Principal Product Security Engineer
Arm Limited
Cambridge, United Kingdom
yesterday
Role details
Contract type
Permanent contract Employment type
Full-time (> 32 hours) Working hours
Regular working hours Languages
EnglishJob location
Cambridge, United Kingdom
Tech stack
Microsoft Windows
Adobe InDesign
Android
Software System Penetration Testing
C++
Federal Information Processing Standards (FIPS)
Firmware
Fuzz Testing
Python
Linux kernel
Software Engineering
System Software
Rust
Software Security
U-Boot
Job description
- Develop software security test framework and processes across Arm's firmware, drivers and system software
- Lead Arm's internal penetration test strategy for software products
- Schedule, prioritise and conduct software security tests
- Lead other security test engineers within the product security team and across the business
Requirements
- Deep knowledge and expertise in design, development, documentation and testing of software specifically for low lever software such as firmware and drivers
- Strong understandings of SoC security fundamentals such as secure boot, measured boot, attestation, signing, Root of Trust
- Proven knowledge in leading software security assessment and penetration testing preferably at SoC level
- Demonstrated skills for finding security vulnerabilities "which matter"
- Professional knowledge of software languages (such as C/C++, Rust, Python)
- Strong background in offensive security research
- Knowledge of Arm assembly, Arm based SoCs and devices
- Experience in leading fuzz testing activities and with tooling
- Capable of providing technical leadership
- Good interpersonal and communication skills
"Nice To Have" Skills and Experience :
- Experience in performing security assessment on products towards external security certification such as common criteria, PSA, SESIP, FIPS
- Have participated in CTFs, Hackathons, or similar events
- Have published work within the offensive security domain at leading venues
- Expericence with security evaluation of Linux kernel security, Android OS security, Windows systems and drivers security
- Experience in security of GPU/CPU/System firmware and drivers
- Professional certifications such as OSCP/OSEE
About the company
With offices worldwide, Arm is a diverse organization of dedicated, creative, and hardworking engineers. By enabling a dynamic, inclusive, meritocratic, and open workplace where everyone can grow and succeed, we encourage our people to share their outstanding contributions to Arm's success in the global marketplace.