... firmware security analysis, and collaborating with development teams to uncover security weaknesses that traditional SDL processes may overlook. You will use practical security research methods ...
... firmware security analysis, and collaborating with development teams to uncover security weaknesses that traditional SDL processes may overlook. You will use practical security research methods ...
... firmware security analysis, and collaborating with development teams to uncover security weaknesses that traditional SDL processes may overlook. You will use practical security research methods ...
... firmware security analysis, and collaborating with development teams to uncover security weaknesses that traditional SDL processes may overlook. You will use practical security research methods ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
NY · On-site
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
New
NY · On-site
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
New
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
NY · On-site
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
New
NY · On-site
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
New
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
... security researchers conducting vulnerability assessments or penetration testing. Required ... Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic ...
Experience with vulnerability research or identifying security weaknesses in firmware or embedded systems * Hands-on experience analyzing or developing firmware * Familiarity with reverse engineering ...
Experience with vulnerability research or identifying security weaknesses in firmware or embedded systems * Hands-on experience analyzing or developing firmware * Familiarity with reverse engineering ...
Firmware vulnerability research, reverse-engineering, or fuzzing * Previous work with AI/ML infrastructure security
Firmware vulnerability research, reverse-engineering, or fuzzing * Previous work with AI/ML infrastructure security
Senior Vulnerability Researcher
Tampa, FL · On-site
$160K - $235K/yr
... firmware, hypervisors, embedded systems, and application stacks * Reverse engineer binaries across x86/x64, ARM, and PowerPC * Develop novel exploits and evaluate security mitigations * Research ...
Quick apply
Senior Vulnerability Researcher
Tampa, FL · On-site
$160K - $235K/yr
... firmware, hypervisors, embedded systems, and application stacks * Reverse engineer binaries across x86/x64, ARM, and PowerPC * Develop novel exploits and evaluate security mitigations * Research ...
Senior Vulnerability Researcher with Security Clearance
San Antonio, TX · On-site
$103K - $142K/yr
Position Title: Senior Security Researcher Location: St. Petersburg, FL | Melbourne, FL | San ... Leading advanced vulnerability research efforts across operating systems, kernels, firmware ...
Senior Vulnerability Researcher with Security Clearance
San Antonio, TX · On-site
$103K - $142K/yr
Position Title: Senior Security Researcher Location: St. Petersburg, FL | Melbourne, FL | San ... Leading advanced vulnerability research efforts across operating systems, kernels, firmware ...
Senior Vulnerability Researcher with Security Clearance
Saint Petersburg, FL · On-site
$109K - $150K/yr
Position Title: Senior Security Researcher Location: St. Petersburg, FL | Melbourne, FL | San ... Leading advanced vulnerability research efforts across operating systems, kernels, firmware ...
Senior Vulnerability Researcher with Security Clearance
Saint Petersburg, FL · On-site
$109K - $150K/yr
Position Title: Senior Security Researcher Location: St. Petersburg, FL | Melbourne, FL | San ... Leading advanced vulnerability research efforts across operating systems, kernels, firmware ...
Vulnerability Researcher
Seattle, WA · On-site
$142K - $263K/yr
... security of iOS and macOS (kernel and user-land), boot ROMs, firmware, and hardware. By ... research on Apple software, firmware, and hardware components. Analyzing and exploiting ...
Vulnerability Researcher
Seattle, WA · On-site
$142K - $263K/yr
... security of iOS and macOS (kernel and user-land), boot ROMs, firmware, and hardware. By ... research on Apple software, firmware, and hardware components. Analyzing and exploiting ...
Firmware Security Researcher information
See salary details
$47.60 - $48.21
4% of jobs
$48.21 - $48.82
6% of jobs
$48.82 - $49.43
11% of jobs
$49.61 is the 25th percentile. Wages below this are outliers.
$49.43 - $50.04
11% of jobs
$50.04 - $50.66
7% of jobs
The median wage is $51.18 / hr.
