Senior Software Engineer, Embedded Product Security

Anduril

Irvine (CA)

On-site

USD 140,000 - 210,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Anduril Industries is seeking a Senior Software Engineer to own product security for the Sentry Tower platform. You will secure boot, runtime hardening, and key management across NVIDIA Jetson compute, integrating signed firmware, encrypted root FS, and trusted updates.

You will collaborate with our product security team to translate requirements into shippable implementations, manage CVE tracking, and ensure fleet resilience against end-of-life hardware while maintaining a practical balance

Qualifications

  • 4+ years of professional software engineering with a security focus on Linux or embedded systems.
  • Hands-on experience implementing a secure boot chain: code signing, chain of trust, UEFI Secure Boot or vendor secure boot.
  • Practical cryptographic engineering: PKI, certificate hierarchies, HSM or PKCS#11-backed signing, key lifecycle management, and full-disk encryption.
  • Strong Linux internals knowledge: patching, boot flow, kernel/initrd, systemd, privilege boundaries, filesystem/device access control.
  • Proficiency in C or Rust, with fluency in shell.

Responsibilities

  • Own the signed boot chain across compute generations: firmware and bootloader signing, Secure Boot hierarchies, signed kernel/initrd, and full-disk encryption.
  • Own signing key management and infrastructure: HSM-backed keys, separation of development/production roots, key rotation, and build-time enforcement of correct signing.
  • Define and implement platform hardening postures: network exposure, privileges, serial console/USB lockdown, fielded vs bench configurations.
  • Drive vulnerability management for the fleet: track CVEs, patching strategy for hardware nearing end-of-life, maintain fleet security state.
  • Partner with product security to translate requirements into implementations and support accreditation efforts.

Skills

Secure boot
PKI
C or Rust
Linux internals
Security engineering

Job description

Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century's most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril's family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.

About The Team

The Sentry Tower Software team develops robotic systems that provide force protection capabilities, monitoring the perimeter of secure areas, land or sea, for approaching people, vehicles, and vessels. We live in a world where security officers are increasingly overwhelmed by sensor data feeds. Our products leverage advanced sensor fusion and autonomy to seamlessly render activity in the environment to Lattice's common operating picture.

About the Job

Sentry Towers are deployed to secure perimeters, some in contexts where the tower itself is a sensitive asset and physical access by an adversary is a realistic threat. That makes product security a hardware-and-software problem, not a policy exercise: if someone can pull a drive, attach a serial cable, plug in USB, or interrupt the bootloader, the design has to hold. We're hiring a Senior Software Engineer to own product security for the tower platform.

You’ll own the trusted boot chain top to bottom, on NVIDIA Jetson compute across several generations. That means signed firmware and bootloaders, UEFI Secure Boot, signed kernel images, encrypted root filesystems, and the key management that makes it real: hardware-security-module-backed signing keys, separate development and production trust roots, and the release pipeline that signs what we ship.

Alongside the boot chain, you’ll own runtime hardening posture: what's exposed on the network, what privileges the operator account holds, which physical interfaces are live in the field versus on a lab bench, and how a fielded fleet gets security patches on hardware whose vendor support is ending. You’ll work closely with our internal product security organization, translating requirements into implementations that ship, and reviewing our design decisions early, while they are still cheap to change.

Two things about this role are worth saying plainly. Security work is often the work of saying no, or of saying "not like that", to engineers under schedule pressure who are not wrong to want to move faster; doing that well without becoming an obstacle is most of the craft. And the feedback loop is slow by construction: signed images cannot be built on your laptop, so the build farm is the gate, and you will wait on it. Some of the job is also inherited rather than chosen, including hardware whose vendor support is ending on a fixed date that will not move for us.

Our Product: https://www.anduril.com/sentry

WHAT YOU'LL DO
  • Own the signed boot chain across compute generations: firmware and bootloader signing, UEFI Secure Boot key hierarchies, signed kernel and initrd, and full-disk encryption with automated unlock.
  • Own signing key management and the infrastructure behind it: HSM-backed keys, separation of development and production trust roots, key rotation, and build-time enforcement that the right keys sign the right artifacts.
  • Define and implement the platform's hardening postures, spanning network exposure and firewall policy, privilege and sudo restriction, serial console and USB lockdown, and the difference between a locked-down fielded system and a debuggable bench unit.
  • Drive vulnerability management for the fielded fleet: track CVEs (Common Vulnerabilities and Exposures) against our kernel and userspace, own the patching strategy for hardware approaching vendor end-of-life, and keep a clear picture of fleet security state.
  • Partner with our product security organization to turn security requirements into shippable implementations, act as our team's security liaison, and support program-specific accreditation efforts.
REQUIRED QUALIFICATIONS
  • 4+ years of professional software engineering with a security focus on Linux or embedded systems.
  • Hands-on experience implementing a secure boot chain: code signing, chain of trust, UEFI Secure Boot or an equivalent vendor secure boot implementation.
  • Practical cryptographic engineering skills: PKI and certificate hierarchies, HSM or PKCS#11-backed signing, key lifecycle management, and full-disk encryption.
  • Strong Linux internals knowledge, particularly in patching, boot flow, kernel and initrd, systemd, privilege boundaries, and filesystem and device access control.
  • Proficiency in C or Rust, plus the ability to work fluently in shel
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software Engineer, Embedded Product Security
Senior Software Engineer, Embedded Product Security

Linuxconfig • Irvine (CA), Northern (KY)

Hybrid
USD 220,000 - 292,000
Senior Cyber Software Engineer
Senior Cyber Software Engineer

Engg • Irvine (CA), Washington

On-site
USD 180,000 - 240,000
Senior Software Engineer, Embedded Product Security
Senior Software Engineer, Embedded Product Security

Triwill Group • Irvine (CA)

On-site
USD 220,000 - 292,000
Senior Software Engineer, Embedded Product Security
Senior Software Engineer, Embedded Product Security

Anduril Industries • Irvine (CA)

On-site
USD 220,000 - 292,000
Senior Software Engineer, Compute Platform Integration
Senior Software Engineer, Compute Platform Integration

Slope • Irvine (CA)

On-site
USD 140,000 - 190,000
Senior Embedded Security Engineer: Secure Boot & Hardening
Senior Embedded Security Engineer: Secure Boot & Hardening

Anduril • Irvine (CA)

On-site
USD 140,000 - 210,000
Senior Embedded Linux Software Engineer – Robotics Platform (DeviceOS)
Senior Embedded Linux Software Engineer – Robotics Platform (DeviceOS)

Triwill Group • Costa Mesa (CA)

On-site
USD 191,000 - 253,000
Equity grants
Comprehensive benefits
Embedded Linux Software Engineer – Robotics Platform (DeviceOS)
Embedded Linux Software Engineer – Robotics Platform (DeviceOS)

Anduril • Costa Mesa (CA)

On-site
USD 166,000 - 220,000
Senior Embedded Linux Software Engineer – Robotics Platform (DeviceOS)
Senior Embedded Linux Software Engineer – Robotics Platform (DeviceOS)

Anduril • Costa Mesa (CA)

On-site
USD 191,000 - 253,000
Senior Embedded Linux Software Engineer – Robotics Platform (DeviceOS)
Senior Embedded Linux Software Engineer – Robotics Platform (DeviceOS)

Anduril-1 • Costa Mesa (CA)

On-site
USD 191,000 - 253,000
Benefits package