> Markdown version of [/jobs/ext/1911408-principal-product-security-architect](https://www.wearedevelopers.com/jobs/ext/1911408-principal-product-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Product Security Architect - **Company:** ARM - **Location:** Valbonne, France - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Booting (BIOS), Cyber Security, Federal Information Processing Standards (FIPS), Firmware, Software Security, Hardware Infrastructure, U-Boot - **Published:** August 4, 2026 - **Apply:** https://fr.indeed.com/viewjob?jk=28602c23fee23cce ## About the Role * 10+ years of experience in product security, security evaluation, certification, or a related field * Strong understanding of security evaluation schemes such as Common Criteria, SESIP, PSA Certified, FIPS 140-3, ISO 21434, EU-CRA or similar frameworks * Confirmed experience collaborating with external security laboratories and navigating formal evaluation processes * Confirmed understanding of cryptographic primitives, secure key lifecycle management, and secure provisioning workflows * Experience with silicon/SoC security architecture, including threat modelling, attacker models, and countermeasures * Good organizational skills with the ability to handle sophisticated, multi-stakeholder projects * Excellent communication, negotiation, and documentation abilities * Ability to work with multi-functional engineering, product, and security teams, * Experience with secure hardware components such as cryptography accelerators, RoT modules, Secure enclaves, HSMs, or TEE/TF-M environments * Experience with secure firmware components such as secure Boot Rom, Bootloader, TFM/TFA, OP-TEE, hyper/micro-visor etc. * Practical knowledge of semiconductor manufacturing flows and supply chain security * Familiarity with side-channel analysis, fault-injection testing, and hardware penetration testing methodologies ## Description Arm is seeking an expert Security Engineer to lead and run interactions with external security laboratories and certification bodies. As a senior member of the Product Security team, you will lead different aspects of security evaluations, coordinate certification activities, and ensure that our products meet industry standard methodologies and regulatory requirements. This role is relevant in guaranteeing that Arm products achieve and maintain the vital assurance levels through detailed, evaluation processes., * Act as the primary technical work with accredited third-party security laboratories responsible for evaluating Arm products * Lead, coordinate, and run end-to-end security evaluation and certification programs, including planning, execution, documentation, and closure * Ensure that all evidence, documentation, test vectors, and artefacts required for certification are accurate, complete, and delivered on schedule * Review and validate lab findings, ensuring corrective actions are implemented and retested when needed * Maintain up-to-date knowledge of evolving certification standards (e.g., Common Criteria, PSA Certified, SESIP, FIPS, OCP safe, ISO21434, IEC 62443, etc.) * Establish and maintain clear, comprehensive, and current documentation for all evaluation processes and certification workflows * Provide internal guidance and mentoring on evaluation methodologies, certification readiness, and standards ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What's (new) with Spring Boot and Containers?](https://www.wearedevelopers.com/videos/1514-what-s-new-with-spring-boot-and-containers) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Microservices: how to get started with Spring Boot and Kubernetes](https://www.wearedevelopers.com/videos/242-microservices-how-to-get-started-with-spring-boot-and-kubernetes) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)