Security Engineer (211941
Listed on 2026-08-22
-
Software Development
Software Engineer, AI Engineer (Applied/Software), DevOps, Python
Aquent is partnering with a leading technology company at the forefront of innovation, dedicated to shaping the future of computing. This is an unparalleled opportunity to join a pioneering team and make a profound impact on the security posture of critical hardware ecosystems. You will play a pivotal role in developing a next-generation platform that leverages cutting-edge AI, compiler technology, and automated fuzzing to secure firmware at scale, transforming how vulnerabilities are identified and mitigated across the industry.
About the Role
Step into a dynamic engineering role where your expertise will directly contribute to building and advancing a groundbreaking firmware security analysis platform. This platform addresses a critical industry challenge by automating the rigorous analysis of third-party firmware, ensuring a robust security posture across a broad ecosystem of hardware and firmware providers. You will be instrumental in bridging research ideas with production-quality engineering solutions, working alongside security researchers, compiler engineers, and platform developers.
This role offers a unique chance to work across multiple layers of the technology stack, from low-level compiler infrastructure to modern AI-assisted development workflows. You will contribute to long-term technical strategy and platform evolution, driving innovation that secures critical firmware ecosystems through advanced analysis technologies.
Key Responsibilities
- Build and enhance security analysis pipelines, including developing preprocessing pipelines for C/C++ firmware code into Intermediate Representation (IR).
- Implement and maintain IR-based transformations to prepare firmware for off-target analysis and fuzzing.
- Create and improve code-analysis workflows, encompassing call-graph extraction, metadata generation, and static-analysis integrations.
- Design and maintain systems for generating and executing fuzzing campaigns using modern frameworks and AI-assisted techniques.
- Improve crash triage systems for automated identification, deduplication, and analysis of security findings.
- Develop automated mechanisms to classify code semantics and enhance analysis accuracy.
- Build scalable automation combining compiler infrastructure, security tooling, and AI-driven workflows.
- Enhance vulnerability detection pipelines and reduce false positives through improved analysis techniques.
- Improve reporting systems to transform raw security findings into actionable engineering insights.
- Validate analysis approaches across diverse firmware targets and environments.
- Improve system reliability, modularity, test coverage, and CI/CD automation.
- Create developer documentation, onboarding guides, and architectural references.
- Support dependency review, reproducible builds, and general open-source readiness activities.
- Help establish contribution workflows, issue triage practices, and release processes for external contributors.
- Write clean, maintainable, and well-tested code.
- Participate in design reviews and technical architecture discussions.
- Collaborate closely with engineers across security, hardware, and platform teams.
- Contribute to long-term technical strategy and platform evolution.
What Success Looks Like
- Security analysis pipelines operate reliably across targeted firmware platforms.
- Vulnerability findings are actionable, accurate, and produce significantly fewer false positives than traditional approaches.
- New firmware targets can be onboarded efficiently through documented, repeatable processes.
- The project achieves a high-quality, sustainable open-source release supported by robust tooling, testing, and documentation.
- Engineering improvements directly increase scalability, coverage, and usability for both internal and external contributors.
Must-Have Qualifications
- Bachelor's degree in Computer Science, Computer Engineering, or a related technical field, or equivalent practical experience.
- Strong professional experience developing software in C/C++.
- Hands-on experience with compiler technologies, IR, or low-level systems programming.
- Experience working with fuzzing frameworks such as lib Fuzzer, AFL, AFL++, or similar technologies.
- Strong understanding of software security principles, including memory-safety vulnerabilities and root-cause analysis.
- Proficiency with Python for automation and tooling development.
- Experience using Git-based development workflows.
- Demonstrated ability to write well-tested, maintainable, and documented production code.
Nice-to-Have Qualifications
- Experience with firmware, embedded systems, device software, or bare-metal development.
- Knowledge of hardware abstraction layers (HALs), MMIO, emulation, rehosting, or cross-compilation techniques.
- Experience with static-analysis platforms such as CodeQL.
- Familiarity with program-analysis concepts such as call graphs, data-flow analysis, or IR transformations.
- Experience integrating AI, machine learning, or large language model technologies into engineering workflows.
- Previous open-source…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).