About the role
NVIDIA's Enterprise Security organization is looking for a Senior Security Engineer passionate about platform and device security! This role includes leading device attestation and our enterprise secure browser program's technical direction. You will define how NVIDIA establishes and continuously verifies trust in every endpoint, workload, and browsing session that touches our worldwide infrastructure across cloud, on-premises, and managed device environments. This role offers a hands-on, high-impact engineering opportunity at the intersection of platform security, endpoint and browser trust, and AI infrastructure. In addition to architecture, you will write production code. A core part of the charter is building SRE agents. These are automation tools powered by intelligent systems. They monitor, diagnose, and fix the security platforms we operate. This work turns manual response playbooks into self-healing systems. You will partner closely with device management, identity governance, network security, and platform engineering to set technical strategy and carry operational ownership. What You'll Be Doing: Design and implement a device attestation service that produces verifiable, cryptographically backed device posture signals from hardware roots of trust (TPM 2.0, Secure Enclave, measured boot) and makes them consumable as a first-class input to access decisions. Lead the engineering and enterprise rollout of our secure browser platform (Prisma Access Browser), including access policies, data-loss prevention controls, browser-extension governance, telemetry, and integrations with identity, Conditional Access, SASE, and ZTNA platforms. Build SRE agents for security platforms, design, code, and operate agentic automation that detects degradation, triages alerts, correlates telemetry, executes safe remediation, and reduces toil across attestation, endpoint, and browser services. Define reference architectures that bind device trust to session trust, so that browser, CLI, and agentic workflows are all evaluated against consistent, continuously reevaluated posture. Integrate device and browser trust signals into identity and access workflows, enabling access decisions based on user identity, device integrity, browser posture, session risk, and application sensitivity. Scale platform-security capabilities across large and heterogeneous endpoint environments while maintaining reliability, performance, security, compliance, and a positive user experience. Establish service-level objectives, observability, capacity planning, and operational readiness for device-trust and secure-browser services. Lead incident response, post-incident reviews, and implementation of durable corrective actions. Partner with multi-functional collaborators across security, IT and product teams to align on architecture, build strategy, and long-term operational ownership. What We Need to See: Bachelor's degree or Master's degree or equivalent experience in Computer Science or a related field. 12+ years of experience in platform, infrastructure, or security engineering, including significant depth in endpoint or platform security. Strong, current software development skills with a track record of shipping and operating production services. Experience designing, building, and owning large-scale distributed services or security platforms, including the operational responsibility that comes with them. Demonstrated experience automating operations at scale: reducing toil, building self-healing or closed-loop remediation, and running services against defined SLOs. Solid understanding of Zero Trust architecture, device trust and posture models, and endpoint attack techniques, plus how identity, device, and network signals combine into access decisions. Working knowledge of at least one hardware or platform trust primitive (TPM, Secure Enclave, measured boot, TEEs, hardware-bound credentials) and the ability to go deep quickly on attestation. Excellent written and verbal communication skills; comfortable driving architecture decisions across senior and executive audiences. Ways To Stand Out From The Crowd: Hands-on experience building attestation or device posture services that run at enterprise scale with high availability and low latency. Deep understanding of TPM and measured boot internals, remote attestation protocols, and device-bound credentials and tokens (DPoP, mTLS, WebAuthn). Familiarity with securing non-human and machine identities, and with how attestation underpins service-to-service and agentic access patterns. Experience deploying or operating an enterprise browser or secure web access stack (Prisma Access Browser, Island, Chrome Enterprise, SASE/ZTNA, CASB, DLP), especially across a large developer population. Familiarity with browser security internals such as extension models, isolation boundaries, and policy enforcement. Experience building AI agents or ML-assisted automation for reliability or security operations, including guardrails, evaluation, and safe-action design or a demonstrated track record of picking up emerging tooling and shipping with it fast. Experience leading enterprise endpoint or device trust transformations, including migration off legacy agents and posture models at scale. At NVIDIA, we operate at the core of enterprise security, architecting and protecting the platforms that support some of the most advanced computing systems in the world. This role offers the opportunity to influence strategy, build the automation that runs our security platforms, engage with executives, and leave a lasting security impact, working alongside outstanding engineers and security leaders! NVIDIA is widely considered to be one of the technology world’s most desirable employers. We have some of the most intelligent and hardworking people in the world working for us. If you're creative and autonomous, we want to hear from you! Your base salary will be determined based on your location, experience, and the pay of employees in similar positions. The base salary range is 196,000 USD - 310,500 USD. You will also be eligible for equity and benefits . Applications for this job will be accepted at least until September 14, 2026. This posting is for an existing vacancy. NVIDIA uses AI tools in its recruiting processes. NVIDIA is committed to fostering an inclusive work environment and proud to be an equal opportunity employer. As we highly value diversity in our current and future employees, we do not discriminate (including in our hiring and promotion practices) on the basis of race, religion, color, national origin, gender, gender expression, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law.