Senior Cyber Software Engineer
Listed on 2026-09-21
-
IT/Tech
Cybersecurity
Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center.
As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.
The Air Defense team is responsible for the cryptographic foundation and platform trust that makes Anduril’s Air Defense products deployable in the world's most demanding environments. The team owns everything from firmware and secure boot to key management, anti-tamper, and the compliance automation that keeps systems accredited — across a portfolio of proprietary hardware and software operating in contested, classified, and often disconnected conditions.
ABOUTTHE JOB
Air Defense employs a variety of advanced proprietary software and hardware products to support global operations. The Cyber Engineer designs and implements the cryptographic and platform security that makes those products trustworthy in contested and classified environments — FIPS-validated encryption, secure and measured boot, full-disk encryption, anti-tamper and zeroization, and secure communications across degraded links. This is a hands‑on engineering role at the lowest levels of the stack.
You will implement cryptography and key handling on constrained hardware, harden Linux and firmware, build the audit and validation tooling that proves the design behaves as specified, and automate the evidence accreditation requires. You will be the engineer government reviewers talk to when they want a real technical answer - but your output is code, firmware, and systems. We are looking for depth in how systems actually fail: someone who has implemented or attacked crypto, boot chains, and protocols, and who reaches for a debugger and a specification rather than a checklist.
Backgrounds in vulnerability research, reverse engineering, or national-security cryptographic engineering map directly onto this work.
- Implement and improve FIPS 140-3 validated encryption across products — algorithm selection, module boundaries, entropy sources, key derivation, and the validation evidence that keeps certification current.
- Own the platform trust chain: secure and measured boot (U-Boot/UEFI), TPM-backed attestation, firmware signing, and rollback protection on embedded and edge hardware.
- Design and implement full-disk and data-at-rest encryption, key management and rotation, and key hierarchies that survive field conditions.
- Build anti-tamper and zeroization: tamper detection and response, emergency erase, key destruction paths, and the tests that prove they work under adversarial conditions.
- Engineer secure communications - protocol design and review, mTLS and workload identity, tunnels and gateways for cross-domain and air-gapped transport, and CNSA-compliant cipher suites.
- Build audit and validation tooling: instrumentation that proves cryptographic and boot-time behavior, plus the harnesses, fuzzers, and adversarial tests that try to break your own designs.
- Harden Linux, container, and firmware baselines - kernel configuration, SELinux/App Armor, attack-surface reduction - and codify them so they hold across every deploy.
- Automate the compliance surface so it stays out of everyone's way: express NIST…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).