Job Title
Principal Platform Security Architect - Firmware & Operating Systems
Role Summary
Hands-on technical role to design and improve security mechanisms across platform firmware, embedded Linux, and data-center management environments (e.g., BIOS/UEFI, BMC, device firmware, and embedded Yocto-based platforms).
The role partners with firmware and platform engineering teams and internal security evaluation teams to integrate, validate, and continuously improve secure boot, firmware update flows, system hardening, and management-plane protections.
Experience Level
Senior / Principal level (principal title). Specific years of experience not stated.
Responsibilities
Key responsibilities include:
- Evaluate and integrate firmware security controls across BIOS, BMC, and device firmware (secure boot, verification, update flows, rollback protection, debug controls).
- Improve security of embedded Linux and BMC environments via system hardening, service isolation, access control, and secure configuration.
- Identify attack surfaces and configuration gaps; define and validate hardening measures and secure defaults.
- Collaborate on security validation, develop tools/scripts, and integrate security checks into CI workflows.
- Support threat modeling and analysis of firmware and management-plane components to identify attack paths and mitigations.
Requirements
Must-have skills and practical experience; nice-to-have items are listed separately.
Must-have
- Hands-on experience with embedded Linux platforms (Yocto/OpenEmbedded) and customizing builds.
- Experience implementing and validating Linux hardening (service/interface hardening, privilege management, attack-surface reduction).
- Practical experience with low-level firmware and boot flows (BIOS/UEFI, bootloaders, platform firmware) and secure boot chains.
- Experience with firmware update mechanisms including signing, verification, and rollback protection.
- Familiarity with Arm architecture boot processes and firmware–hardware interaction.
- Awareness of platform interconnects (e.g., PCIe) and related security considerations for devices and data-center environments.
- Experience developing automation or validation tools and integrating checks into CI pipelines.
- Proficiency in C/C++ for systems or embedded development and ability to work on low-level components.
- Understanding of Linux security fundamentals (authentication, authorization, system-level protections) and file/data protection approaches (encryption, e.g., eCryptfs or similar).
- Ability to analyze firmware and system-level attack surfaces and recommend mitigations.
Nice-to-have
- Experience with BMC ecosystems such as OpenBMC.
- Familiarity with Linux security features (SELinux, AppArmor, capabilities).
- Experience with firmware analysis, fuzzing, or security testing techniques.
- Familiarity with container security in embedded/management environments.
- Knowledge of hardware roots of trust (TPM, DICE) and networking/security in management/data-center contexts.
Education Requirements
Not specified.
About the Company
Company: Arm
Headquarters: Cambridge, United Kingdom
ARM is a global leader in semiconductor and software design, driving innovation in computing technology. The company specializes in designing processors and systems that provide the essential building blocks for electronic devices. ARM's architecture is widely used in smartphones, servers, and IoT devices, and its collaborative culture fosters bold thinking, diversity, and high-impact benefits for its talented workforce.

Date Posted: 2026-07-28