> Markdown version of [/jobs/ext/3003700-senior-cyber-software-engineer](https://www.wearedevelopers.com/jobs/ext/3003700-senior-cyber-software-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cyber Software Engineer - **Company:** Anduril Industries - **Location:** Irvine, CA, United States - **Experience:** Expert - **Salary:** $191,000.0 - $253,000.0 - **Contract:** Permanent contract - **Skills:** C++ (Programming Language), Communications Protocols, Cyber Security, Computer Engineering, Continuous Integration, Software Debugging, Linux, Device Drivers, File Systems, Federal Information Processing Standards (FIPS), Firmware, Joint Test Action (IEEE Standards), Python (Programming Language), Key Management, Linux Kernel, Public Key Infrastructure, Proprietary Software, Ansible, Cyber-physical Systems, Reverse Engineering, Security Software, Rust (Programming Language), Policy as Code, Diagnostic Tools, Extensible Firmware Interface, Selinux, Kubernetes, Information Technology, Production Code, National Industrial Security Program Operating Manual (NISPOM), U-Boot, Terraform, Software Version Control, Vulnerability Analysis, Golang - **Published:** September 19, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9179593/senior-cyber-software-engineer ## About the Role * You write production code, and we will evaluate you on it. Real fluency in C/C++, Rust, Golang, or Python - C or Rust strongly preferred for the firmware and cryptographic work - and the ability to read and modify the others. * 5-8 years of engineering experience with deep technical ownership of security-critical systems. Time spent primarily authoring policy, running scan tools, or coordinating artifacts will not substitute. * Applied cryptography in practice rather than theory: you have implemented or integrated cryptographic libraries, handled keys and entropy correctly, and can explain how a device proves its identity at boot and how that trust is revoked. * Low-level systems depth: the Linux kernel and userspace boundary, memory, filesystems, device drivers or firmware, and the ability to debug all of it with the tools you would expect - gdb, ftrace, and a logic analyzer when it comes to that. * Experience assessing and hardening firmware, embedded, or cyber-physical systems, and a demonstrated understanding of how skilled adversaries attack them. * Secure communications and network protocol work: TLS/PKI internals, tunneling, and what breaks in disconnected or degraded networks. * Experience building and sustaining CI/CD systems; you treat pipelines and infrastructure as software, with version control, review, and tests. * Working command of RMF and NIST 800-53 - enough to know exactly what an assessor needs and to automate producing it. You do not need to have been a full-time assessor. * Currently possesses and is able to maintain an active U.S. Top Secret security clearance; TS/SCI with polygraph preferred., * 8+ years of relevant engineering experience, or equivalent depth from a national-security cryptographic or capabilities-development background. * Direct experience with FIPS 140-2/140-3 validation, CSfC, Type 1 encryption, HAIPE, or KMI. * CNSA 2.0 / Suite B implementation, or post-quantum cryptography migration work. * Vulnerability research, reverse engineering, exploit development, or hardware attack experience (fault injection, side channel, JTAG/SWD). * Anti-tamper, TEMPEST, or physical security engineering for deployed systems. * Embedded and edge depth: U-Boot/UEFI, TPM/TEE (OP-TEE, TrustZone), secure elements, and the realities of constrained or intermittently connected devices. * Rust or Golang shipped at production scale in a security-critical component, or took a system through ATO or IATT as the responsible engineer. * Policy-as-code at scale (OSCAL, OPA/Rego, OpenSCAP, InSpec), plus Terraform, Ansible or Nix, and Kubernetes hardening. * Degree in Computer Science, Computer Engineering, Cybersecurity, or a related discipline - or equivalent demonstrated experience. Familiarity with NISPOM (32 CFR Part 117), DAAPM, JSIG, and CNSSI 1253 is a plus. ## Description The Air Defense team is responsible for the cryptographic foundation and platform trust that makes Anduril's Air Defense products deployable in the world's most demanding environments. The team owns everything from firmware and secure boot to key management, anti-tamper, and the compliance automation that keeps systems accredited - across a portfolio of proprietary hardware and software operating in contested, classified, and often disconnected conditions., Air Defense employs a variety of advanced proprietary software and hardware products to support global operations. The Cyber Engineer designs and implements the cryptographic and platform security that makes those products trustworthy in contested and classified environments - FIPS-validated encryption, secure and measured boot, full-disk encryption, anti-tamper and zeroization, and secure communications across degraded links. This is a hands-on engineering role at the lowest levels of the stack. You will implement cryptography and key handling on constrained hardware, harden Linux and firmware, build the audit and validation tooling that proves the design behaves as specified, and automate the evidence accreditation requires. You will be the engineer government reviewers talk to when they want a real technical answer - but your output is code, firmware, and systems. We are looking for depth in how systems actually fail: someone who has implemented or attacked crypto, boot chains, and protocols, and who reaches for a debugger and a specification rather than a checklist. Backgrounds in vulnerability research, reverse engineering, or national-security cryptographic engineering map directly onto this work. WHAT YOU'LL DO * Implement and improve FIPS 140-3 validated encryption across products - algorithm selection, module boundaries, entropy sources, key derivation, and the validation evidence that keeps certification current. * Own the platform trust chain: secure and measured boot (U-Boot/UEFI), TPM-backed attestation, firmware signing, and rollback protection on embedded and edge hardware. * Design and implement full-disk and data-at-rest encryption, key management and rotation, and key hierarchies that survive field conditions. * Build anti-tamper and zeroization: tamper detection and response, emergency erase, key destruction paths, and the tests that prove they work under adversarial conditions. * Engineer secure communications - protocol design and review, mTLS and workload identity, tunnels and gateways for cross-domain and air-gapped transport, and CNSA-compliant cipher suites. * Build audit and validation tooling: instrumentation that proves cryptographic and boot-time behavior, plus the harnesses, fuzzers, and adversarial tests that try to break your own designs. * Harden Linux, container, and firmware baselines - kernel configuration, SELinux/AppArmor, attack-surface reduction - and codify them so they hold across every deploy. * Automate the compliance surface so it stays out of everyone's way: express NIST 800-53, STIG, and CNSSI requirements as machine-readable policy evaluated in CI, generating accreditation evidence as build output - and when a control's intent is better met by a different implementation, make that argument to reviewers with evidence., To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind: * No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Surviving the Vulnpocalypse: Open Source and Supply Chain Security in a Post Mythos World](https://www.wearedevelopers.com/videos/100279-surviving-the-vulnpocalypse-open-source-and-supply-chain-security-in-a-post-mythos-world) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)