> Markdown version of [/jobs/ext/3047085-principal-security-engineer-fuzzing-specialist](https://www.wearedevelopers.com/jobs/ext/3047085-principal-security-engineer-fuzzing-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Engineer - Fuzzing Specialist - **Company:** Arm Limited - **Location:** Cambridge, UK - **Salary:** £126,200.0 - £170,800.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, C++ (Programming Language), Static Program Analysis, Profiling, Software Debugging, Firmware, Fuzz Testing, Python (Programming Language), Open Source Technology, Quick EMUlator (QEMU), Reverse Engineering, Scripting, Kubernetes, Bare Metal, Data Analytics - **Published:** September 24, 2026 - **Apply:** https://www.totaljobs.com/job/principal-security-engineer/arm-job108032404 ## About the Role * 1+ years in application or product security with a deep focus on coverage-guided fuzzing. * Hands-on expertise with at least one modern fuzzing framework (e.g., libFuzzer, AFL++, Honggfuzz). * Proficient in C/C++ plus strong scripting ability in Python for automation. * Solid understanding of memory-safety vulnerabilities, undefined behaviour, sanitisers, and compiler instrumentation. * Demonstrated ability to triage crashes using debuggers, profilers, and reverse-engineering tools (gdb/lldb, IDA/Ghidra). * Excellent written communication for documenting findings and influencing engineering teams. "Nice To Have" Skills and Experience : * Contributions to open-source fuzzing tools, sanitisers, or security research publications. * Knowledge of distributed fuzzing at scale (GCP/AWS, Kubernetes, or bare-metal clusters). * Familiarity with kernel, embedded, or firmware fuzzing (e.g., Syzkaller, QEMU-based harnesses). * Background in reverse engineering, static analysis or symbolic execution. * Experience integrating fuzzing into CI/CD pipelines and tracking coverage metrics. If you're passionate about breaking software safely, love high-coverage charts, and want to make a measurable dent in product security, we'd love to hear from you! ## Description As a Security Engineer - Fuzzing Specialist, you will own and evolve our coverage-guided fuzzing program. Your mission is to uncover hard-to-reach security flaws before attackers do, drive fixes to closure, and help product teams to embrace dynamic testing like fuzzing. You'll scout for new attack surfaces, craft high-performance fuzzing harnesses, and design custom sanitisers that push the state of the art. Success means measurable coverage gains, actionable crash reports, and products that ship with provable resilience., * Map & prioritise fuzzing surfaces across services, libraries, APIs, and protocols; maintain a living risk-based roadmap. * Design, build, and extend fuzzing harnesses (libFuzzer, AFL++, Honggfuzz, etc.) that improve code-path exploration and minimise false positives. * Continuously improve coverage by growing seed corpus, deploying targeted mutation strategies, and integrating new instrumentation techniques. * Automate crash triage & root-cause analysis; distinguish exploitable vulnerabilities from benign faults and drive CVE-level findings to remediation. * Develop custom sanitisers to expose classes of bugs traditional fuzzing misses. * Validate fixes & guard against regressions through differential fuzzing and regression corpora. * Assess external disclosures (bug bounties, supply-chain advisories) to determine fuzzing detectability and refine harnesses when gaps are found. * Document, report, and share insights - from coverage metrics to post-mortems to create data-driven security. ## Related Videos - [Mutation Testing and Fuzzing in C#](https://www.wearedevelopers.com/videos/703-mutation-testing-and-fuzzing-in-c) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Profiling Symfony & PHP apps with Blackfire](https://www.wearedevelopers.com/videos/265-profiling-symfony-php-apps-with-blackfire) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 131 - AI'm not sure about OSS](https://www.wearedevelopers.com/magazine/472-dev-digest-131-ai-m-not-sure-about-oss)