Software Security Architect, Operating Systems | Consumer Devices
Defines the security architecture for a next-generation operating system, spanning trust boundaries, hardware-backed protections, isolation, secure updates, and AI-agent guardrails. The role requires deep privileged-systems expertise, systems programming ability, and experience securing platforms across hardware, firmware, and software.
About the job
Responsibilities
- Define the operating system’s security architecture, trust boundaries, privilege model, and protections for sensitive user data.
- Integrate roots of trust, secure elements, trusted execution environments, and processor security capabilities with the operating system.
- Design platform defenses including secure boot, code signing, attestation, secure updates, key protection, and device recovery.
- Establish isolation and access controls across the kernel, applications, system services, and AI workloads.
- Define guardrails for AI applications and agents accessing information, sensors, tools, and retained context.
- Lead threat modeling and architecture reviews, translating emerging threats into enforceable requirements.
- Prototype solutions, review security-critical systems code, and guide engineering teams through technical and product tradeoffs.
Requirements
- Deep experience designing or securing operating systems, kernels, embedded platforms, hypervisors, or other privileged systems software.
- Complex understanding of operating system internals, including memory protection, process isolation, executable loading, device drivers, and privilege boundaries.
- Experience building security architectures spanning hardware, firmware, operating systems, applications, and cloud services.
- Practical expertise with secure boot, code signing, device identity, attestation, trusted execution, and hardware-backed key protection.
- Ability to write or review systems code in C, C++, Rust, or comparable languages.
- Strong understanding of secure development and exploit mitigation.
- Ability to build threat models, influence cross-functional teams, and communicate security tradeoffs clearly.
Nice to Have
- Experience shipping security technologies for consumer operating systems, mobile platforms, or connected devices.
- Kernel hardening, memory-safety mitigations, virtualization-based security, or secure enclave integration.
- Security architecture for AI agents, sensitive-context isolation, permissioned tool use, or prompt-injection resistance.
- Device provisioning, manufacturing security, secure recovery, or hardware-product lifecycle security.
Compensation
- Annual salary range: $268,000–$342,000 USD.
Skills
Operating Systems, Kernel Security, C, C++, Rust, Secure Boot, Code Signing, Attestation, Trusted Execution Environments, Threat Modeling, Hypervisors, Memory Protection, Process Isolation, Hardware Security
Similar jobs
Security Engineering jobsLeads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.
Leads cyber-focused AI misuse enforcement, managing analysts and contractors while developing detection and mitigation strategies for attacks, malware, and exploitation. Requires people management, cybersecurity expertise, high-volume abuse enforcement, data analysis with SQL or Python, and cross-functional risk communication.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Leads a hands-on security engineering function spanning AI security, application and cloud security, detection and response, identity, and compliance controls. The role requires 8+ years of security engineering experience, deep AWS expertise, production code review ability, and experience operating in PCI DSS scope.
Owns DRTM adoption, attestation, and platform hardening across x86 and ARM infrastructure, working across firmware, bootloaders, kernels, hardware, and silicon security. The role requires deep systems-security experience, upstream Linux or firmware contributions, and strong vendor and OEM leadership.