting moment in the company’s history to join. We are assembling a team of highly talented and driven individuals across the country. Driven by our core values of humanity, excellence, and creativity, our team is determined to deliver on our mission and transform the energy landscape for the better.
Feeling energized to make a meaningful impact on the world? Then keep reading - you’ve come to the right place.
ROLE DESCRIPTION
As a Senior Product Security Engineer, you will operate as an elite individual contributor balancing hands-on systems software development (50%) with high-assurance threat modeling, protocol verification, and security design/analysis (50%). Reporting directly to the Security/Safety Architect, your primary objective will be to design, write, and rigorously verify the secure communication middleware and OTA update plans that run on our asset edge controllers. You will build deterministic, zero-trust architectures capable of maintaining total cryptographic integrity and operational resilience under active duress from highly sophisticated, nation-state level adversaries. You will be designing systems that have to remain secure for operational lifetimes of decades.
Relocation assistance is available.
WHAT YOU'LL DO:
- Secure Middleware Engineering (50%): Write clean, production-grade, and memory-safe systems code (C, C++, Rust) running directly on asset edge hardware and interfacing with onboard Hardware Security Engines (HSE) and Modules (HSM).
- Asynchronous Protocol Architecture: Evaluate, test, and adapt existing Delay-Disruption Tolerant Networking (DTN) standards; architect and implement custom transport wrapping where standard frameworks fall short under physical hardware constraints.
- Cryptographic Disruption Handling: Build defensive state machines that maintain absolute system integrity during prolonged network blackouts—specifically solving for offline replay prevention, asynchronous certificate validity management, key expiration limits, and secure local data-at-rest queuing.
- High-Assurance Analysis & Verification (50%): Apply rigorous static analysis, threat modeling, and formal verification methodologies to mathematically analyze cryptographic handshakes and communication boundaries, ensuring software cannot be forced into unverified failure states.
- Adversarial Threat Modeling: Design architectural and software boundaries tailored to withstand Advanced Persistent Threats (APTs) and nation-state actors targeting the bulk power system. Extend the product threat model to account for physical hardware tampering and supply-chain risk vectors.
WHAT YOU'LL BRING:
- Cyber Security Qualifications: - Security Architecture: - 10+ years of experience in Cyber Security, including positions that require architect-level decisions. - Demonstrated skill at architecting secure systems. - Applied Cryptography: Practical expertise in symmetric/asymmetric cryptographic primitives, mutual TLS, secure session state management, and designing robust API boundaries for distributed edge-to-cloud systems. - Application Security: 2+ years of Application Security experience (finding flaws in bespoke software) - Security Engineering: 2+ years experience directly related to building security tooling - Embedded Hardware Security: Direct experience implementing hardware root-of-trust, secure boot protocols, firmware signing, and writing code that interacts with HSMs, HSEs, or TPMs.
- Systems Programming: 5+ years of experience writing production-grade, optimized code in C, C++, or Rust
- High-Assurance Mindset: A track record of achieving security outcomes through rigorous software architecture, verification engineering, and clean code execution rather than policy compliance or automated compliance scanner management.
- Clearance Note: No active U.S. government security clearance is required for this role.
- Note: This is not an IT Security Governance, Risk and Compliance (GRC) role.
PREFERRED QUALIFICATIONS:
- Prior experience designing high-assurance systems within the Aerospace, Defense, Financial, Semiconductor Security, High-Assurance Consultancies, or the Intelligence Community (IC) sectors.
- Embedded Programming within resource-constrained environments (embedded Linux, RTOS, or bare-metal targets).
- Exposure to network resilience strategies, store-and-forward mechanics, mesh topologies, or formal DTN protocol definitions (e.g., Bundle Protocol).
- Familiarity with the mathematical intent behind formal verification frameworks, protocol simulation tools, or abstract interpretation engines.
- Experience with Go inside modern cloud-scale data ingestion and optimization environments.
- Deep t
Salary insight
The midpoint of this range ($197k) is right around the median disclosed salary for San Francisco roles listed on ForgeApply ($203k across 6,346 jobs).
See full Security Engineer salary data for San Francisco →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Ready to apply to Formenergy?
Apply in about a minuteSimilar jobs
- Senior Security Engineer — Accenturefederalservices · Hill AFB, UT
- Senior Security Engineer — Eliseai · New York City
- Senior Security Engineer — Echotwin · San Francisco Office
- Senior Security Engineer — Novaintelligence · New York
- Senior Security Engineer — Nectar-social · Palo Alto, CA
- Senior Security Engineer — Shein · Los Angeles
- Senior Security Engineer — Karbon · Austin, TX, United States; Chicago, IL, United States; Dallas, TX, United States; Denver, CO, United States; Los Angeles, CA, United States; San Diego, CA, United States; San Francisco, CA, United States
- Senior Security Engineer — Macroscope · San Francisco
More like this: Security & Cybersecurity Jobs · Security & Cybersecurity Jobs in San Francisco · More jobs at Formenergy · Browse all jobs