Software Security Engineer, Infra & DevOps team Annapurna
- Haifa
- Company career page
- Verified live · yesterday
Mentioned in this posting
- Python
- AWS
- Penetration Testing
- Cryptography
Description
The Annapurna Labs Security Team secures the firmware at the foundation of AWS custom silicon. We work on Graviton processors and the Nitro System — hardware that runs a substantial share of the world's The Annapurna Labs Security Team secures the firmware at the foundation of AWS custom silicon. We work on Graviton processors and the Nitro System — hardware that runs a substantial share of the world's cloud workloads — in close collaboration with the silicon architects and firmware developers who design it. Our engineers operate at the lowest levels of the stack: secure boot chains, hardware root of trust, attestation, cryptographic protocol design, and the boundaries between trust domains within the system. Key job responsibilities As a Security Engineer, you will threat model new silicon and firmware architectures, conduct low-level penetration testing against privileged and externally reachable interfaces, review designs and code across multiple firmware components, and build the fuzzing and analysis tooling that makes this work repeatable at silicon scale. You will also help raise the security bar across the wider organization through direct engagement with firmware and hardware teams. We are looking for engineers fluent in C and ARM assembly, with real depth in secure boot, applied cryptography, or embedded exploitation, and the technical credibility to hold a position in a room full of people who designed the system you are testing. - 4+ years of low-level systems security research and vulnerability testing experience - Experience developing security tools (fuzzers, scanners, analysis frameworks) - Security architecture design and threat modeling experience - Proficiency in C and experience with Python - Deep knowledge of security aspects of ARM/x86 processor architectures - Strong understanding of hardware security (secure boot, cryptographic implementations, side-channel attacks) - Knowledge of security protocols and cryptographic primitives - Experience in AI usage for security research - Technical English proficiency