3 months ago
Abu Dhabi, United Arab EmiratesSenior
Responsibilities
- Review product security designs, document missing controls, and drive security improvement analysis.
- Execute threat modeling, attack surface enumeration, and attack tree creation for embedded products.
- Research and propose technologies aligned with client requirements and strategies.
- Conduct source code audits, functional testing, fuzz testing, and other end-to-end security posture assessments.
- Verify implementations against product security architectures, requirements, and threat models.
- Document and present product security risks in technical and business-oriented language.
- Support a team of two to three security engineers and consultants assessing emerging technologies and products.
- Collaborate with client development and security teams and partners across engagements and projects.
Requirements
- Bachelor's or master's degree in Electrical Engineering, Computer Science, Computer Engineering, or Electronics Engineering, or equivalent practical experience.
- At least four years of experience in embedded, general-purpose, or special-purpose computer system-level software security.
- Experience developing, auditing, or testing security solutions for embedded, IoT, general computing, or mobile systems.
- Experience with embedded systems, Linux, or real-time operating system security concepts.
- Experience reviewing system security architecture and related technologies.
- Experience with ARM architecture and debugging software on ARM platforms.
- Experience with C, C++, Rust, or ARM Assembly in system software such as bootloaders, drivers, kernels, or system services.
- Experience with secure boot, firmware and software integrity, OTA updates, and hardware-backed device attestation.
- Experience with cryptographic primitives and security practices including encryption, attestation, key rooting, derivation, and key wrapping.
- Experience identifying and reporting system software vulnerabilities, including memory corruption and side-channel attacks.
- Familiarity with hardware-backed security features, security domains, and trust-boundary separation.
- Familiarity with TEE, TPM, SE, SPU, and related technologies.
- Experience working with international teams across regions and time zones.
- Proficiency in English, strong communication skills, analytical thinking, problem-solving ability, and willingness to learn.
Benefits
- On-site role, as indicated by the posting's #LI-Onsite designation.
- Work involves international teams across regions and worldwide time zones.
