> Markdown version of [/jobs/ext/1871174-principal-platform-security-architect-firmware-and-operating-systems](https://www.wearedevelopers.com/jobs/ext/1871174-principal-platform-security-architect-firmware-and-operating-systems). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Platform Security Architect -Firmware and Operating Systems - **Company:** Arm Limited - **Location:** Cambridge, UK - **Experience:** Expert - **Salary:** £126,200.0 - £170,800.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, ARM Architecture, User Authentication, BIOS, Booting (BIOS), Data Centers, Software Debugging, Linux, File Systems, Linux on Embedded Systems, Embedded Software, Firmware, Fuzz Testing, Network Security, Linux Security Modules, PCI Express, Extensible Firmware Interface, Cloud Platform System, Yocto, Selinux, U-Boot - **Published:** August 1, 2026 - **Apply:** https://www.totaljobs.com/job/principal-architect/arm-job107780138 ## About the Role * Hands-on experience with embedded Linux systems, including building and customizing platforms using Yocto/OpenEmbedded * Hands-on experience implementing and validating Linux hardening controls, including service/interface hardening, privilege management, and reduction of system attack surface * Experience contributing to the implementation or integration of security controls in firmware or embedded environments * Strong understanding of low-level firmware and boot flows, including BIOS/UEFI, bootloaders, and platform firmware components * Experience with secure boot chains and firmware trust models, including firmware verification and UEFI-based systems * Experience working with firmware update mechanisms, including signing, verification, and rollback protection * Familiarity with Arm architecture and boot processes, including early boot stages and firmware-hardware interaction * Familiarity with platform interconnects such as PCIe, and associated security considerations in device and data-center environments * Experience developing automation, validation tools, or scripts, including integration into CI workflows * Proficiency in C/C++ for systems or embedded development, with the ability to work with low-level components when needed * Understanding of Linux security fundamentals, including authentication, authorization, and system-level protections * Familiarity with file system and data protection mechanisms, including encryption approaches such as eCryptfs or similar * Ability to analyze and reason about firmware and system-level attack surfaces "Nice To Have" Skills and Experience : * Experience with BMC platforms or ecosystems such as OpenBMC * Experience with Linux security features (e.g., SELinux, AppArmor, capabilities) * Experience with firmware analysis, fuzzing, or security testing techniques * Familiarity with container security in embedded or management environments * Familiarity with hardware roots of trust (e.g., TPM, DICE) * Familiarity with networking and network security concepts, particularly in management or data-center environments ## Description We are looking for a Platform Security Architect to support the design and improvement of security mechanisms across platform firmware and embedded Linux environments. This is a hands-on technical role spanning both embedded systems (e.g., Yocto-based platforms) and data center systems (e.g., BMC and platform firmware). The work includes securing boot chains, firmware update mechanisms, and Linux-based management environments, including embedded controllers and server management subsystems. You will work closely with firmware and platform engineering teams to help integrate security controls across BIOS, BMC, and device firmware, and collaborate with internal security evaluation teams to support validation and continuous improvement of these controls. The role involves working across low-level firmware, embedded Linux, and system hardening, with opportunities to contribute at both design and implementation levels. Responsibilities: * Firmware Security: Evaluate and support integration of security mechanisms across BIOS, BMC, and device firmware, including secure boot, firmware verification, update flows, rollback protection, and debug controls * Embedded Linux & BMC Security: Contribute to improving the security of Linux-based management environments through system hardening, service isolation, access control, and secure configuration * System Hardening: Identify potential attack surfaces and configuration gaps, and help apply and validate hardening measures and secure defaults * Security Validation & CI Integration: Collaborate with internal security evaluation and engineering teams to support testing, develop validation tools/scripts, and integrate security checks into CI workflows * Threat Analysis: Support threat modeling and analysis of firmware and management plane components to identify attack paths and improvement areas ## Related Videos - [10M Data Records Lost, Underwater Computing, and Psychedelic Fish - Matthias Geniar](https://www.wearedevelopers.com/videos/1908-10m-data-records-lost-underwater-computing-and-psychedelic-fish-matthias-geniar) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How to Submit CFPs and Get into Public Speaking - Moran Weber](https://www.wearedevelopers.com/videos/2112-how-to-submit-cfps-and-get-into-public-speaking-moran-weber) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)