Arm logo

Principal Product Security Engineer

Arm
July 31, 2026
Full-time
On-site
Cambridge, ENG, United Kingdom
Test Engineering Jobs, Level - Senior

Job Title

Principal Product Security Engineer

Role Summary

Lead Arm's offensive software security efforts for firmware, drivers and system software with primary focus on fuzzing and penetration testing. Define and operate software security test frameworks and penetration-test strategy across product teams.

This role provides technical leadership to security test engineers and drives measurable reduction of software vulnerabilities in Arm-based systems.

Experience Level

Senior / Principal level. Senior technical leadership and significant hands-on experience in offensive software security and product-level security assessments are expected. No explicit years-of-experience specified.

Responsibilities

Core responsibilities include designing and executing offensive security testing across system software and leading related activities:

  • Develop and maintain software security test frameworks and processes for firmware, drivers and system software.
  • Define and lead internal penetration-test strategy for Arm software products.
  • Plan, prioritise and conduct software security tests including fuzzing and exploit development.
  • Lead and mentor security test engineers within the Product Security team and across the organisation.
  • Coordinate test schedules and ensure findings are triaged and tracked to remediation.

Requirements

Must-have technical skills and experience to perform the role:

  • Deep experience in design, development, documentation and testing of low-level software (firmware, drivers).
  • Strong understanding of SoC security fundamentals: secure boot, measured boot, attestation, signing, Root of Trust.
  • Proven track record leading software security assessments and penetration testing at SoC or system level.
  • Demonstrated ability to find and prioritise real-world security vulnerabilities.
  • Proficiency with low-level and systems programming languages such as C/C++, Rust and scripting in Python.
  • Practical experience in offensive security research, vulnerability discovery and exploit development.
  • Familiarity with Arm assembly and Arm-based SoCs and devices.
  • Experience running and leading fuzz-testing activities and associated tooling.
  • Technical leadership, strong interpersonal and communication skills.

Nice-to-have:

  • Experience with security evaluation for external certifications (Common Criteria, PSA, SESIP, FIPS).
  • Participation in CTFs, hackathons, or published offensive security research.
  • Experience evaluating Linux kernel, Android OS, Windows systems/drivers, or GPU/CPU/system firmware security.

Education Requirements

The posting lists professional certifications such as OSCP and OSEE as nice-to-have. No specific degree, field-of-study, or mandatory academic credential is stated.


About the Company

Company: Arm

Headquarters: Cambridge, United Kingdom

ARM is a global leader in semiconductor and software design, driving innovation in computing technology. The company specializes in designing processors and systems that provide the essential building blocks for electronic devices. ARM's architecture is widely used in smartphones, servers, and IoT devices, and its collaborative culture fosters bold thinking, diversity, and high-impact benefits for its talented workforce.

Arm logo

Date Posted: 2026-07-11