Principal Product Security Architect
hace 2 días
Valbonne
OverviewArm is seeking an expert Security Engineer to lead and run interactions with external security laboratories and certification bodies. As a senior member of the Product Security team, you will lead different aspects of security evaluations, coordinate certification activities, and ensure that our products meet industry standard methodologies and regulatory requirements.This role is relevant in guaranteeing that Arm products achieve and maintain the vital assurance levels through detailed, evaluation processes.ResponsibilitiesAct as the primary technical work with accredited third-party security laboratories responsible for evaluating Arm productsLead, coordinate, and run end-to-end security evaluation and certification programs, including planning, execution, documentation, and closureEnsure that all evidence, documentation, test vectors, and artefacts required for certification are accurate, complete, and delivered on scheduleReview and validate lab findings, ensuring corrective actions are implemented and retested when neededMaintain up-to-date knowledge of evolving certification standards (e.g., Common Criteria, PSA Certified, SESIP, FIPS, OCP safe, ISO21434, IEC 62443, etc.)Establish and maintain clear, comprehensive, and current documentation for all evaluation processes and certification workflowsProvide internal guidance and mentoring on evaluation methodologies, certification readiness, and standardsRequired Skills & Experience10+ years of experience in product security, security evaluation, certification, or a related fieldStrong understanding of security evaluation schemes such as Common Criteria, SESIP, PSA Certified, FIPS 140-3, ISO 21434, EU-CRA or similar frameworksConfirmed experience collaborating with external security laboratories and navigating formal evaluation processesConfirmed understanding of cryptographic primitives, secure key lifecycle management, and secure provisioning workflowsExperience with silicon/SoC security architecture, including threat modelling, attacker models, and countermeasuresGood organizational skills with the ability to handle sophisticated, multi-stakeholder projectsExcellent communication, negotiation, and documentation abilitiesAbility to work with multi-functional engineering, product, and security teamsNice-to-Have SkillsExperience with secure hardware components such as cryptography accelerators, RoT modules, Secure enclaves, HSMs, or TEE/TF-M environmentsExperience with secure firmware components such as secure Boot Rom, Bootloader, TFM/TFA, OP-TEE, hyper/micro-visor etc.Practical knowledge of semiconductor manufacturing flows and supply chain securityFamiliarity with side-channel analysis, fault-injection testing, and hardware penetration testing methodologiesAdditional InformationPlease note that a relocation package (including visa sponsorship support) is available for this role, for candidates who require it.#LI-CI Accommodations at ArmAt Arm, we want our people to Do Great Things. If you need support or an accommodation to Be Your Brilliant Self during the recruitment process, please email accommodations@arm.com. To note, by sending us the requested information, you consent to its use by Arm to arrange for appropriate accommodations. All accommodation requests will be treated with confidentiality, and information concerning these requests will only be disclosed as necessary to provide the accommodation. Although this is not an exhaustive list, examples of support include breaks between interviews, having documents read aloud or office accessibility. Please email us about anything we can do to accommodate you during the recruitment process.Hybrid Working at ArmArm’s approach to hybrid working is designed to create a working environment that supports both high performance and personal wellbeing. We believe in bringing people together face to face to enable us to work at pace, whilst recognizing the value of flexibility. Within that framework, we empower groups/teams to determine their own hybrid working patterns, depending on the work and the team’s needs. Details of what this means for each role will be shared upon application. In some cases, the flexibility we can offer is limited by local legal, regulatory, tax, or other considerations, and where this is the case, we will collaborate with you to find the best solution. Please talk to us to find out more about what this could look like for you.Equal Opportunities at ArmArm is an equal opportunity employer, committed to providing an environment of mutual respect where equal opportunities are available to all applicants and colleagues. We are a diverse organization of dedicated and innovative individuals, and don’t discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.