Staff Security Engineer - Fuzzing Specialist

Arm

Cambridge

Hybrid

GBP 70,000 - 90,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

A leading technology firm in Cambridge is seeking a Staff Security Engineer – Fuzzing Specialist to enhance security through advanced fuzzing techniques. The successful candidate will design and develop fuzzing harnesses, triage crashes, and contribute to documentation and reporting. Ideal applicants have 1+ years of relevant experience, proficiency in C/C++ and Python, and expertise with modern fuzzing frameworks. This role supports a hybrid working model, fostering collaboration and innovation in product security.

Qualifications

  • 1+ years in application or product security focusing on fuzzing.
  • Expertise with fuzzing frameworks (e.g., libFuzzer, AFL++).
  • Strong skills in programming languages C/C++ and scripting in Python.
  • Understanding of memory-safety vulnerabilities and compiler instrumentation.
  • Ability to triage crashes with debugging tools.

Responsibilities

  • Map and prioritize fuzzing surfaces across different services.
  • Design and improve fuzzing harnesses to enhance code coverage.
  • Automate crash reporting and drive resolution of findings.
  • Develop custom sanitizers for bugs missed by traditional fuzzing.
  • Document insights and metrics to inform security practices.

Skills

Coverage-guided fuzzing
C/C++ programming
Python scripting
Memory-safety vulnerabilities
Documentation and communication

Tools

libFuzzer
AFL++
Honggfuzz
GDB
IDA

Job description

Staff Security Engineer – Fuzzing Specialist

Join to apply for the Staff Security Engineer – Fuzzing Specialist role at Arm.

Job Overview

As a Security Engineer – Fuzzing Specialist, you will own and evolve our coverage‑guided fuzzing program. Your mission is to uncover hard‑to‑reach security flaws before attackers do, drive fixes to closure, and help product teams embrace dynamic testing like fuzzing. You’ll scout for new attack surfaces, craft high‑performance fuzzing harnesses, and design custom sanitizers that push the state of the art. Success means measurable coverage gains, actionable crash reports, and products that ship with provable resilience.

Responsibilities
  • Map & prioritise fuzzing surfaces across services, libraries, APIs, and protocols; maintain a living risk‑based roadmap.
  • Design, build, and extend fuzzing harnesses (libFuzzer, AFL++, Honggfuzz, etc.) that improve code‑path exploration and minimise false positives.
  • Continuously improve coverage by growing seed corpus, deploying targeted mutation strategies, and integrating new instrumentation techniques.
  • Automate crash triage & root‑cause analysis; distinguish exploitable vulnerabilities from benign faults and drive CVE‑level findings to remediation.
  • Develop custom sanitizers to expose classes of bugs traditional fuzzing misses.
  • Validate fixes & guard against regressions through differential fuzzing and regression corpora.
  • Assess external disclosures (bug bounties, supply‑chain advisories) to determine fuzzing detectability and refine harnesses when gaps are found.
  • Document, report, and share insights – from coverage metrics to post‑mortems to create data‑driven security forms.
Required Skills and Experience
  • 1+ years in application or product security with a deep focus on coverage‑guided fuzzing.
  • Hands‑on expertise with at least one modern fuzzing framework (e.g., libFuzzer, AFL++, Honggfuzz).
  • Proficient in C/C++ plus strong scripting ability in Python for automation.
  • Solid understanding of memory‑safety vulnerabilities, undefined behaviour, sanitizers, and compiler instrumentation.
  • Demonstrated ability to triage crashes using debuggers, profilers, and reverse‑engineering tools (gdb/lldb, IDA/Ghidra).
  • Excellent written communication for documenting findings and influencing engineering teams.
Nice to Have Skills and Experience
  • Contributions to open‑source fuzzing tools, sanitizers, or security research publications.
  • Knowledge of distributed fuzzing at scale (GCP/AWS, Kubernetes, or bare‑metal clusters).
  • FamiliarityTraited with kernel, embedded, or firmware fuzzing (e.g., Syzkaller, QEMU‑based harnesses).
  • Background in reverse engineering, static analysis or symbolic execution.
  • Experience integrating fuzzing into CI/CD pipelines and tracking coverage metrics.

If you’re passionate about breaking software safely, love high‑coverage charts, and want to make a measurable dent in product security, we’d love to hear Анд.

Accommodations at Arm

At Arm, we want to build extraordinary teams. If you need an adjustment or an accommodation during the recruitment process, please email accommodations@arm.com. By sending us the requested information, you consent to its use by Arm to arrange appropriate accommodations. All accommodation or adjustment requests will be treated with confidentiality, and information concerning these requests will only be disclosed as necessary to provide the accommodation.

Hybrid Working at Arm

Arm’s approach to hybridPapa… (brief overview of hybrid working).

Equal Opportunities at Arm

Arm is an equal opportunity employer, committed to providing an environment of mutual respect where equal opportunities are available to all applicants and colleagues. We are a diverse organization of dedicated and innovative individuals, and don’t discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability,-Germain protected veteran.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Engineer - Fuzzing Specialist
Principal Security Engineer - Fuzzing Specialist

Arm Limited • Cambridge

Hybrid
GBP 50,000 - 70,000
Principal Security Engineer - Fuzzing Specialist
Principal Security Engineer - Fuzzing Specialist

Camwebdir • United Kingdom

Hybrid
GBP 90,000 - 140,000
Lead Fuzzing Security Engineer (Hybrid)
Lead Fuzzing Security Engineer (Hybrid)

Camwebdir • United Kingdom

Hybrid
GBP 90,000 - 140,000
Senior Product Security Engineer
Senior Product Security Engineer

Arm Limited • Cambridge

Hybrid
GBP 90,000 - 130,000
Staff Full Stack Software Engineer
Staff Full Stack Software Engineer

Arm Limited • Cambridge

Hybrid
GBP 90,000 - 120,000
Staff Full Stack Software Engineer
Staff Full Stack Software Engineer

Camwebdir • United Kingdom

Hybrid
GBP 85,000 - 120,000
Staff Linux Support Engineer
Staff Linux Support Engineer

Arm Limited • Cambridge

Hybrid
GBP 50,000 - 75,000
Hybrid working
Senior Product Security Engineer
Senior Product Security Engineer

Arm Limited • Cambridge

Hybrid
GBP 60,000 - 80,000
Staff Linux Support Engineer
Staff Linux Support Engineer

Camwebdir • United Kingdom

Hybrid
GBP 60,000 - 90,000
Staff Hardware Security Engineer
Staff Hardware Security Engineer

Camwebdir • United Kingdom

Hybrid
GBP 90,000 - 130,000
Hybrid working
Recruitment accommodations