Senior Software Engineer, Embedded Product Security

Anduril
Irvine
Workplace: OnsiteFull timeUSD 220,000 - 292,000 annuallyFunction: Software EngineeringExperience: 4+ yearsSkills: ["Communication","Stakeholder management","Translating requirements"]

Own the trusted boot chain and runtime hardening for Sentry Tower across NVIDIA Jetson compute generations. Implement firmware and bootloader signing, UEFI Secure Boot, encrypted root filesystems, and HSM-backed key management. Define network and privilege hardening postures, drive CVE tracking and patching for deployed fleets, and translate security requirements into shippable implementations with the product security organization.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Anduril
Anduril
2 days ago

Senior Software Engineer, Embedded Product Security

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Own the trusted boot chain and runtime hardening for Sentry Tower across NVIDIA Jetson compute generations. Implement firmware and bootloader signing, UEFI Secure Boot, encrypted root filesystems, and HSM-backed key management. Define network and privilege hardening postures, drive CVE tracking and patching for deployed fleets, and translate security requirements into shippable implementations with the product security organization.
Location: Irvine
Workplace: Onsite
Employment Type: Full time
Job Function: Software Engineering
Seniority: Mid level

Key Responsibilities

  • •Own the signed boot chain across compute generations: firmware/bootloader signing, UEFI Secure Boot key hierarchies, signed kernel/initrd, and full-disk encryption with automated unlock.
  • •Own signing key management and infrastructure: HSM-backed keys, separation of development/production trust roots, key rotation, and build-time enforcement.
  • •Define and implement platform hardening postures across network exposure/firewall policy, privilege/sudo restrictions, and serial console/USB lockdown.
  • •Drive vulnerability management for the fielded fleet by tracking CVEs against kernel and userspace and owning patching strategy for hardware near end-of-life.
  • •Partner with the product security organization to turn requirements into shippable implementations and support program-specific accreditation efforts.

Pay and Benefits

Salary: USD 220,000 - 292,000 annually

Key Requirements

  • •4+ years of professional software engineering with a security focus on Linux or embedded systems.
  • •Hands-on experience implementing a secure boot chain, including code signing and chain of trust (UEFI Secure Boot or equivalent).
  • •Practical cryptographic engineering skills: PKI/certificate hierarchies, HSM or PKCS#11-backed signing, key lifecycle management, and full-disk encryption.
  • •Strong Linux internals knowledge, including patching, boot flow, kernel/initrd, systemd, privilege boundaries, and filesystem/device access control.
  • •Proficiency in C or Rust and the ability to work fluently in shell; plus practical hardening and vulnerability management on real systems.
Experience:4+ yearsEmbedded systemsLinuxSecurity engineeringFleet patchingDefense technology
Skills:CommunicationStakeholder managementTranslating requirements
Languages:English
Tech Stack:LinuxNVIDIA JetsonUEFI Secure BootHSMPKCS#11PKICRustShellKernelInitrdSystemdFull-disk encryptionUEFINixNixOSBazelBuildrootYoctoTPM

Eligibility

Security Clearance:Secret

Company Brief

Anduril
Designs and builds advanced defense systems combining autonomous aircraft, sensors, and AI-driven software for military and national security applications, focused on modernizing battlefield capabilities and distributed sensing.
Industry: Defense Technology
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series E+
Headquarters: Costa Mesa, United States
Founded: 2017
WebsiteLinkedIn