$50.66 - $51.27
11% of jobs
$51.27 - $51.88
7% of jobs
$51.88 - $52.49
11% of jobs
$52.76 is the 75th percentile. Wages above this are outliers.
$52.49 - $53.10
11% of jobs
$53.10 - $53.72
7% of jobs
$53.72 - $54.33
11% of jobs
$47
$51
$54
How much do firmware security researcher jobs pay per hour?
What is a firmware security researcher?
What are some common challenges firmware security researchers face when analyzing embedded systems?
What are the key skills and qualifications needed to thrive as a firmware security researcher, and why are they important?
What is the difference between Firmware Security Researcher vs Embedded Security Analyst?
| Aspect | Firmware Security Researcher | Embedded Security Analyst |
|---|---|---|
| Credentials | Cybersecurity certifications, knowledge of firmware analysis tools | Security certifications, embedded systems knowledge |
| Work Environment | Research labs, cybersecurity firms, tech companies | Manufacturers, IoT companies, embedded device firms |
| Industry Usage | Focus on firmware vulnerabilities and exploits | Focus on embedded system security and threat mitigation |
The Firmware Security Researcher primarily investigates firmware vulnerabilities and exploits, often working in research labs or cybersecurity firms. In contrast, the Embedded Security Analyst focuses on securing embedded systems within manufacturing or IoT environments. Both roles require cybersecurity knowledge, but their focus areas and work settings differ.
What are popular job titles related to Firmware Security Researcher jobs?
For Firmware Security Researcher jobs, the most frequently searched job titles are:

SoC Offensive Security Staff Engineer
Austin, TX • On-site
Full-time
Re-posted 5 days ago
Key responsibilities
Perform adversarial security analysis of SoC and chiplet micro-architectures, identifying vulnerabilities across pre-silicon and post-silicon environments.
Review architectural specifications, evaluate platforms, and collaborate with development teams to uncover security weaknesses.
Apply automation, scripting, and AI-assisted techniques to support vulnerability discovery, test generation, and attack surface exploration.
Job description
The Security Research and Response team in Arm's Architecture and Technology Group is seeking a highly skilled SoC Offensive Security Staff Engineer to apply an attacker's mindset to Arm's next-generation solutions, identifying design and integration-level vulnerabilities early in the development lifecycle!
Working as part of the SoC Offensive Security team, you will perform adversarial security assessments across multiple projects by reviewing architectural specifications, evaluating pre- and post-silicon platforms, conducting firmware security analysis, and collaborating with development teams to uncover security weaknesses that traditional SDL processes may overlook. You will use practical security research methods, automation, and where appropriate, AI-assisted techniques to improve the depth, scale, and efficiency of adversarial analysis. Your work will contribute directly to improving the security of Arm's next-generation silicon solutions!
Responsibilities:- Perform adversarial security analysis of SoC and chiplet micro-architectures, identifying unknown or emerging vulnerabilities across pre-silicon and post-silicon environments.
- Engage with project teams at different stages of the development lifecycle to review architecture, micro-architecture, system-level specifications, security assumptions, RTL implementations, and firmware components.
- Participate in design reviews, security discussions, and focused hackathons to develop new threat scenarios, perform adversarial testing, and improve security models.
- Apply automation, scripting, and AI-assisted techniques where appropriate to support vulnerability discovery, specification analysis, test generation, triage, or exploration of complex attack surfaces.
- Demonstrate the practical impact of vulnerabilities by developing Proofs of Concept (PoCs), exploits, and security demonstrations where appropriate.
- Investigate multi-stage and cross-component attack chains beyond those captured in threat models or standard verification activities.
- Collaborate closely with internal security researchers and engineering teams to accelerate security assessments and identify effective mitigations.
- Contribute to improving threat models, security mitigations, and security architecture recommendations based on assessment findings.
- Contribute to the development and continuous improvement of offensive security methodologies, tools, and best practices across the SoC Offensive Security team.
