- Robot type
- Service and Consumer
- Location
- San FranciscoCaliforniaUSA
- Job type
- Software
- Posted
- Jun 8, 2026
Full-time
Infrastructure Security Engineer
Job description
Skip is on a mission to make life joyful through powered movement.
Job responsibilities
- Design and operate Skip's PKI infrastructure -- device certificate provisioning, certificate authority management, key lifecycle management, and revocation -- across our device fleet and cloud services
- Own device identity and secure boot: ensure every MO/GO that leaves our factory is cryptographically authenticated and that firmware updates can only come from Skip
- Harden our GCP infrastructure across networking, IAM, secrets management, and data isolation between Dev and Prod environments
- Build and maintain security tooling for secrets management, vulnerability scanning, dependency auditing, and incident detection
- Define and implement secure OTA (over-the-air) update pipelines that ensure firmware integrity from signing through delivery to device
- Automate infrastructure provisioning and security configuration using Terraform and GCP-native tooling
- Partner with firmware engineers to define embedded security requirements -- secure element usage, TrustZone, attestation -- and ensure cloud-side infrastructure meets them
- Contribute to compliance readiness as we approach regulated market entry, including audit logging, access controls, and data handling practices
Job requirements
- 6+ years of experience in infrastructure engineering, platform security, or a combined DevSecOps role
- Hands-on experience designing and operating PKI systems: CA hierarchies, certificate provisioning at scale, key management, and revocation
- Strong GCP or equivalent cloud infrastructure experience (IAM, VPC, Secret Manager, Cloud KMS, audit logging)
- Experience with Infrastructure as Code (Terraform or equivalent)
- Solid understanding of TLS, mTLS, code signing, and secure boot concepts in the context of connected devices or IoT
- Experience with CI/CD security: signing pipelines, artifact attestation, secrets hygiene
- Able to operate independently in a fast-paced environment where the security playbook is still being written
- Ability to relocate to work at the Skip Bay Area office
