> Markdown version of [/jobs/ext/2493595-offensive-firmware-security-engineer](https://www.wearedevelopers.com/jobs/ext/2493595-offensive-firmware-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Offensive Firmware Security Engineer - **Company:** Mediatek Inc - **Location:** San Jose, CA, United States - **Experience:** Expert - **Salary:** $180,000.0 - $260,000.0 - **Contract:** Permanent contract - **Skills:** C (Programming Language), Software System Penetration Testing, AUTomotive Open System Architecture (AUTOSAR), C++ (Programming Language), Cyber Security, Computer Programming, Computer Engineering, Software Debugging, Linux, Firmware, Joint Test Action (IEEE Standards), Python (Programming Language), Reverse Engineering, Secure Coding, Information Technology, IDA Pro, Vulnerability Analysis - **Published:** August 31, 2026 - **Apply:** https://www.careerboard.com/us/en/find-jobs-in-United-States/-FD1312CC41B596A493/ ## About the Role * BS+ in Computer Engineering, Computer Science, or Electrical Engineering. * 7+ years of relevant work experience * Programming background in ARM/RISCV assembly, Python, C, C+, and/or RUST * Knowledge of Embedded system architecture and security (eg Android/Linux, ARM trust zone, hypervisor/virtualization etc.). * Knowledge of hardware/software vulnerabilities and their exploit techniques * Experience with security design review or threat modeling throughout hardware to software. * Experience with secure code review, analysis, vulnerability assessment, hacking/attack analysis. * Motivated by pursuing difficult and novel problems in a highly complex environment * Excellent at multitasking, organizing, and prioritizing complex projects to meet deadlines * Listens for nuances and digs into details to understand systems deeply Preferred Requirement * experience on any automotive grade platform such as AUTOSAR, QNX, Android Automotive, etc. * JTAG, debugging, binary instrumentation frameworks, Reverse-engineering (IDA Pro, Ghidra) * ISO21434 or ISO 26262 compliance experience * TARA or HARA methodology and execution experience * CACSE (Certified Automotive Cyber-Security Expert) certificate * CACSP (Automotive Cyber-Security Professional) certificate ## Description * Perform security architecture design review and threat analysis of firmware and hardware, to ensure security properties and robustness of our complex software products * Identify vulnerabilities in our firmware, build proof of concepts, and drive remediation via secure code reviews, fuzz and penetration testing * Recommend security controls, evangelize and drive adoption of new or improved tools, practices, and plans to increase product robustness and reliability. * Collaborate with engineers, customers, and/or partners to perform internal or external security audits on our products to ensure the security quality. * Respond to product security incidents, coordinate engineering teams and partners to solve security related issues * Work with other parts of our company on a broad range of technologies and initiatives to enhance security. * Research and exploit side-channel, fault, and advanced physical attacks ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [A Hitchhikers Guide to Container Security - Automotive Edition 2024](https://www.wearedevelopers.com/videos/1119-a-hitchhikers-guide-to-container-security-automotive-edition-2024) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)