- Strong knowledge of SoC architecture and IP integration.
- Thread modeling standalone IPs and Subsystems. Candidate should have experience enumerating micro-architectural attack surfaces and SoC integration concerns.
- Demonstrated experience conducting adversarial assessments (PoCs, exploits, CTFs, published work).
- Practical experience with SystemVerilog RTL, UVM-based validation environments and HW Dev IDEs
- Comfortable reusing current verification environments and adapting them for negative and offensive testing.
- Hands-on lab experience setting up development and testing platforms, delivering security evaluations, and validating findings in practical environments.
- Firmware security analysis experience on projects like UEFI, uBoot, MCUBoot, Trusted Firmware or similar.
- Experience with security focused specifications and standards such as Caliptra, DICE, or related attestation and hardware root-of trust standards.
- Strong, determined problem solving outlook with creative security mentality.
- Great communication skills, with the ability to influence design teams and clearly articulate risk and recommendations.
- Ability to independently conduct complex technical investigations across assigned areas of responsibility.
- Familiarity with typical Hardware interface standards : PCIe, CXL, SMBus, SPI, I2C, UART, etc.
- Familiarity with ARM’s AMBA interconnect protocols: AXI, CHI, CXS, APB, ATB, LPI, etc.
- Experience with formal proof tools and approaches for HW Security.
- Experience with TEE and their HW building blocks. Should be able to elaborate on what is in the TCB of a confidential VM.
- Experience with hardware fuzzing in pre and post silicon environments
- Experience with software exploitation techniques.
- Reverse engineering skills for hardware, firmware, or microarchitecture.
- Contributions to open standard bodies or participation in security-focused special interest groups (e.g., industry working groups, architecture forums).
You will join a team of hard-working security engineers at the forefront of identifying vulnerabilities in Arm based systems. Your work will shape the security posture of silicon programs and provide opportunities to influence architectural direction, collaborate with extraordinary engineers, and conduct hands-on offensive security research.
This role offers a unique opportunity to have direct impact on silicon designs, contribute to industry leading security practices, and help ensure Arm’s next generation of solutions are robust against evolving adversaries. Arm is proud to foster an inclusive, diverse, and collaborative environment where your expertise and creativity will be valued.
#LS-KS1
We value people as individuals and our dedication is to reward people competitively and equitably for the work they do and the skills and experience they bring to Arm. Salary is only one component of Arm's offering. The total reward package will be shared with candidates during the recruitment and selection process.
At Arm, we want to build extraordinary teams. If you need an adjustment or an accommodation during the recruitment process, please email accommodations@arm.com. To note, by sending us the requested information, you consent to its use by Arm to arrange for appropriate accommodations. All accommodation or adjustment requests will be treated with confidentiality, and information concerning these requests will only be disclosed as necessary to provide the accommodation. Although this is not an exhaustive list, examples of support include breaks between interviews, having documents read aloud, or office accessibility. Please email us about anything we can do to accommodate you during the recruitment process.
Hybrid Working at ArmArm's approach to hybrid working is designed to create a working environment that supports both high performance and personal wellbeing. We believe in bringing people together face to face to enable us to work at pace, whilst recognizing the value of flexibility. Within that framework, we empower groups/teams to determine their own hybrid working patterns, depending on the work and the team's needs. Details of what this means for each role will be shared upon application. In some cases, the flexibility we can offer is limited by local legal, regulatory, tax, or other considerations, and where this is the case, we will collaborate with you to find the best solution. Please talk to us to find out more about what this could look like for you.
Equal Opportunities at ArmArm is an equal opportunity employer, committed to providing an environment of mutual respect where equal opportunities are available to all applicants and colleagues. We are a diverse organization of dedicated and innovative individuals, and don't discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Employment Type: EstablishedAbout Arm
Sourced by ZipRecruiter
Industry
It services
Company size
5,001 - 10,000 Employees
Headquarters location
Cambridge, GI, GB