Principal Product Security Engineer

Arm Limited
Cambridge, United Kingdom
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English

Job location

Cambridge, United Kingdom

Tech stack

Microsoft Windows
Adobe InDesign
Android
Software System Penetration Testing
C++
Federal Information Processing Standards (FIPS)
Firmware
Fuzz Testing
Python
Linux kernel
Software Engineering
System Software
Rust
Software Security
U-Boot

Job description

  • Develop software security test framework and processes across Arm's firmware, drivers and system software
  • Lead Arm's internal penetration test strategy for software products
  • Schedule, prioritise and conduct software security tests
  • Lead other security test engineers within the product security team and across the business

Requirements

  • Deep knowledge and expertise in design, development, documentation and testing of software specifically for low lever software such as firmware and drivers
  • Strong understandings of SoC security fundamentals such as secure boot, measured boot, attestation, signing, Root of Trust
  • Proven knowledge in leading software security assessment and penetration testing preferably at SoC level
  • Demonstrated skills for finding security vulnerabilities "which matter"
  • Professional knowledge of software languages (such as C/C++, Rust, Python)
  • Strong background in offensive security research
  • Knowledge of Arm assembly, Arm based SoCs and devices
  • Experience in leading fuzz testing activities and with tooling
  • Capable of providing technical leadership
  • Good interpersonal and communication skills

"Nice To Have" Skills and Experience :

  • Experience in performing security assessment on products towards external security certification such as common criteria, PSA, SESIP, FIPS
  • Have participated in CTFs, Hackathons, or similar events
  • Have published work within the offensive security domain at leading venues
  • Expericence with security evaluation of Linux kernel security, Android OS security, Windows systems and drivers security
  • Experience in security of GPU/CPU/System firmware and drivers
  • Professional certifications such as OSCP/OSEE

About the company

With offices worldwide, Arm is a diverse organization of dedicated, creative, and hardworking engineers. By enabling a dynamic, inclusive, meritocratic, and open workplace where everyone can grow and succeed, we encourage our people to share their outstanding contributions to Arm's success in the global marketplace.

Apply for this position