1X
Product Security Engineer
About this role
1X is hiring a Product Security Engineer to protect their NEO humanoid robot across the entire stack—from bootloader to cloud services. You'll conduct security audits, penetration testing, and threat modeling while designing secure-by-default systems that enable families to safely trust robots operating in their homes.
What you'll do
- Audit code and systems across NEO's stack to identify and remediate security vulnerabilities
- Lead end-to-end security initiatives partnering with Robotics, Infrastructure, and Manufacturing teams
- Conduct penetration tests, threat models, and risk assessments against NEO and supporting infrastructure
- Design and implement security-critical components like secure boot chains and code-signing pipelines
- Define security architecture for robot provisioning, deployment, and operation at scale
What they're looking for
- Linux/embedded systems security and hardening
- Cryptography and PKI design
- C, C++, Rust, Go, or Python programming and code auditing
- Penetration testing and offensive security
- Secure boot and Trusted Execution Environments
- Cloud security (AWS, GCP, Azure) and CI/CD infrastructure
- Systems thinking across hardware, firmware, software, and cloud
- Threat modeling and vulnerability research
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
1X
1X builds humanoid robots for home use, with its NEO robot requiring sophisticated hardware, firmware, and cloud systems. The company is hiring across compliance testing, audio systems, embedded firmware, cloud platform development, and supplier engineering to bring its robots to production and scale.
View all jobs at 1XLikely interview questions
- Walk us through a time you identified a critical security vulnerability in a production system. How did you approach the analysis, and what was your process for driving remediation across teams?
- Describe your experience with Linux security mechanisms like namespaces, seccomp, and SELinux. How have you used these to harden systems or design least-privilege services?