Job Description:
The Security Research and Response team in Arm's Architecture and Technology Group is seeking a highly skilled SoC Offensive Security Staff Engineer to apply an attacker's mindset to Arm's next-generation solutions, identifying design and integration-level vulnerabilities early in the development lifecycle!
Working as part of the SoC Offensive Security team, you will perform adversarial security assessments across multiple projects by reviewing architectural specifications, evaluating pre- and post-silicon platforms, conducting firmware security analysis, and collaborating with development teams to uncover security weaknesses that traditional SDL processes may overlook. You will use practical security research methods, automation, and where appropriate, AI-assisted techniques to improve the depth, scale, and efficiency of adversarial analysis. Your work will contribute directly to improving the security of Arm's next-generation silicon solutions!
Responsibilities:
- Perform adversarial security analysis of SoC and chiplet micro-architectures, identifying unknown or emerging vulnerabilities across pre-silicon and post-silicon environments.
- Engage with project teams at different stages of the development lifecycle to review architecture, micro-architecture, system-level specifications, security assumptions, RTL implementations, and firmware components.
- Participate in design reviews, security discussions, and focused hackathons to develop new threat scenarios, perform adversarial testing, and improve security models.
- Apply automation, scripting, and AI-assisted techniques where appropriate to support vulnerability discovery, specification analysis, test generation, triage, or exploration of complex attack surfaces.
- Demonstrate the practical impact of vulnerabilities by developing Proofs of Concept (PoCs), exploits, and security demonstrations where appropriate.
- Investigate multi-stage and cross-component attack chains beyond those captured in threat models or standard verification activities.
- Collaborate closely with internal security researchers and engineering teams to accelerate security assessments and identify effective mitigations.
- Contribute to improving threat models, security mitigations, and security architecture recommendations based on assessment findings.
- Contribute to the development and continuous improvement of offensive security methodologies, tools, and best practices across the SoC Offensive Security team.