SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 191,000 - 253,000 / annual
Anduril Industries is a defense technology company transforming U.S. and allied military capabilities through advanced technology. The Air Defense team is responsible for the cryptographic foundation and platform trust that makes Anduril's Air Defense products deployable in the world's most demanding environments.
You will design and implement the cryptographic and platform security that makes Air Defense products trustworthy in contested and classified environments. This is a hands-on engineering role at the lowest levels of the stack, working with FIPS-validated encryption, secure and measured boot, full-disk encryption, anti-tamper and zeroization, and secure communications across degraded links.
Key responsibilities include:
- Implement and improve FIPS 140-3 validated encryption across products — algorithm selection, module boundaries, entropy sources, key derivation, and validation evidence that keeps certification current
- Own the platform trust chain: secure and measured boot (U-Boot/UEFI), TPM-backed attestation, firmware signing, and rollback protection on embedded and edge hardware
- Design and implement full-disk and data-at-rest encryption, key management and rotation, and key hierarchies that survive field conditions
- Build anti-tamper and zeroization: tamper detection and response, emergency erase, key destruction paths, and tests that prove they work under adversarial conditions
- Engineer secure communications — protocol design and review, mTLS and workload identity, tunnels and gateways for cross-domain and air-gapped transport, and CNSA-compliant cipher suites
- Build audit and validation tooling: instrumentation that proves cryptographic and boot-time behavior, plus harnesses, fuzzers, and adversarial tests
- Harden Linux, container, and firmware baselines — kernel configuration, SELinux/AppArmor, attack-surface reduction — and codify them across every deploy
- Automate the compliance surface: express NIST 800-53, STIG, and CNSSI requirements as machine-readable policy evaluated in CI, generating accreditation evidence as build output
You will be the engineer government reviewers talk to when they want a real technical answer — but your output is code, firmware, and systems. The role seeks depth in how systems actually fail: someone who has implemented or attacked crypto, boot chains, and protocols, and who reaches for a debugger and a specification rather than a checklist.
REQUIREMENTS:
- Production-code fluency in C/C++, Rust, Golang, or Python — C or Rust strongly preferred for firmware and cryptographic work — and ability to read and modify the others
- 5-8 years of engineering experience with deep technical ownership of security-critical systems (policy authoring, scan tools, or artifact coordination will not substitute)
- Applied cryptography in practice: implemented or integrated cryptographic libraries, handled keys and entropy correctly, and can explain how a device proves its identity at boot and how that trust is revoked
- Low-level systems depth: Linux kernel and userspace boundary, memory, filesystems, device drivers or firmware, and ability to debug with gdb, ftrace, and logic analyzers
- Experience assessing and hardening firmware, embedded, or cyber-physical systems, with demonstrated understanding of how skilled adversaries attack them
- Secure communications and network protocol work: TLS/PKI internals, tunneling, and what breaks in disconnected or degraded networks
- Experience building and sustaining CI/CD systems; treating pipelines and infrastructure as software with version control, review, and tests
- Working command of RMF and NIST 800-53 — enough to know exactly what an assessor needs and to automate producing it
- Currently possesses and is able to maintain an active U.S. Top Secret security clearance; TS/SCI with polygraph preferred
PREFERRED QUALIFICATIONS:
- 8+ years of relevant engineering experience, or equivalent depth from a national-security cryptographic or capabilities-development background
- Direct experience with FIPS 140-2/140-3 validation, CSfC, Type 1 encryption, HAIPE, or KMI
- CNSA 2.0 / Suite B implementation, or post-quantum cryptography migration work
- Vulnerability research, reverse engineering, exploit development, or hardware attack experience (fault injection, side channel, JTAG/SWD)
- Anti-tamper, TEMPEST, or physical security engineering for deployed systems
- Embedded and edge depth: U-Boot/UEFI, TPM/TEE (OP-TEE, TrustZone), secure elements, and realities of constrained or intermittently connected devices
- Rust or Golang shipped at production scale in a security-critical component, or took a system through ATO or IATT as the responsible engineer
- Policy-as-code at scale (OSCAL, OPA/Rego, OpenSCAP, InSpec), plus Terraform, Ansible or Nix, and Kubernetes hardening
- Degree in Computer Science, Computer Engineering, Cybersecurity, or related discipline — or equivalent demonstrated experience. Familiarity with NISPOM (32 CFR Part 117), DAAPM, JSIG, and CNSSI 1253 is a plus