Arm logo

Senior Product Security Engineer

Arm
July 31, 2026
Full-time
Remote friendly (Cambridge, ENG, United Kingdom)
Worldwide
£73,500 - £99,500 GBP yearly
Other Semiconductor Jobs, Level - Senior

Job Title

Senior Product Security Engineer

Role Summary

Evaluate and improve the security posture of SoC and embedded firmware products by assessing system architectures, reviewing firmware code, threat-modeling, and performing targeted tests. Work with hardware, firmware and product teams to define secure boot, key management, isolation, and update flows.

Experience Level

Senior

Responsibilities

Primary responsibilities include:

  • Review firmware and SoC architectures to identify security risks and create threat models.
  • Assess critical security features such as secure boot, rollback protection, memory isolation, and TEEs.
  • Perform C/C++ security code reviews to find implementation-level flaws.
  • Design and validate secure firmware architectures for key handling and update flows.
  • Conduct targeted hands-on tests (including advanced attack surfaces when required) to validate security concerns.
  • Collaborate with cross-functional teams to embed security into the development lifecycle.
  • Communicate risks and remediation clearly to technical and non-technical stakeholders.

Requirements

Must-have:

  • Proven experience securing hardware–firmware interfaces or embedded systems.
  • Hands-on expertise in C/C++ security code reviews and firmware hardening.
  • Experience with secure boot, key provisioning, trusted computing and firmware update flows.
  • Understanding of firmware attack surfaces such as fault injection, code injection, and privilege escalation.
  • Familiarity with isolation technologies (e.g., Arm TrustZone, secure monitor, memory protection).
  • Ability to run and interpret quick, targeted tests to verify security assumptions.
  • Strong collaboration, communication, and documentation skills.

Nice-to-have:

  • Familiarity with hardware design flows (RTL, UVM/SystemVerilog).
  • Exposure to TPMs, Secure Elements, or hardware-backed crypto modules.
  • Experience with vulnerability discovery or public CVEs, or academic/industry research in embedded security.
  • Experience evaluating products against certification schemes such as SESIP, PSA Certified, or Common Criteria.

Education Requirements

Not specified.


About the Company

Company: Arm

Headquarters: Cambridge, United Kingdom

ARM is a global leader in semiconductor and software design, driving innovation in computing technology. The company specializes in designing processors and systems that provide the essential building blocks for electronic devices. ARM's architecture is widely used in smartphones, servers, and IoT devices, and its collaborative culture fosters bold thinking, diversity, and high-impact benefits for its talented workforce.

Arm logo

Date Posted: 2026-07-28