Distinguished Technologist - Principal Architect, Platform Security and Firmware Systems
HP · Texas
📍 Spring, Texas, United States of Americavia workdayFirst listed here 2026-09-24
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to HP.
Distinguished Technologist - Principal Architect, Platform Security and Firmware Systems
Description -
HP is seeking a senior technical leader to serve as a lead architect for hardware rooted Platform Root of Trust for HP's commercial PC platform. In this role, you will be responsible for envisioning, defining, and driving the architecture of hardware, firmware, software, and cloud-integrated security capabilities that protect HP commercial PCs from current and emerging threats. You will also work across the hardware and security architecture teams, collaborate with HP's Security Research Labs, Firmware (BIOS) team, our security business that creates and deploys industry leading enterprise security and manageability solutions, product management, manufacturing, supply chain, customer enablement, and field organizations to create cohesive system solutions that deliver unique customer value.
This position requires deep expertise in embedded systems, platform firmware, hardware, security, device manageability, and PC system architecture. The role also requires the ability to translate complex technical capabilities into customer-relevant value propositions and to influence internal and external stakeholders without relying solely on formal authority.
Responsibilities
Serve as principal architect for HP Endpoint Security Controller roadmap, associated hardware and firmware based capabilities, cryptographic identity, attestation, secure communication, event logging, and future controller generations.
Define and evolve HP Sure Start architecture and related firmware resilience capabilities, including hardware-enforced firmware authenticity, recovery, update, and protection mechanisms.
Drive secure BIOS and firmware configuration management strategies, including HP Sure Admin ecosystem capabilities, key management, zero-touch provisioning, customer deployment models, and integration with enterprise management tools.
Lead cross-functional architecture definition across hardware, BIOS, embedded controller firmware, diagnostics, cloud services, client software, manageability tools, product management, and customer-facing teams.
Anticipate emerging threats and technology shifts, including quantum-safe cryptography, platform attestation, supply-chain security, physical tamper resistance, peripheral authentication, and new non-volatile memory architectures.
Partner with silicon vendors, operating-system providers, standards organizations, internal and external security research teams, and internal product teams to influence and align platform security direction.
Support customer briefings, field escalations, competitive positioning, technical marketing, training events, and executive communications related to HP commercial PC platform security.
Create specifications, proof-of-concepts, validation tools, scripts, demonstrations, and reference implementations that accelerate adoption of new security capabilities.
Mentor engineers and technical leaders by sharing architectural context, reviewing designs, developing talent, and helping teams make practical tradeoffs among security, cost, schedule, customer experience, and portfolio impact.
Education & Experience Recommended
Bachelor’s degree in Electrical Engineering, Computer Engineering, Computer Science, or equivalent practical experience.
Extensive experience in PC, embedded, firmware, hardware, or platform system architecture, preferably in commercial client systems or security-sensitive devices.
Demonstrated ability to architect solutions that span hardware, firmware, software, cloud services, manufacturing, and customer deployment environments.
Deep technical understanding of BIOS/UEFI, embedded controllers, secure boot, firmware update and recovery flows, cryptographic signing, PKI based device identity, attestation, and secure configuration management.
Experience defining product requirements, writing technical specifications, driving proof-of-concepts, and influencing roadmap decisions across multiple engineering teams.
Ability to communicate complex technical ideas clearly to executive, engineering, customer, sales, and field audiences.
Proven ability to lead through influence in a matrixed organization and to resolve ambiguity across competing business, technical, and customer priorities.
Preferred Qualifications
Experience with hardware based roots of trust, platform certificates, DICE/SPDM concepts, supply-chain assurance, quantum-safe cryptography, secure element or embedded security controller identity, and compliance or certification frameworks.
Experience with enterprise endpoint manageability platforms such as Intune, SCCM, device-management consoles, or cloud-based key management services.
Hands-on capability with scripting or development tools such as PowerShell, C#, Python, Java, GitHub, Visual Studio Code, or similar environments.
Experience with customer-facing technical briefings, sales enablement, competitive analysis, standards participation, patent development, or external security ecosystem collaboration.
Familiarity with commercial PC platform architecture, silicon vendor security technologies, Windows platform security, docking, peripheral security, battery authentication, telemetry, and right-to-repair considerations.
Critical Technical Domains
HP Endpoint Security Controller architecture, roadmap definition, cryptographic identity, attestation evidence, enhanced logging, and next-generation hardware requirements.
HP Sure Start and firmware resilience, including hardware-enforced firmware authenticity, recovery, update protection, and quantum-safe firmware protection.
HP Sure Admin and secure BIOS settings management, including key management, zero-touch provisioning, smart card or YubiKey authentication concepts, fine-grained authorization, and enterprise deployment workflows.
Platform security roadmap planning across BIOS, embedded controller firmware, manufacturing diagnostic
More Texas jobs
Texas jobs · Browse all locations