SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Software Engineer (Android VMs)

Anduril - Bellevue, WA, United States - In-office - posted 2026-09-29

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 191,000 - 253,000 / annual

Anduril Industries is seeking a Senior Software Engineer to design, implement, and harden Android virtual machines running on crosvm. You will work across the full virtualization stack—from the virtual machine monitor (VMM) and guest kernel through secure boot and platform security features—to deliver production-quality, security-hardened Android VMs for military command and control systems. You will own hard problems end-to-end, collaborating with platform and security teams to set the technical direction for secure Android virtualization. Your responsibilities include: • Design, build, and maintain Android VMs on crosvm, including VMM configuration, device models (virtio), and guest/host integration • Bring up and boot Android guest images: kernel, bootloader, init, and Android framework layers • Harden the virtualization boundary by reducing attack surface, sandboxing device backends, and reasoning about guest-to-host and host-to-guest threat models • Implement and validate secure boot and chain-of-trust for VMs (measured/verified boot, key management, rollback protection) • Analyze and mitigate Android VM security issues; contribute to threat modeling, security reviews, and vulnerability remediation • Debug across the stack—hypervisor/VMM, guest kernel, and Android userspace—using appropriate tooling for each layer • Collaborate with platform, kernel, and security teams to isolate and resolve issues spanning hardware, firmware, and software • Document architecture, security properties, trust boundaries, and design decisions Anduril's Connected Warfare and Warfighter Systems organizations build systems that support global command and control missions, connecting robots, humans, and sensors across domains to enable connected warfare and mission autonomy. REQUIREMENTS: • Strong systems programming in C/C++ and Rust, including low-level work with memory safety, concurrency, and performance under real constraints • Hands-on experience with crosvm (or comparable VMM such as QEMU, rust-vmm, or Firecracker): device models, virtio, VM lifecycle, and VMM configuration • Solid understanding of virtualization and hardware-assisted virtualization (KVM, guest/host memory management, vCPUs, MMIO/IOMMU, virtio transport) • Android VM security knowledge: guest/host isolation, sandboxing of VMM/device backends, and the guest-to-host attack surface • Android platform security fundamentals: SELinux/sandboxing, verified boot (AVB/dm-verity), keystore/KeyMint, and the Android trust model • Secure boot and chain-of-trust expertise: measured vs. verified boot, signing and key management, rollback protection, and root-of-trust concepts • Comfortable working from specifications, kernel/driver source, and register-level documentation • Ability to debug low-level systems issues (kernel logs, ftrace/perf, gdb, VMM tracing/logging) across host and guest • Git proficiency • Must be eligible to obtain and maintain a U.S. Security Clearance PREFERRED QUALIFICATIONS: • Experience with Android Virtualization Framework (AVF), pVM/protected VMs, or microdroid • Guest and host Linux kernel development: drivers, virtio backends/frontends, and kernel debugging • TEE/TrustZone experience and integration with a hardware root of trust • Bootloader work in the Android ecosystem (U-Boot, ABL, or equivalent) and secure boot bring-up • Cryptographic key provisioning, attestation, and lifecycle management for VMs and devices • Familiarity with fuzzing, sandboxing frameworks (seccomp/minijail), and hardening techniques for VMMs • CI for systems/kernel builds and automated VM image testing • Qualcomm platform security experience: Secure Boot, QFPROM/eFuses, TrustZone/QTEE, and the Qualcomm secure boot chain • Experience bringing up Qualcomm platform security from scratch: fuse provisioning, signing infrastructure, and enabling secure boot on new silicon • Familiarity with SoC-level root-of-trust, secure debug/authenticated debug, and anti-rollback on Qualcomm platforms • Contributions to AOSP, crosvm, rust-vmm, or the upstream Linux kernel • Experience with Android CTS/VTS or comparable platform compliance and validation

Similar roles