> Markdown version of [/jobs/ext/3006893-senior-software-engineer-embedded-product-security](https://www.wearedevelopers.com/jobs/ext/3006893-senior-software-engineer-embedded-product-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Software Engineer, Embedded Product Security - **Company:** Anduril Industries - **Location:** Irvine, CA, United States - **Experience:** Expert - **Salary:** $220,000.0 - $292,000.0 - **Contract:** Permanent contract - **Skills:** Booting (BIOS), UClibc (C Standard Library), Linux, File Systems, Firmware, Joint Test Action (IEEE Standards), Key Management, Linux Kernel, Packet Analyzer, Public Key Infrastructure, Software Engineering, Software Vulnerability Management, Extensible Firmware Interface, Software Security, SC Clearance, Yocto, Sentry, U-Boot - **Published:** September 19, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9179599/senior-software-engineer-embedded-product-security ## About the Role * 4+ years of professional software engineering with a security focus on Linux or embedded systems. * Hands-on experience implementing a secure boot chain: code signing, chain of trust, UEFI Secure Boot or an equivalent vendor secure boot implementation. * Practical cryptographic engineering skills: PKI and certificate hierarchies, HSM or PKCS#11-backed signing, key lifecycle management, and full-disk encryption. * Strong Linux internals knowledge, particularly in patching, boot flow, kernel and initrd, systemd, privilege boundaries, and filesystem and device access control. * Proficiency in C or Rust, plus the ability to work fluently in shell. * Practical hardening and vulnerability-management experience on real systems: attack-surface reduction, CVE triage on a deployed fleet, and live patching strategies that don't break the product. * Ability to explain a security decision to engineers who need to implement it, and to a program stakeholder who needs to accept the residual risk. * US person status required. Active US Secret clearance, or a previously granted Secret clearance eligible for reactivation., * Experience with NVIDIA Jetson secure boot specifically, or with another SoC vendor's secure boot and fusing workflow. * Familiarity with measured boot, TPMs, or remote attestation. * Experience with declarative configuration and reproducible builds. Nix or NixOS is what we use and what we most want to see; adjacent depth in Bazel, Buildroot, or Yocto is a solid substitute. * Background in defense or government accreditation processes, or work against a formal security controls framework. * Offensive security experience, including hardware attacks such as bus sniffing, glitching, or JTAG and boot interruption. * Experience with supply chain security, artifact provenance, or SBOM tooling. ## Description Sentry Towers are deployed to secure perimeters, some in contexts where the tower itself is a sensitive asset and physical access by an adversary is a realistic threat. That makes product security a hardware-and-software problem, not a policy exercise: if someone can pull a drive, attach a serial cable, plug in USB, or interrupt the bootloader, the design has to hold. We're hiring a Senior Software Engineer to own product security for the tower platform. You'll own the trusted boot chain top to bottom, on NVIDIA Jetson compute across several generations. That means signed firmware and bootloaders, UEFI Secure Boot, signed kernel images, encrypted root filesystems, and the key management that makes it real: hardware-security-module-backed signing keys, separate development and production trust roots, and the release pipeline that signs what we ship. Alongside the boot chain, you'll own runtime hardening posture: what's exposed on the network, what privileges the operator account holds, which physical interfaces are live in the field versus on a lab bench, and how a fielded fleet gets security patches on hardware whose vendor support is ending. You'll work closely with our internal product security organization, translating requirements into implementations that ship, and reviewing our design decisions early, while they are still cheap to change. Two things about this role are worth saying plainly. Security work is often the work of saying no, or of saying "not like that", to engineers under schedule pressure who are not wrong to want to move faster; doing that well without becoming an obstacle is most of the craft. And the feedback loop is slow by construction: signed images cannot be built on your laptop, so the build farm is the gate, and you will wait on it. Some of the job is also inherited rather than chosen, including hardware whose vendor support is ending on a fixed date that will not move for us. Our Product: https://www.anduril.com/sentry WHAT YOU'LL DO * Own the signed boot chain across compute generations: firmware and bootloader signing, UEFI Secure Boot key hierarchies, signed kernel and initrd, and full-disk encryption with automated unlock. * Own signing key management and the infrastructure behind it: HSM-backed keys, separation of development and production trust roots, key rotation, and build-time enforcement that the right keys sign the right artifacts. * Define and implement the platform's hardening postures, spanning network exposure and firewall policy, privilege and sudo restriction, serial console and USB lockdown, and the difference between a locked-down fielded system and a debuggable bench unit. * Drive vulnerability management for the fielded fleet: track CVEs (Common Vulnerabilities and Exposures) against our kernel and userspace, own the patching strategy for hardware approaching vendor end-of-life, and keep a clear picture of fleet security state. * Partner with our product security organization to turn security requirements into shippable implementations, act as our team's security liaison, and support program-specific accreditation efforts., To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind: * No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates.