Lead SoC Security Software Engineer

anodize

United States

On-site

USD 180,000 - 240,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Anodize is seeking a Lead SoC Security Software Engineer to own the software foundation for our hardware security. You will bridge firmware, silicon, and cryptography to protect Root of Trust, secure media pathways, and secret storage.

You will architect security primitives across TF-A, secure boot, and kernel interactions, while collaborating with silicon teams to harden against side-channel and fault-injection attacks. This is a high-impact, hands-on leadership role in a stealth startup.

Qualifications

  • 6+ years in SoC/Embedded Security.
  • Experience with ARMv8/v9 and TrustZone.
  • Experience with PKI and hardware-based key storage.
  • Strong C or Rust for constrained environments.

Responsibilities

  • Root of Trust & Secure Boot: Architect and implement the chain of trust from power-on.
  • Secure Subsystem & Cryptography: Firmware for Secure Subsystem / TEE managing keys and cryptographic ops.
  • Encrypted Media Pipelines: Design end-to-end encrypted pathways for media, with DRM/HDCP and memory isolation.
  • Hardware/Software Co-Design: Define security requirements with silicon teams (OTP/eFuses, PUF, crypto accelerators).
  • Vulnerability Hardening: Model threats and implement defenses against physical and logical attacks.

Skills

SoC/Embedded Security
ARM v8/v9
TrustZone
C or Rust
Cryptography

Tools

TF-A
OP-TEE
dm-verity
KVM
eBPF

Job description

Lead SoC Security Software Engineer

We're a well-funded, stealth startup building a new end-to-end personal computing platform based on our own custom silicon. As our Lead SoC Security Software Engineer, you will own the software foundation for our hardware security. You will operate at the intersection of firmware, silicon, and cryptography, architecting the systems that keep our platform private and tamper-proof. You will bridge the gap between hardware primitives and high-level software, ensuring our Root of Trust, secure media pathways, and secrets storage are secure by design.

Responsibilities
  • Root of Trust & Secure Boot: Architect and implement the entire chain of trust from power-on, including TF-A, secure boot sequences, and hardware-backed verification.
  • Secure Subsystem & Cryptography: Build the firmware for our Secure Subsystem / TEE to manage sensitive keys, execute cryptographic operations in isolation, and handle secure provisioning.
  • Encrypted Media Pipelines: Design and enforce end-to-end encrypted pathways for high-value media, integrating DRM and HDCP frameworks while maintaining memory isolation from the application processor.
  • Hardware/Software Co-Design: Work directly with the silicon and hardware teams to define security requirements for IP blocks, including OTP/eFuses, PUF, and crypto accelerators.
  • Vulnerability Hardening: Proactively model threats and implement defenses against physical and logical attacks, including side-channel analysis and fault injection, to ensure our product stays resilient.
Minimum Requirements
  • 6+ years in SoC/Embedded Security: Deep expertise in silicon-level security, firmware engineering, and building secure platforms.
  • ARM Architecture Experience: Hands-on experience with ARM v8/v9, ARM TrustZone, and low-level firmware integration (TF-A, OP-TEE).
  • Cryptography & Key Management: Practical experience implementing PKI, symmetric/asymmetric schemes, and hardware-based secret storage in production environments.
  • Low-Level Software Fluency: Expert-level C or Rust programming for constrained environments; comfortable reading datasheets and debugging assembly.
Preferred Qualifications
  • Experience implementing secure display/video paths, DRM, or memory isolation primitives.
  • Experience hardening firmware against physical side-channel and fault-injection attacks.
  • Background in Linux kernel security (dm-verity, module signing, hypervisors) or TEE development.
  • Experience delivering firmware through the full silicon lifecycle, from tape-out and secure manufacturing to field deployment.
  • Familiarity with Linux kernel fundamentals, KVM, eBPF, and security modules.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

S 105 - Embedded Systems Security Engineer
S 105 - Embedded Systems Security Engineer

Dorle Controls • Foster (OK)

On-site
USD 120,000 - 160,000
Lead SoC Security Architect - Firmware, Crypto & Trust
Lead SoC Security Architect - Firmware, Crypto & Trust

anodize • United States

On-site
USD 180,000 - 240,000
S 105 - Embedded Systems Security Engineer
S 105 - Embedded Systems Security Engineer

Dorleco • Foster City (CA)

On-site
USD 140,000 - 210,000
Embedded Systems Security Engineer
Embedded Systems Security Engineer

RITWIK Infotech Inc • Foster City (CA)

On-site
USD 150,000 - 210,000
Senior Security Architect – Hardware
Senior Security Architect – Hardware

Jobtailor • California (MO)

On-site
USD 180,000 - 240,000
Security Architect
Security Architect

Acceler8 Talent • Mountain View (CA)

Hybrid
USD 180,000 - 280,000
Lead Security & Infrastructure Engineer
Lead Security & Infrastructure Engineer

Anodize • Los Altos (CA), San Francisco (CA)

On-site
USD 150,000 - 210,000
Embedded Systems Security Engineer
Embedded Systems Security Engineer

DeWinter Group • Foster City (CA)

On-site
USD 120,000 - 160,000
Senior SoC Security Architect - Hybrid, Root-of-Trust Focus
Senior SoC Security Architect - Hybrid, Root-of-Trust Focus

Arm • Austin (TX)

Hybrid
USD 198,000 - 268,000
Embedded Systems Security Engineer: Hardware Trust
Embedded Systems Security Engineer: Hardware Trust

Dorleco • Foster City (CA)

On-site
USD 140,000 - 210,000