> Markdown version of [/jobs/ext/1510044-soc-security-architecture-sdl-lead](https://www.wearedevelopers.com/jobs/ext/1510044-soc-security-architecture-sdl-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SoC Security Architecture & SDL Lead - **Company:** ARM - **Location:** Austin, TX, United States - **Experience:** Expert - **Salary:** $198,100.0 - $268,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, User Authentication, Cyber Security, Federal Information Processing Standards (FIPS), Firmware, Hardware Security Module, Key Management, Secure Coding, Subsystems, U-Boot - **Published:** July 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=76b8035bcc76d0c4 ## About the Role We are seeking a highly skilled and experienced SoC Security Architecture & SDL Lead to drive both the Security Architectural definition and the end-to-end Secure Development Lifecycle (SDL) across Arm's hardware security IP and SoC programs., We have exciting opportunities for experienced and self-motivated Security Engineers with demonstrated expertise in SoC Solutions and looking to make a difference in an innovative and inclusive team. If you're ready to make an impact, you have found the right place! ## Description This role unifies security-by-design leadership with process governance, ensuring that our silicon platforms achieve industry-leading trustworthiness from architecture through post-silicon delivery., The Security Architecture & SDL Lead is responsible for driving both the Security Architecture definition and the Secure Development Lifecycle (SDL) for Arm IP and SoC products. This role ensures that all subsystem and SoC designs meet Arm's security requirements through detailed threat modeling, architecture, verification, and documentation. Acting as both a security process owner and technical authority, the SDL & Architecture Lead guarantees that security is embedded and successful from concept to production silicon. As the Security Architect, you will be responsible for defining and developing creative Security Architecture solutions for SoCs for multiple product market segments. This includes solutions for the SoC Root of Trust, Secure Boot, Key Management, Confidential Compute, Authentication and Encryption, and Secure Manufacturing and Device Lifetime Management. As the SDL Lead, you will lead the successful implementation of the Solution SDL process for the product, ensuring security objectives are achieved throughout the development and productization phases. This would include Threat Model, Security Architecture, Security V&V Plan, Documentation, and Certifications and Compliance leadership., * Develop architectures for SOC and subsystem Security, Root of Trust, Secure Boot, Key Management, Confidential Compute, Authentication, Encryption, and Secure Manufacturing. Architect robust access control, privilege management, isolation, and confidentiality mechanisms between hardware and software domains. * Develop and maintain architectural threat models, mapping assets, attack surfaces, and mitigations aligned with the Secure Development Lifecycle methodology. Derive Security Functional Requirements (SFRs) from threat models and ensure traceability through development and verification. * Working knowledge of cryptographic design, fault/side-channel mitigation, and firmware security. Lead creation of the Key Management Plan, ensuring secure key generation, distribution, storage, and lifecycle alignment across device usecases and manufacturing. * Familiarity with security certifications (PSA Certified, ISO/SAE 21434, FIPS 140-3, Common Criteria). SDL Leadership * Own and lead the Solution SDL process across all project phases, ensuring compliance with Arm standards and external certifications. * Drive timely creation and review of SDL artifacts (Threat Models, Security Architecture, V&V Plans, and Security Documentation) and coordinate as necessary for for external audit and certification. * Integrate SDL checkpoints into program plans and ensure organizational engagement from design through post-silicon validation. * Deliver complete security documentation including Threat Models, Security Architecture Reports, Key Management Plans, and Assumptions of Use (AoUs). * Mentor engineering teams and champion SDL adoption across global engineering teams. Verification & Validation Leadership * Collaborate with Verification & Validation Leads to define and implement Security Verification & Validation (V&V) Plans. * Ensure all SFRs are testable, verified, and validated at pre- and post-silicon stages. Ensure security issues are triaged, resolved, and systematically looped back into the SDL process for continuous improvement. * Approve sign-off criteria and ensure security verification evidence supports product release readiness. * Support security assessments, penetration testing, and certification activities (PSA Certified, FIPS 140-3, ISO/SAE 21434). ## Related Videos - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [10M Data Records Lost, Underwater Computing, and Psychedelic Fish - Matthias Geniar](https://www.wearedevelopers.com/videos/1908-10m-data-records-lost-underwater-computing-and-psychedelic-fish-matthias-geniar) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Develop on Windows, Deploy on Red Hat Enterprise Linux](https://www.wearedevelopers.com/videos/1600-develop-on-windows-deploy-on-red-hat-enterprise-linux) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 201: Don't Stop Thinking, AI Slop vs. OSS Security, Rank Things](https://www.wearedevelopers.com/magazine/674-dev-digest-201-don-t-stop-thinking-ai-slop-vs-oss-security-rank-things) - [Dev Digest 230: Secure Agent Sandboxes, $100m OSS & Tricking Claude](https://www.wearedevelopers.com/magazine/744-dev-digest-230-secure-agent-sandboxes-100m-oss-tricking-claude) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)