Senior Firmware Security Engineer
CornelisnetworksFull Time
Job description
About the role
As a , you will play a pivotal role in ensuring the security and integrity of our firmware products. Your expertise will be essential in identifying vulnerabilities, implementing security measures, and enhancing the overall security posture of our firmware solutions. You will collaborate closely with cross-functional teams to develop and maintain secure firmware, contributing to the advancement of our innovative networking technologies. This position offers an exciting opportunity to work at the forefront of firmware security in a dynamic and fast-paced environment.
Key facts
What you'll do
- Conduct thorough security assessments of firmware to identify vulnerabilities and potential threats.
- Design and implement security protocols and best practices to safeguard firmware against attacks.
- Collaborate with software and hardware engineers to integrate security features into the firmware development lifecycle.
- Develop and maintain security documentation, including threat models, risk assessments, and security policies.
- Perform code reviews and static analysis to ensure compliance with security standards and practices.
- Stay updated on the latest security trends, vulnerabilities, and technologies relevant to firmware and embedded systems.
- Lead incident response efforts related to firmware security breaches, providing expertise in forensic analysis and remediation.
- Mentor junior engineers and provide guidance on secure coding practices and firmware security principles.
- Participate in security audits and assessments, providing recommendations for improvements.
- Work closely with product management to define security requirements and ensure they are met throughout the development process.
- Collaborate with external security researchers and organizations to enhance the security of our products.
- Contribute to the development of security training programs for engineering teams to foster a culture of security awareness.
Requirements
- Bachelor's degree in Computer Science, Electrical Engineering, or a related field.
- A minimum of 5 years of experience in firmware development with a strong focus on security.
- Proficiency in programming languages such as C, C++, and Python, with a solid understanding of embedded systems.
- Extensive knowledge of security vulnerabilities and mitigation techniques specific to firmware and embedded devices.
- Experience with security assessment tools and methodologies, including static and dynamic analysis.
- Familiarity with secure coding standards and best practices, such as OWASP and NIST guidelines.
- Strong analytical and problem-solving skills, with the ability to think critically about security challenges.
- Excellent communication skills, both written and verbal, to effectively convey complex security concepts to technical and non-technical stakeholders.
- Ability to work independently and collaboratively in a fast-paced environment, managing multiple priorities effectively.
- A proactive approach to continuous learning and staying abreast of emerging security threats and technologies.
Nice to have
- Master's degree in a relevant field or equivalent work experience.
- Certifications such as Certified Information Systems Security Professional (CISSP) or Certified Ethical Hacker (CEH).
- Experience with hardware security features, such as Trusted Platform Modules (TPMs) and secure boot processes.
- Knowledge of networking protocols and security measures, particularly in the context of IoT devices.
- Familiarity with regulatory compliance standards, such as ISO 27001 or GDPR.
Skills & tools
- Proficient in firmware development and security assessment tools.
- Strong understanding of cryptographic principles and their application in firmware security.
- Familiarity with debugging tools and techniques for embedded systems.
- Experience with version control systems, such as Git, and continuous integration/continuous deployment (CI/CD) practices.
- Knowledge of threat modeling and risk assessment frameworks.
Practical notes
- This position is based in an unspecified location, and candidates should be open to relocation if necessary.
- The company offers competitive compensation and benefits, including potential visa sponsorship for qualified international candidates.
- Interested applicants can apply through the provided link: https://cornelisnetworks.bamboohr.com/careers/220.
META
Company: Cornelisnetworks
Title: Senior Firmware Security Engineer
Listed
location: Unknown
Job type: Full-time