> Markdown version of [/jobs/ext/1218603-soc-offensive-security-staff-engineer](https://www.wearedevelopers.com/jobs/ext/1218603-soc-offensive-security-staff-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SoC Offensive Security Staff Engineer - **Company:** ARM - **Location:** Austin, TX, United States - **Salary:** $198,100.0 - $268,000.0 - **Contract:** Permanent contract - **Skills:** Adobe InDesign, Artificial Intelligence, Cyber Security, Microarchitecture, Firmware, Hardware Interface Design, PCI Express, Reverse Engineering, Subsystems, SystemVerilog, Universal Asynchronous Receiver/Transmitter, Scripting, Extensible Firmware Interface, Serial Peripheral Interface - **Published:** July 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=23b2bfa6093ea5b1 ## About the Role * Strong knowledge of SoC architecture and IP integration. * Thread modeling standalone IPs and Subsystems. Candidate should have experience enumerating micro-architectural attack surfaces and SoC integration concerns. * Demonstrated experience conducting adversarial assessments (PoCs, exploits, CTFs, published work). * Practical experience with SystemVerilog RTL, UVM-based validation environments and HW Dev IDEs * Comfortable reusing current verification environments and adapting them for negative and offensive testing. * Hands-on lab experience setting up development and testing platforms, delivering security evaluations, and validating findings in practical environments. * Firmware security analysis experience on projects like UEFI, uBoot, MCUBoot, Trusted Firmware or similar. * Experience with security focused specifications and standards such as Caliptra, DICE, or related attestation and hardware root-of trust standards. * Strong, determined problem solving outlook with creative security mentality. * Great communication skills, with the ability to influence design teams and clearly articulate risk and recommendations. * Ability to independently conduct complex technical investigations across assigned areas of responsibility. "Nice To Have" Skills and Experience: * Familiarity with typical Hardware interface standards : PCIe, CXL, SMBus, SPI, I2C, UART, etc. * Familiarity with ARM's AMBA interconnect protocols: AXI, CHI, CXS, APB, ATB, LPI, etc. * Experience with formal proof tools and approaches for HW Security. * Experience with TEE and their HW building blocks. Should be able to elaborate on what is in the TCB of a confidential VM. * Experience with hardware fuzzing in pre and post silicon environments * Experience with software exploitation techniques. * Reverse engineering skills for hardware, firmware, or microarchitecture. * Contributions to open standard bodies or participation in security-focused special interest groups (e.g., industry working groups, architecture forums). ## Description The Security Research and Response team in Arm's Architecture and Technology Group is seeking a highly skilled SoC Offensive Security Staff Engineer to apply an attacker's mindset to Arm's next-generation solutions, identifying design and integration-level vulnerabilities early in the development lifecycle! Working as part of the SoC Offensive Security team, you will perform adversarial security assessments across multiple projects by reviewing architectural specifications, evaluating pre- and post-silicon platforms, conducting firmware security analysis, and collaborating with development teams to uncover security weaknesses that traditional SDL processes may overlook. You will use practical security research methods, automation, and where appropriate, AI-assisted techniques to improve the depth, scale, and efficiency of adversarial analysis. Your work will contribute directly to improving the security of Arm's next-generation silicon solutions! Responsibilities: * Perform adversarial security analysis of SoC and chiplet micro-architectures, identifying unknown or emerging vulnerabilities across pre-silicon and post-silicon environments. * Engage with project teams at different stages of the development lifecycle to review architecture, micro-architecture, system-level specifications, security assumptions, RTL implementations, and firmware components. * Participate in design reviews, security discussions, and focused hackathons to develop new threat scenarios, perform adversarial testing, and improve security models. * Apply automation, scripting, and AI-assisted techniques where appropriate to support vulnerability discovery, specification analysis, test generation, triage, or exploration of complex attack surfaces. * Demonstrate the practical impact of vulnerabilities by developing Proofs of Concept (PoCs), exploits, and security demonstrations where appropriate. * Investigate multi-stage and cross-component attack chains beyond those captured in threat models or standard verification activities. * Collaborate closely with internal security researchers and engineering teams to accelerate security assessments and identify effective mitigations. * Contribute to improving threat models, security mitigations, and security architecture recommendations based on assessment findings. * Contribute to the development and continuous improvement of offensive security methodologies, tools, and best practices across the SoC Offensive Security team., You will join a team of hard-working security engineers at the forefront of identifying vulnerabilities in Arm based systems. Your work will shape the security posture of silicon programs and provide opportunities to influence architectural direction, collaborate with extraordinary engineers, and conduct hands-on offensive security research. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [10M Data Records Lost, Underwater Computing, and Psychedelic Fish - Matthias Geniar](https://www.wearedevelopers.com/videos/1908-10m-data-records-lost-underwater-computing-and-psychedelic-fish-matthias-geniar) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)