Senior Software Engineer, Embedded Product Security

Anduril-1

Irvine (CA)

On-site

USD 220,000 - 292,000

Full time

43 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Equity grants
Competitive benefits

Job summary

Anduril Industries seeks a Senior Software Engineer to own product security for embedded towers. You’ll implement the trusted boot chain, sign firmware, manage keys with an HSM, and enforce full-disk encryption across NVIDIA Jetson hardware.

You’ll also define runtime hardening, patching strategies for fielded fleets, and collaborate with our product security team to translate requirements into shippable, verifiable protections.

Qualifications

  • 4+ years of professional software engineering with a security focus on Linux or embedded systems.
  • Hands-on experience implementing a secure boot chain: code signing, chain of trust, UEFI Secure Boot or equivalent.
  • Practical cryptographic engineering skills: PKI/hierarchies, HSM or PKCS#11 signing, key lifecycle, and full-disk encryption.
  • Strong Linux internals knowledge: patching, boot flow, kernel/initrd, systemd, access control.
  • Proficiency in C or Rust, and shell fluency.
  • Hardening and vulnerability-management experience on real systems: CVE triage, live patching strategies.
  • US person status and eligibility for security clearance.

Responsibilities

  • Own the signed boot chain across compute generations and manage key signing workflows.
  • Define and implement hardening postures, including network exposure, privileges, and interfaces.
  • Drive vulnerability management for the fielded fleet and patching strategies.
  • Collaborate with product security to translate requirements into shipable implementations.
  • Support accreditation efforts and act as security liaison for programs.

Skills

Secure boot implementation
Linux internals
C and Rust programming
Shell scripting
Cryptographic engineering
Vulnerability management
Clear communication
US person status

Tools

NVIDIA Jetson secure boot

Job description

Senior Software Engineer, Embedded Product Security

Irvine, California, United States

Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.

About The Team

The Sentry Tower Software team develops robotic systems that provide force protection capabilities, monitoring the perimeter of secure areas, land or sea, for approaching people, vehicles, and vessels. We live in a world where security officers are increasingly overwhelmed by sensor data feeds. Our products leverage advanced sensor fusion and autonomy to seamlessly render activity in the environment to Lattice’s common operating picture.

About the Job

Sentry Towers are deployed to secure perimeters, some in contexts where the tower itself is a sensitive asset and physical access by an adversary is a realistic threat. That makes product security a hardware-and-software problem, not a policy exercise: if someone can pull a drive, attach a serial cable, plug in USB, or interrupt the bootloader, the design has to hold. We’re hiring a Senior Software Engineer to own product security for the tower platform.

You’ll own the trusted boot chain top to bottom, on NVIDIA Jetson compute across several generations. That means signed firmware and bootloaders, UEFI Secure Boot, signed kernel images, encrypted root filesystems, and the key management that makes it real: hardware-security-module-backed signing keys, separate development and production trust roots, and the release pipeline that signs what we ship.

Alongside the boot chain, you’ll own runtime hardening posture: what’s exposed on the network, what privileges the operator account holds, which physical interfaces are live in the field versus on a lab bench, and how a fielded fleet gets security patches on hardware whose vendor support is ending. You’ll work closely with our internal product security organization, translating requirements into implementations that ship, and reviewing our design decisions early, while they are still cheap to change.

Two things about this role are worth saying plainly. Security work is often the work of saying no, or of saying “not like that”, to engineers under schedule pressure who are not wrong to want to move faster; doing that well without becoming an obstacle is most of the craft. And the feedback loop is slow by construction: signed images cannot be built on your laptop, so the build farm is the gate, and you will wait on it. Some of the job is also inherited rather than chosen, including hardware whose vendor support is ending on a fixed date that will not move for us.

