SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Software Engineer, Embedded Product Security

Anduril - Irvine, CA, United States - In-office - posted 2026-09-18

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 220,000 - 292,000 / annual

Anduril Industries is a defense technology company building advanced autonomous systems and AI-powered command-and-control platforms for military applications. The Sentry Tower Software team develops robotic perimeter security systems that leverage sensor fusion and autonomy to monitor secure areas. You will own product security for the Sentry Tower platform, a hardware-and-software problem where physical access by adversaries is a realistic threat. Your responsibilities span the entire trusted boot chain and runtime hardening posture. Key responsibilities include: - Own the signed boot chain across NVIDIA Jetson compute generations: firmware and bootloader signing, UEFI Secure Boot key hierarchies, signed kernel and initrd images, and full-disk encryption with automated unlock. - Manage signing key infrastructure: HSM-backed keys, separation of development and production trust roots, key rotation, and build-time enforcement that correct keys sign correct artifacts. - Define and implement platform hardening postures: network exposure and firewall policy, privilege and sudo restrictions, serial console and USB lockdown, and differences between locked-down fielded systems and debuggable bench units. - Drive vulnerability management for the fielded fleet: track CVEs against kernel and userspace, own patching strategy for hardware approaching vendor end-of-life, and maintain clear picture of fleet security state. - Partner with the product security organization to translate security requirements into shippable implementations, act as the team's security liaison, and support program-specific accreditation efforts. The role requires balancing security rigor with engineering velocity—saying no or "not like that" to engineers under schedule pressure without becoming an obstacle. You'll also manage inherited constraints, including hardware with fixed vendor end-of-life dates and slow feedback loops inherent to signed image builds on shared infrastructure. REQUIREMENTS: - 4+ years of professional software engineering with security focus on Linux or embedded systems - Hands-on experience implementing secure boot chains: code signing, chain of trust, UEFI Secure Boot or equivalent vendor secure boot - Practical cryptographic engineering: PKI and certificate hierarchies, HSM or PKCS#11-backed signing, key lifecycle management, full-disk encryption - Strong Linux internals knowledge: patching, boot flow, kernel and initrd, systemd, privilege boundaries, filesystem and device access control - Proficiency in C or Rust, plus fluent shell scripting - Practical hardening and vulnerability-management experience on real systems: attack-surface reduction, CVE triage on deployed fleets, live patching strategies - Ability to explain security decisions to engineers and program stakeholders - US person status required; active US Secret clearance or previously granted Secret clearance eligible for reactivation NICE TO HAVE: - NVIDIA Jetson secure boot experience or other SoC vendor secure boot and fusing workflow - Measured boot, TPMs, or remote attestation familiarity - Declarative configuration and reproducible builds (Nix/NixOS preferred; Bazel, Buildroot, or Yocto acceptable) - Defense or government accreditation process background - Offensive security experience including hardware attacks (bus sniffing, glitching, JTAG, boot interruption) - Supply chain security, artifact provenance, or SBOM tooling experience

Similar roles