Job Description:
We are seeking a highly skilled and experienced SoC Security Architecture & SDL Process Lead to drive both the Security Architectural definition and the end-to-end Secure Development Lifecycle (SDL) across Arm’s hardware security IP and SoC programs.
This role unifies security-by-design leadership with process governance, ensuring that our silicon platforms achieve industry-leading trustworthiness from architecture through post-silicon delivery.
We have exciting opportunities for experienced and self-motivated Security Engineers with demonstrated expertise in SoC Solutions and looking to make a difference in an innovative and inclusive team. If you're ready to make an impact, you have found the right place!
Responsibilities:
The Security Architecture & SDL Lead is responsible for driving both the Security Architecture definition and the Secure Development Lifecycle (SDL) for Arm IP and SoC products. This role ensures that all subsystem and SoC designs meet Arm’s security requirements through detailed threat modeling, architecture, verification, and documentation. Acting as both a security process owner and technical authority, the SDL & Architecture Lead guarantees that security is embedded and successful from concept to production silicon.
As the Security Architect, you will be responsible for defining and developing creative Security Architecture solutions for SoCs for multiple product market segments. This includes solutions for the SoC Root of Trust, Secure Boot, Key Management, Confidential Compute, Authentication and Encryption, and Secure Manufacturing and Device Lifetime Management.
As the SDL Lead, you will lead the successful implementation of the Solution SDL process for the product, ensuring security objectives are achieved throughout the development and productization phases. This would include Threat Model, Security Architecture, Security V&V Plan, Documentation, and Certifications and Compliance leadership.
Required Skills and Experience:
Security Architecture Leadership
- Develop architectures for SOC and subsystem Security, Root of Trust, Secure Boot, Key Management, Confidential Compute, Authentication, Encryption, and Secure Manufacturing. Architect robust access control, privilege management, isolation, and confidentiality mechanisms between hardware and software domains.
- Develop and maintain architectural threat models, mapping assets, attack surfaces, and mitigations aligned with the Secure Development Lifecycle methodology. Derive Security Functional Requirements (SFRs) from threat models and ensure traceability through development and verification.
- Working knowledge of cryptographic design, fault/side-channel mitigation, and firmware security. Lead creation of the Key Management Plan, ensuring secure key generation, distribution, storage, and lifecycle alignment across device usecases and manufacturing.
- Familiarity with security certifications (PSA Certified, ISO/SAE 21434, FIPS 140-3, Common Criteria).
SDL Leadership
- Own and lead the Solution SDL process across all project phases, ensuring compliance with Arm standards and external certifications.
- Drive timely creation and review of SDL artifacts (Threat Models, Security Architecture, V&V Plans, and Security Documentation) and coordinate as necessary for for external audit and certification.
- Integrate SDL checkpoints into program plans and ensure organizational engagement from design through post-silicon validation.
- Deliver complete security documentation including Threat Models, Security Architecture Reports, Key Management Plans, and Assumptions of Use (AoUs).
- Mentor engineering teams and champion SDL adoption across global engineering teams.
Verification & Validation Leadership
- Collaborate with Verification & Validation Leads to define and implement Security Verification & Validation (V&V) Plans.
- Ensure all SFRs are testable, verified, and validated at pre- and post-silicon stages. Ensure security issues are triaged, resolved, and systematically looped back into the SDL process for continuous improvement.
- Approve sign-off criteria and ensure security verification evidence supports product release readiness.
- Support security assessments, penetration testing, and certification activities (PSA Certified, FIPS 140-3, ISO/SAE 21434).
In Return:
We are proud to have a set of behaviors that reflect our culture and guide our decisions, defining how we work together to innovate, defy ordinary, and shape outstanding products!
- Partner and Customer focus – We anticipate and exceed customer needs.
- Teamwork and Communication – We collaborate optimally across diverse teams.
- Creativity and Innovation – We challenge the status quo. We develop careers and personal growth.
- Impact and influence – We deliver measurable, trusted results.
- Deliver on your promises –You demonstrate ownership and accountability.
- United in Purpose, Empowered Through Inclusion – We value diversity to build better solutions.
#LI-MS1
Salary Range:
$241,100-$326,100 per yearWe value people as individuals and our dedication is to reward people competitively and equitably for the work they do and the skills and experience they bring to Arm. Salary is only one component of Arm's offering. The total reward package will be shared with candidates during the recruitment and selection process.
Accommodations at Arm
At Arm, we want to build extraordinary teams. If you need an adjustment or an accommodation during the recruitment process, please email accommodations@arm.com. To note, by sending us the requested information, you consent to its use by Arm to arrange for appropriate accommodations. All accommodation or adjustment requests will be treated with confidentiality, and information concerning these requests will only be disclosed as necessary to provide the accommodation. Although this is not an exhaustive list, examples of support include breaks between interviews, having documents read aloud, or office accessibility. Please email us about anything we can do to accommodate you during the recruitment process.
Hybrid Working at Arm
Arm’s approach to hybrid working is designed to create a working environment that supports both high performance and personal wellbeing. We believe in bringing people together face to face to enable us to work at pace, whilst recognizing the value of flexibility. Within that framework, we empower groups/teams to determine their own hybrid working patterns, depending on the work and the team’s needs. Details of what this means for each role will be shared upon application. In some cases, the flexibility we can offer is limited by local legal, regulatory, tax, or other considerations, and where this is the case, we will collaborate with you to find the best solution. Please talk to us to find out more about what this could look like for you.
Equal Opportunities at Arm
Arm is an equal opportunity employer, committed to providing an environment of mutual respect where equal opportunities are available to all applicants and colleagues. We are a diverse organization of dedicated and innovative individuals, and don’t discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.