Senior Product Security Engineer - Audio Tech
About the role
Join the future of product security at Bose. Security and stability are the two pillars of our product innovation. We are seeking a Security Engineer to support the product security initiatives of our growing Audio Technology business. You will play a central role in securing Bose's proprietary audio technologies. As Bose continues to innovate, there is a constant need to protect our intellectual property and embed security throughout the development lifecycle. The ideal candidate has extensive experience in secure software development within a fast-paced, agile product environment.
Responsibilities
- Architecting and implementing protections for intellectual property, including anti-reverse engineering, secure firmware distribution, and debug interface lockdown
- Collaborating with cross-functional teams including product firmware, Audio Technology, DevOps, cloud engineering, manufacturing, and program management
- Architecting and designing products to guarantee secure practices, data confidentiality, and system integrity
- Engineering and implementing ARM TrustZone secure applets, implementing a cryptographic IoT device identity and root of trust
- Streamlining secrets, key management, cryptography, and credential management
- Defining security requirements and conducting security assessments
- Implementing firmware and intellectual property (IP) protection mechanisms to safeguard proprietary software and embedded technologies
- Performing obfuscation of firmware and algorithm binaries to protect against reverse engineering and unauthorized modification
- Integrating firmware encryption, digital signing, and integrity verification into embedded software and secure update processes
- Ensuring compliance with applicable security regulations and standards (e.g., EU CRA, ETSI EN 303 645, NIST) and supporting audits and certifications
- Advising engineering peers on security matters in the form of architectural guidance, code/design reviews, and solution development
- Improving vulnerability discovery, patching processes, and leading responses to external security threats
- Performing security testing on products and supporting security fix implementations
- Designing and maintaining private X.509 and JWK chains of trust used for validating the authenticity of portable audio devices
- Staying up-to-date on security news, relevant technologies, user groups, industry trends, and emerging security opportunities
- Being a stakeholder on interdisciplinary teams advocating for security
Requirements
- Experience delivering licensed software that runs on customer products and systems where you do not trust the system it runs on
- Hands-on experience implementing firmware protection mechanisms, including secure boot, firmware encryption, digital signing, secure firmware distribution, and anti-tamper controls
- Experience implementing binary obfuscation and anti-reverse engineering techniques for embedded firmware or proprietary algorithm binaries
- Experience implementing IP protection and anti-tamper mechanisms in embedded systems, including secure boot enforcement, firmware encryption, and hardware debug port protection
- Experience developing for embedded systems and Linux platforms in C/C++
- Strong knowledge of cryptographic theory and engineering, including encryption, hashing, signing, digital certificates, and hardware security modules (HSMs)
- Experience collaborating with cross-functional engineering teams to integrate security controls into embedded products throughout the development lifecycle
- Bachelor's degree in Computer Science or equivalent. A master's degree is beneficial
- 6 or more years of industry experience working in firmware development with a focus on security. An advanced degree can contribute toward experience
Optional qualifications
- Experience aligning embedded product security practices with regulatory and compliance requirements (EU CRA, NIST, ISO 27001, IEC 62443, or similar frameworks)
- Building internal security applications with cryptographic guarantees such as firmware encryption and signing, custom developer enablement tools, secure asset provisioning, etc.
- Experience developing for mobile applications (iOS or Android)
- Experience mitigating dependency or code-level defects including memory management issues, input validation, timing attacks, broken authentication, and side-channel attacks
Benefits
Competitive salary, benefits, and pension. In addition to competitive base pay we offer rewards including bonus programs, comprehensive health and welfare benefits, a 401(k) plan, plus exclusive perks designed to support your wellbeing, and a generous employee discount where you can immerse yourself in our products and experiences.
Pay
The hiring range for this position in the primary work location of Framingham, Massachusetts is: $123,500-$169,850. The hiring range for other Bose work locations may vary.