Give the private agent a trustworthy foundation beneath the operating system. You will connect device identity and boot integrity to usable security decisions.
Not open yet: Pilot expansion
This work starts when that stage arrives, so there is no application to submit today and we will not pretend otherwise. What is written below is what the role is for and what would make somebody right for it, published early on purpose so you can decide whether it is worth watching.
The work
Integrate supported roots of trust, protected key storage, measured boot and attestation. Evaluate TPMs, secure elements and trusted execution environments against a specific threat model. Coordinate provisioning, debug access and lifecycle changes with hardware and firmware teams.
The milestone
In your first 90 days, demonstrate a platform-specific attestation or protected-key workflow and document the attacks it does and does not address.
Evidence
Bring hardware security or low-level platform security experience. Explain why attestation does not prove that an agent's decision is correct or that all side channels are closed.
Evidence, not credentials. We are describing work you can point at, in whatever form it exists.
The exercise
Design a policy for a device with a valid identity but an unexpected firmware measurement.