  • Own the signed boot chain across compute generations: firmware and bootloader signing, UEFI Secure Boot key hierarchies, signed kernel and initrd, and full-disk encryption with automated unlock.
  • Own signing key management and the infrastructure behind it: HSM-backed keys, separation of development and production trust roots, key rotation, and build-time enforcement that the right keys sign the right artifacts.
  • Define and implement the platform’s hardening postures, spanning network exposure and firewall policy, privilege and sudo restriction, serial console and USB lockdown, and the difference between a locked-down fielded system and a debuggable bench unit.
  • Drive vulnerability management for the fielded fleet: track CVEs (Common Vulnerabilities and Exposures) against our kernel and userspace, own the patching strategy for hardware approaching vendor end-of-life, and keep a clear picture of fleet security state.
  • Partner with our product security organization to turn security requirements into shippable implementations, act as our team’s security liaison, and support program-specific accreditation efforts.
REQUIRED QUALIFICATIONS
  • 4+ years of professional software engineering with a security focus on Linux or embedded systems.
  • Hands-on experience implementing a secure boot chain: code signing, chain of trust, UEFI Secure Boot or an equivalent vendor secure boot implementation.
  • Practical cryptographic engineering skills: PKI and certificate hierarchies, HSM or PKCS#11-backed signing, key lifecycle management, and full-disk encryption.
  • Strong Linux internals knowledge, particularly in patching, boot flow, kernel and initrd, systemd, privilege boundaries, and filesystem and device access control.
  • Proficiency in C or Rust, plus the ability to work fluently in shell.
  • Practical hardening and vulnerability-management experience on real systems: attack-surface reduction, CVE triage on a deployed fleet, and live patching strategies that don’t break the product.
  • Ability to explain a security decision to engineers who need to implement it, and to a program stakeholder who needs to accept the residual risk.
  • US person status required. Active US Secret clearance, or a previously granted Secret clearance eligible for reactivation.
NICE TO HAVE
  • Experience with NVIDIA Jetson secure boot specifically, or with another SoC vendor’s secure boot and fusing workflow.
  • Familiarity with measured boot, TPMs, or remote attestation.
  • Experience with declarative configuration and reproducible builds. Nix or NixOS is what we use and what we most want to see; adjacent depth in Bazel, Buildroot, or Yocto is a solid substitute.
  • Background in defense or government accreditation processes, or work against a formal security controls framework.
  • Offensive security experience, including hardware attacks such as bus sniffing, glitching, or JTAG and boot interruption.
  • Experience with supply chain security, artifact provenance, or SBOM tooling.

US Salary Range

$220,000 - $292,000 USD

The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril's total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including:

At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you’re supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits .

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.

As set forth in Anduril Industries’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Software Engineer, Embedded Product Security
Senior Software Engineer, Embedded Product Security

Triwill Group • Irvine (CA)

On-site
USD 220,000 - 292,000
Senior Software Engineer, Embedded Product Security
Senior Software Engineer, Embedded Product Security

AI Chopping Block • Irvine (CA), Northern (KY)

On-site
USD 220,000 - 292,000
Security Software Engineer, Endpoint Security
Security Software Engineer, Endpoint Security

Anduril-1 • Boston (MA)

On-site
USD 166,000 - 220,000
Senior Software Engineer, Greenfield Product
Senior Software Engineer, Greenfield Product

Anduril-1 • Costa Mesa (CA)

On-site
USD 152,000 - 253,000
Senior Software Engineer, Embedded Product Security
Senior Software Engineer, Embedded Product Security

Linuxconfig • Irvine (CA), Northern (KY)

Hybrid
USD 220,000 - 292,000
Principal Software Engineer, InfraEng Platform Team
Principal Software Engineer, InfraEng Platform Team

Anduril-1 • Seattle (WA)

On-site
USD 253,000 - 336,000
Staff Software Engineer, Discovery
Staff Software Engineer, Discovery

Anduril-1 • Boston (MA)

On-site
USD 220,000 - 292,000
Equity grants
Comprehensive benefits
Production Software Engineer
Production Software Engineer

Anduril-1 • Waltham (MA)

On-site
USD 166,000 - 220,000
Equity grants
Comprehensive benefits
Manufacturing Engineer, Production, Sentry
Manufacturing Engineer, Production, Sentry

Anduril-1 • Irvine (CA)

On-site
USD 129,000 - 171,000
Equity grants
Benefits package
Senior Vulnerability Engineer
Senior Vulnerability Engineer

Anduril Industries, Inc. • Boston (MA)

On-site
USD 152,000 - 253,000