Job Title
Senior Product Security Engineer
Role Summary
Evaluate and improve the security posture of SoC and embedded firmware products by assessing system architectures, reviewing firmware code, threat-modeling, and performing targeted tests. Work with hardware, firmware and product teams to define secure boot, key management, isolation, and update flows.
Experience Level
Senior
Responsibilities
Primary responsibilities include:
- Review firmware and SoC architectures to identify security risks and create threat models.
- Assess critical security features such as secure boot, rollback protection, memory isolation, and TEEs.
- Perform C/C++ security code reviews to find implementation-level flaws.
- Design and validate secure firmware architectures for key handling and update flows.
- Conduct targeted hands-on tests (including advanced attack surfaces when required) to validate security concerns.
- Collaborate with cross-functional teams to embed security into the development lifecycle.
- Communicate risks and remediation clearly to technical and non-technical stakeholders.
Requirements
Must-have:
- Proven experience securing hardware–firmware interfaces or embedded systems.
- Hands-on expertise in C/C++ security code reviews and firmware hardening.
- Experience with secure boot, key provisioning, trusted computing and firmware update flows.
- Understanding of firmware attack surfaces such as fault injection, code injection, and privilege escalation.
- Familiarity with isolation technologies (e.g., Arm TrustZone, secure monitor, memory protection).
- Ability to run and interpret quick, targeted tests to verify security assumptions.
- Strong collaboration, communication, and documentation skills.
Nice-to-have:
- Familiarity with hardware design flows (RTL, UVM/SystemVerilog).
- Exposure to TPMs, Secure Elements, or hardware-backed crypto modules.
- Experience with vulnerability discovery or public CVEs, or academic/industry research in embedded security.
- Experience evaluating products against certification schemes such as SESIP, PSA Certified, or Common Criteria.
Education Requirements
Not specified.
About the Company
Company: Arm
Headquarters: Cambridge, United Kingdom
ARM is a global leader in semiconductor and software design, driving innovation in computing technology. The company specializes in designing processors and systems that provide the essential building blocks for electronic devices. ARM's architecture is widely used in smartphones, servers, and IoT devices, and its collaborative culture fosters bold thinking, diversity, and high-impact benefits for its talented workforce.

Date Posted: 2026-07-28