Jobs · Information Technology · Massachusetts

Senior Product Security Engineer - Audio Tech

Bose Corporation · Framingham, MA · 4 wk ago
Information Technology$124k–$170k/yrFull-time

About the role

Join the future of product security at Bose. Security and stability are the two pillars of our product innovation. We are seeking a Security Engineer to support the product security initiatives of our growing Audio Technology business. You will play a central role in securing Bose's proprietary audio technologies. As Bose continues to innovate, there is a constant need to protect our intellectual property and embed security throughout the development lifecycle. The ideal candidate has extensive experience in secure software development within a fast-paced, agile product environment.

Responsibilities

  • Architecting and implementing protections for intellectual property, including anti-reverse engineering, secure firmware distribution, and debug interface lockdown
  • Collaborating with cross-functional teams including product firmware, Audio Technology, DevOps, cloud engineering, manufacturing, and program management
  • Architecting and designing products to guarantee secure practices, data confidentiality, and system integrity
  • Engineering and implementing ARM TrustZone secure applets, implementing a cryptographic IoT device identity and root of trust
  • Streamlining secrets, key management, cryptography, and credential management
  • Defining security requirements and conducting security assessments
  • Implementing firmware and intellectual property (IP) protection mechanisms to safeguard proprietary software and embedded technologies
  • Performing obfuscation of firmware and algorithm binaries to protect against reverse engineering and unauthorized modification
  • Integrating firmware encryption, digital signing, and integrity verification into embedded software and secure update processes
  • Ensuring compliance with applicable security regulations and standards (e.g., EU CRA, ETSI EN 303 645, NIST) and supporting audits and certifications
  • Advising engineering peers on security matters in the form of architectural guidance, code/design reviews, and solution development
  • Improving vulnerability discovery, patching processes, and leading responses to external security threats
  • Performing security testing on products and supporting security fix implementations
  • Designing and maintaining private X.509 and JWK chains of trust used for validating the authenticity of portable audio devices
  • Staying up-to-date on security news, relevant technologies, user groups, industry trends, and emerging security opportunities
  • Being a stakeholder on interdisciplinary teams advocating for security

Requirements

  • Experience delivering licensed software that runs on customer products and systems where you do not trust the system it runs on
  • Hands-on experience implementing firmware protection mechanisms, including secure boot, firmware encryption, digital signing, secure firmware distribution, and anti-tamper controls
  • Experience implementing binary obfuscation and anti-reverse engineering techniques for embedded firmware or proprietary algorithm binaries
  • Experience implementing IP protection and anti-tamper mechanisms in embedded systems, including secure boot enforcement, firmware encryption, and hardware debug port protection
  • Experience developing for embedded systems and Linux platforms in C/C++
  • Strong knowledge of cryptographic theory and engineering, including encryption, hashing, signing, digital certificates, and hardware security modules (HSMs)
  • Experience collaborating with cross-functional engineering teams to integrate security controls into embedded products throughout the development lifecycle
  • Bachelor's degree in Computer Science or equivalent. A master's degree is beneficial
  • 6 or more years of industry experience working in firmware development with a focus on security. An advanced degree can contribute toward experience

Optional qualifications

  • Experience aligning embedded product security practices with regulatory and compliance requirements (EU CRA, NIST, ISO 27001, IEC 62443, or similar frameworks)
  • Building internal security applications with cryptographic guarantees such as firmware encryption and signing, custom developer enablement tools, secure asset provisioning, etc.
  • Experience developing for mobile applications (iOS or Android)
  • Experience mitigating dependency or code-level defects including memory management issues, input validation, timing attacks, broken authentication, and side-channel attacks

Benefits

Competitive salary, benefits, and pension. In addition to competitive base pay we offer rewards including bonus programs, comprehensive health and welfare benefits, a 401(k) plan, plus exclusive perks designed to support your wellbeing, and a generous employee discount where you can immerse yourself in our products and experiences.

Pay

The hiring range for this position in the primary work location of Framingham, Massachusetts is: $123,500-$169,850. The hiring range for other Bose work locations may vary.

Similar jobs