Principal Product Security Architect
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Arm is seeking an expert Security Engineer to lead and run interactions with external security laboratories and certification bodies. As a senior member of the Product Security team, you will lead different aspects of security evaluations, coordinate certification activities, and ensure that our products meet industry standard methodologies and regulatory requirements.
This role is relevant in guaranteeing that Arm products achieve and maintain the vital assurance levels through detailed, evaluation processes., * Act as the primary technical work with accredited third-party security laboratories responsible for evaluating Arm products
- Lead, coordinate, and run end-to-end security evaluation and certification programs, including planning, execution, documentation, and closure
- Ensure that all evidence, documentation, test vectors, and artefacts required for certification are accurate, complete, and delivered on schedule
- Review and validate lab findings, ensuring corrective actions are implemented and retested when needed
- Maintain up-to-date knowledge of evolving certification standards (e.g., Common Criteria, PSA Certified, SESIP, FIPS, OCP safe, ISO21434, IEC 62443, etc.)
- Establish and maintain clear, comprehensive, and current documentation for all evaluation processes and certification workflows
- Provide internal guidance and mentoring on evaluation methodologies, certification readiness, and standards
Requirements
- 10+ years of experience in product security, security evaluation, certification, or a related field
- Strong understanding of security evaluation schemes such as Common Criteria, SESIP, PSA Certified, FIPS 140-3, ISO 21434, EU-CRA or similar frameworks
- Confirmed experience collaborating with external security laboratories and navigating formal evaluation processes
- Confirmed understanding of cryptographic primitives, secure key lifecycle management, and secure provisioning workflows
- Experience with silicon/SoC security architecture, including threat modelling, attacker models, and countermeasures
- Good organizational skills with the ability to handle sophisticated, multi-stakeholder projects
- Excellent communication, negotiation, and documentation abilities
- Ability to work with multi-functional engineering, product, and security teams, * Experience with secure hardware components such as cryptography accelerators, RoT modules, Secure enclaves, HSMs, or TEE/TF-M environments
- Experience with secure firmware components such as secure Boot Rom, Bootloader, TFM/TFA, OP-TEE, hyper/micro-visor etc.
- Practical knowledge of semiconductor manufacturing flows and supply chain security
- Familiarity with side-channel analysis, fault-injection testing, and hardware penetration testing methodologies
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on fr.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?
Walking Into The Era of Supply Chain Risks
Understanding and Mitigating Common Web Vulnerabilities