Offensive Firmware Security Engineer

Mediatek Inc
San Jose, CA, United States
4 days ago
Apply on www.careerboard.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$180,000.0 - $260,000.0
Working hours
Regular working hours

Tech stack

C (Programming Language) Software System Penetration Testing AUTomotive Open System Architecture (AUTOSAR) C++ (Programming Language) Cyber Security Computer Programming Computer Engineering Software Debugging Linux Firmware Joint Test Action (IEEE Standards) Python (Programming Language)
+5 more
Reverse Engineering Secure Coding Information Technology IDA Pro Vulnerability Analysis

Job description

  • Perform security architecture design review and threat analysis of firmware and hardware, to ensure security properties and robustness of our complex software products
  • Identify vulnerabilities in our firmware, build proof of concepts, and drive remediation via secure code reviews, fuzz and penetration testing
  • Recommend security controls, evangelize and drive adoption of new or improved tools, practices, and plans to increase product robustness and reliability.
  • Collaborate with engineers, customers, and/or partners to perform internal or external security audits on our products to ensure the security quality.
  • Respond to product security incidents, coordinate engineering teams and partners to solve security related issues
  • Work with other parts of our company on a broad range of technologies and initiatives to enhance security.
  • Research and exploit side-channel, fault, and advanced physical attacks

Requirements

  • BS+ in Computer Engineering, Computer Science, or Electrical Engineering.
  • 7+ years of relevant work experience
  • Programming background in ARM/RISCV assembly, Python, C, C+, and/or RUST
  • Knowledge of Embedded system architecture and security (eg Android/Linux, ARM trust zone, hypervisor/virtualization etc.).
  • Knowledge of hardware/software vulnerabilities and their exploit techniques
  • Experience with security design review or threat modeling throughout hardware to software.
  • Experience with secure code review, analysis, vulnerability assessment, hacking/attack analysis.
  • Motivated by pursuing difficult and novel problems in a highly complex environment
  • Excellent at multitasking, organizing, and prioritizing complex projects to meet deadlines
  • Listens for nuances and digs into details to understand systems deeply

Preferred Requirement

  • experience on any automotive grade platform such as AUTOSAR, QNX, Android Automotive, etc.
  • JTAG, debugging, binary instrumentation frameworks, Reverse-engineering (IDA Pro, Ghidra)
  • ISO21434 or ISO 26262 compliance experience
  • TARA or HARA methodology and execution experience
  • CACSE (Certified Automotive Cyber-Security Expert) certificate
  • CACSP (Automotive Cyber-Security Professional) certificate

Benefits & conditions

Salary range: $180,000- $260,000

Employee may be eligible for performance bonus, short and long term incentive programs. Actual total compensation will be dependent upon the individual’s skills, experience and qualifications. In addition, MediaTek provides a variety of benefits including comprehensive health insurance coverage, life and disability insurance, savings plan, Company paid holidays, Paid time off (PTO), Parental leave, 401K and more.

MediaTek is an Equal Opportunity Employer that is committed to inclusion and diversity to all, regardless of age, ancestry, color, disability (mental and physical), exercising the right to family care and medical leave, gender, gender expression, gender identity, genetic information, marital status, medical condition, military or veteran status, national origin, political affiliation, race, religious creed, sex (includes pregnancy, childbirth, breastfeeding and related medical conditions), and sexual orientation. Seniority level

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerboard.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:57 min

Following security research and continuous developer education

Martin Schmiedecker · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:19 min

Orchestrating over-the-air firmware updates for vehicle modules

Denis Grahovac · World Congress 2021

3:20 min

Certifying safety-critical automotive software and deploying progressive testing strategies

David Romić · World Congress 2023

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

2:20 min

Utilizing custom firmware for variable torque manipulation

Daniel Meilak Daniel Meilak +1 · World Congress 2026 Europe

Videos

See all

Related articles

See all