Job Title
Principal Product Security Architect
Role Summary
Lead interactions with external security laboratories and certification bodies to plan, execute, and close security evaluations and certification programs for Arm products. As a senior member of Product Security, you will coordinate cross-functional teams to ensure products meet industry-standard evaluation methodologies and regulatory requirements.
Experience Level
Senior — typically 10+ years in product security, security evaluation, certification, or related fields.
Responsibilities
Accountable for running and validating formal product security evaluations and maintaining certification readiness.
- Act as the primary technical contact with accredited third-party security laboratories.
- Lead end-to-end security evaluation and certification programs: plan, execute, document, and close activities.
- Prepare, review, and deliver evidence, test vectors, and artefacts required for certification on schedule.
- Review and validate lab findings; manage corrective actions and retesting.
- Maintain up-to-date certification and evaluation documentation and workflows.
- Track and interpret evolving certification standards (e.g., Common Criteria, PSA Certified, SESIP, FIPS, ISO 21434, IEC 62443).
- Provide internal guidance and mentoring on evaluation methodologies and certification readiness.
Requirements
Must-have qualifications and experience required to perform the role:
- 10+ years of experience in product security, security evaluation, certification, or a related field.
- Strong understanding of security evaluation schemes such as Common Criteria, SESIP, PSA Certified, FIPS 140-3, ISO 21434, EU-CRA or similar frameworks.
- Proven experience collaborating with external security laboratories and managing formal evaluation processes.
- Knowledge of cryptographic primitives, secure key lifecycle management, and secure provisioning workflows.
- Experience with silicon/SoC security architecture, including threat modelling, attacker models, and countermeasures.
- Good organizational, communication, negotiation, and documentation skills; ability to manage multi-stakeholder projects.
Nice-to-have:
- Experience with secure hardware components (cryptography accelerators, Root-of-Trust modules, HSMs, secure enclaves).
- Experience with secure firmware components (secure boot ROM, bootloader, TFM/TF-A, OP-TEE, hypervisor environments).
- Practical knowledge of semiconductor manufacturing flows and supply chain security.
- Familiarity with side-channel analysis, fault-injection testing, and hardware penetration testing methodologies.
Education Requirements
Not specified.
About the Company
Company: Arm
Headquarters: Cambridge, United Kingdom
ARM is a global leader in semiconductor and software design, driving innovation in computing technology. The company specializes in designing processors and systems that provide the essential building blocks for electronic devices. ARM's architecture is widely used in smartphones, servers, and IoT devices, and its collaborative culture fosters bold thinking, diversity, and high-impact benefits for its talented workforce.

Date Posted: 2026-07-31