Systems Security Software Engineer
$135,200–$156,000 year
HybridRedmond, Washington, United States
Job Summary
Design and maintain automated firmware security-analysis pipelines for vulnerability discovery using C++, Python, and LLVM. Develop compiler passes to convert firmware into analyzable intermediate representations and create fuzzing harnesses that maximize code coverage. Investigate crashes from fuzzing campaigns, perform root-cause analysis, and improve detection accuracy by reducing false positives. Build AI-assisted systems for functionality classification and generate security artifacts while debugging firmware-rehosting environments. Collaborate with researchers to validate findings, design scalable CI workflows, and prepare the platform for open-source release.
Required Qualifications
- Bachelor's degree in computer science, computer engineering, electrical engineering, or a related technical field, or equivalent practical experience
- Seven or more years of professional experience developing systems software with C or C++
- Five or more years of experience with LLVM, compiler infrastructure, compiler development, or program analysis
- Three or more years of experience with fuzzing, vulnerability research, or application security
- Experience developing compiler passes, static-analysis tools, or code-transformation frameworks
- Strong understanding of LLVM Intermediate Representation and compiler-optimization concepts
- Experience debugging low-level software, memory-corruption issues, and complex system behavior
- Proficiency with Python for automation, tooling, or pipeline development
- Experience working within Linux development environments
- Strong problem-solving skills with the ability to debug across compiler, firmware, and systems-software layers
- Experience with Git and modern software-development practices
Desired Qualifications
- Experience with firmware security, embedded systems, or bare-metal software development
- Knowledge of firmware architectures, hardware abstraction layers, memory-mapped input/output, or firmware-rehosting techniques
- Experience with fuzzing technologies such as libFuzzer, AFL, or AFL++
- Experience with sanitizer technologies, including AddressSanitizer, UndefinedBehaviorSanitizer, or MemorySanitizer
- Experience with static analysis, data-flow analysis, call-graph analysis, CodeQL, or similar security-analysis frameworks
- Experience building developer platforms, continuous-integration automation, or large-scale engineering tooling
- Familiarity with cross-compilation toolchains and embedded-development workflows
- Experience integrating large language models or AI-assisted automation into developer or security tooling
- Experience contributing to open-source software projects
- Experience developing production-quality testing frameworks and automation infrastructure
- Ability to succeed within a research-oriented environment while delivering production-ready software
- Strong collaboration and communication skills across engineering and research teams
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.