Arm

Principal Platform Security Architect -Firmware & Operating Systems

Arm
Apply
4 months ago
Cambridge, United KingdomStaff+

Responsibilities

  • Evaluate and integrate security mechanisms across BIOS, BMC, and device firmware, including secure boot, firmware verification, update flows, rollback protection, and debug controls.
  • Improve the security of embedded Linux and BMC management environments through system hardening, service isolation, access control, and secure configuration.
  • Identify attack surfaces and configuration gaps and apply and validate hardening measures and secure defaults.
  • Develop validation tools and scripts and integrate security checks into CI workflows with security evaluation and engineering teams.
  • Support threat modeling and analysis of firmware and management-plane components.

Requirements

  • Hands-on experience building and customizing embedded Linux platforms with Yocto/OpenEmbedded.
  • Hands-on experience implementing and validating Linux hardening controls, including service and interface hardening, privilege management, and attack-surface reduction.
  • Experience implementing or integrating security controls in firmware or embedded environments.
  • Strong understanding of BIOS/UEFI, bootloaders, platform firmware components, secure boot chains, firmware verification, firmware updates, signing, and rollback protection.
  • Familiarity with Arm architecture, early boot stages, firmware-hardware interaction, PCIe, and platform security considerations.
  • Experience developing automation, validation tools, or scripts and integrating them into CI workflows.
  • Proficiency in C/C++ for systems or embedded development and ability to work with low-level components.
  • Understanding of Linux authentication, authorization, system protections, file-system and data-protection mechanisms, including eCryptfs or similar approaches.
  • Ability to analyze firmware and system-level attack surfaces.
  • Nice-to-have experience includes BMC platforms such as OpenBMC, SELinux, AppArmor, Linux capabilities, firmware analysis, fuzzing, security testing, container security, TPM, DICE, networking, and network security.

Benefits

  • Relocation package, including visa sponsorship support, is available for candidates who require it.
  • Hybrid working patterns are determined by the team, with role-specific details provided during the application process.
  • Recruitment accommodations are available for applicants who need them.

Tech Stack

Arm

About Arm

5,001-10,000 employees

Arm’s foundational technology is defining the future of computing. A future built by the greatest technology ecosystem in the world. A future built on Arm. Arm is everywhere technology matters. Technology matters everywhere. Together, we’ll power every technology revolution moving forward, including cloud computing, automotive and autonomous systems, IoT, the metaverse, and beyond. Changing the world. Again. On Arm.

Contact me