Senior Software Engineer, Attestation Services - Dgx Cloud

NVIDIA NVIDIA · Semiconductors · Santa Clara, CA +3 · Remote

NVIDIA is seeking a Senior Software Engineer to lead the development and operation of a global, cloud-native attestation platform. This role involves architecting highly available, multi-tenant services and APIs to prove the integrity and authenticity of NVIDIA systems, partnering with security, silicon, and cloud engineering teams. The position requires strong experience in distributed systems, security, and cloud-native platforms, with a focus on building foundational security and trust services.

What you'd actually do

  1. Lead the development and build of NVIDIA's attestation platform. Establish a single source of trust for the integrity of physical devices and digital systems across Data Center, Automotive, Networking, and AI ecosystems.
  2. Define and evolve a unified attestation strategy across hardware roots of trust, firmware, and runtime integrity — partnering with security, silicon, platform, and software teams to deliver end-to-end trust from silicon to customer-facing SDKs.
  3. Develop highly available, low-latency global cloud services, RESTful APIs, SDKs, and CLIs with 99.9%+ availability, horizontal scalability, automated rollouts, and robust observability.
  4. Architect adaptable, rule-based appraisal policy engines (e.g., Open Policy Agent) for evaluating attestation evidence against endorsements and reference values across diverse compliance and security requirements.
  5. Integrate attestation with firmware signing chains, provenance verification, and software bill of materials (SBOM) to ensure end-to-end supply chain trust across NVIDIA's hardware and software portfolio.

Skills

Required

  • BS/MS in Computer Science, Information Security, or a related field, or equivalent experience.
  • 12+ years of experience designing and building large-scale, distributed systems and cloud services, with at least 3 years focused on security, attestation, or trusted computing.
  • Strong programming proficiency in C or C++
  • Experience with device or software attestation, including remote attestation protocols, challenge-response flows, and trust model design
  • Solid understanding of cryptographic concepts, PKI, attestation token formats (JWT, CWT, EAT), and platform security technologies including TEEs (Intel SGX/TDX, AMD SEV-SNP), TPMs, DICE, and SPDM.
  • Proven track record building and operating scalable REST APIs and microservices in production.
  • Experience with cloud-native platforms: Kubernetes, Docker/containers, and CI/CD pipeline development and management.
  • Demonstrated ability to lead complex, multi-functional technical projects from architecture through deployment and long-term operation.
  • Excellent communication and analytical skills

Nice to have

  • Rust
  • Go
  • Python
  • GPU or accelerator attestation
  • embedded security modules and TEE platforms (TPM2, AMD SEV-SNP, Intel TDX/SGX, Nitro Enclaves)
  • architecting and scaling attestation services in production environments
  • secure API communication (mTLS, token signing, certificate management)
  • secret/key storage solutions (e.g., HashiCorp Vault, AWS Secrets Manager)
  • IETF RATS architecture (RFC 9334) and associated attestation standards
  • maintaining or contributing to open-source repositories
  • rule-based policy architectures tailored to attestation appraisal and compliance requirements

What the JD emphasized

  • 12+ years of experience designing and building large-scale, distributed systems and cloud services, with at least 3 years focused on security, attestation, or trusted computing.
  • Proven track record building and operating scalable REST APIs and microservices in production.
  • Demonstrated ability to lead complex, multi-functional technical projects from architecture through deployment and long-term operation.