Staff Product Security Engineer

ARM LIMITED

Staff Product Security Engineer

Salary Not Specified

ARM LIMITED, Newtown, Cambridge

  • Full time
  • Permanent
  • Onsite working

Posted 2 weeks ago, 16 May | Get your application in now before you miss out!

Closing date: Closing date not specified

job Ref: 7939fa4987df4de2b6b044e178f69b9c

Full Job Description

The Arm Product Security Incident Response Team (PSIRT) is looking for a highly motivated, experienced addition to their team, to help deliver on Arm's commitment to coordinated vulnerability disclosure (CVD) and navigate the ever-changing landscape of product security. Growth in this area has created an opportunity join a highly visible and dynamic team at the cutting edge of technology., This role is based within the Arm PSIRT and is responsible for managing security vulnerabilities and incidents related to Arm's products and services. We continuously monitor for threats, assess vulnerabilities, coordinate incident response, and facilitate remediation. We also prioritise risks and maintain transparent communication with partners and the community regarding security issues. Arm is committed to maintaining industry-leading product security based on continuous improvement of our organisation's security posture through investments into culture and process.,

  • Day-to-day handling of suspected and confirmed vulnerabilities in Arm's portfolio of products using the established incident response process

  • Support Arm's engineering teams with analysis of reported vulnerabilities, including impact and severity assessments

  • Lead the development of Arm's vulnerability monitoring capabilities using internal and external sources

  • Liaise with Arm's engineering teams to facilitate the responsible disclosure of product security vulnerabilities

  • Engage with ecosystem peers across engineering and security teams to continuously improve Arm's product security processes based on growing industry expectations

    At least 2 years prior experience in a PSIRT or similar security function

  • Bachelor's or higher in a related field or equivalent experience

  • Excellent English written and verbal communication skills with a customer focus and ability to communicate vulnerabilities to a technical level

  • A good understanding of software, hardware, network, and system security

  • A good understanding of common classes of vulnerabilities and attack methodologies

  • Ability and willingness to expand security knowledge into various product spaces


  • "Nice To Have" Skills and Experience :

  • Experience with security research in products and ability to apply that knowledge to product security incident response

  • Experience in software vulnerability management and SDL practices

  • Prior engagement in working groups or similar with these key bodies FIRST, MITRE, CERT

  • Experience with ticket management systems such as Jira

  • Experience with incident management tooling

  • Experience with scripting languages, such as python

  • Familiarity Arm's technologies and/or semiconductors/compilers/firmware

    At Arm, we want our people to Do Great Things. If you need support or an accommodation to Be Your Brilliant Self during the recruitment process, please email accommodations@arm.com. To note, by sending us the requested information, you consent to its use by Arm to arrange for appropriate accommodations. All accommodation requests will be treated with confidentiality, and information concerning these requests will only be disclosed as necessary to provide the accommodation. Although this is not an exhaustive list, examples of support include breaks between interviews, having documents read aloud or office accessibility. Please email us about anything we can do to accommodate you during the recruitment process., Power the Future on Arm


  • Working in software engineering at Arm is about shaping a future of technology for which we don't yet have words. Our engineers lead innovation in physical Ip, AI and machine learning, cloud architecture, automotive tech, and every aspect of computing that matters.

    Spanning software's full spectrum, from compilers to AI-powered IoT and beyond, your code can enable virtually anything to be produced on silicon. Whether you're developing award-winning VR gaming or life-enhancing medical equipment, you can improve the lives of millions by being your brilliant self at Arm., Life in the office doesn't get any better - especially when those offices are as sleek as ours and the people there are creative and compassionate. Combine that with our popular 'we, not I' mindset, and you enjoy the kind of teamwork and togetherness rarely found elsewhere. We share so much in common, not least the same passion for progress, but we also welcome each other's diversity. Ultimately, we love to inspire and be inspired every day.