SoC Security Architecture & SDL Lead
Arm · Austin, TX · 4 wk ago
HybridArt & Creative$198k–$268k/yrFull-time
Responsibilities
- Drive both the Security Architectural definition and the Secure Development Lifecycle (SDL) for Arm IP and SoC products.
- Ensure that all subsystem and SoC designs meet Arm’s security requirements through detailed threat modeling, architecture, verification, and documentation.
- Act as both a security process owner and technical authority, guaranteeing that security is embedded and successful from concept to production silicon.
- Define and develop creative Security Architecture solutions for SoCs for multiple product market segments.
- Develop and maintain architectural threat models, mapping assets, attack surfaces, and mitigations aligned with the Secure Development Lifecycle methodology.
- Derive Security Functional Requirements (SFRs) from threat models and ensure traceability through development and verification.
- Lead creation of the Key Management Plan, ensuring secure key generation, distribution, storage, and lifecycle alignment across device usecases and manufacturing.
- Lead the successful implementation of the Solution SDL process for the product, ensuring security objectives are achieved throughout the development and productization phases.
- Deliver complete security documentation including Threat Models, Security Architecture Reports, Key Management Plans, and Assumptions of Use (AoUs).
- Mentor engineering teams and champion SDL adoption across global engineering teams.
- Collaborate with Verification & Validation Leads to define and implement Security Verification & Validation (V&V) Plans.
- Ensure all SFRs are testable, verified, and validated at pre- and post-silicon stages.
- Ensure security issues are triaged, resolved, and systematically looped back into the SDL process for continuous improvement.
- Support security assessments, penetration testing, and certification activities (PSA Certified, FIPS 140-3, ISO/SAE 21434).
Required Skills And Experience
- Security Architecture Leadership
- Develop architectures for SOC and subsystem Security, Root of Trust, Secure Boot, Key Management, Confidential Compute, Authentication, Encryption, and Secure Manufacturing.
- Architect robust access control, privilege management, isolation, and confidentiality mechanisms between hardware and software domains.
- Develop and maintain architectural threat models, mapping assets, attack surfaces, and mitigations aligned with the Secure Development Lifecycle methodology.
- Derive Security Functional Requirements (SFRs) from threat models and ensure traceability through development and verification.
- Working knowledge of cryptographic design, fault/side-channel mitigation, and firmware security.
- Lead creation of the Key Management Plan, ensuring secure key generation, distribution, storage, and lifecycle alignment across device usecases and manufacturing.
- Familiarity with security certifications (PSA Certified, ISO/SAE 21434, FIPS 140-3, Common Criteria).
- SDL Leadership
- Own and lead the Solution SDL process across all project phases, ensuring compliance with Arm standards and external certifications.
- Drive timely creation and review of SDL artifacts (Threat Models, Security Architecture, V&V Plans, and Security Documentation) and coordinate as necessary for external audit and certification.
- Integrate SDL checkpoints into program plans and ensure organizational engagement from design through post-silicon validation.
- Deliver complete security documentation including Threat Models, Security Architecture Reports, Key Management Plans, and Assumptions of Use (AoUs).
- Mentor engineering teams and champion SDL adoption across global engineering teams.
- Verification & Validation Leadership
- Collaborate with Verification & Validation Leads to define and implement Security Verification & Validation (V&V) Plans.
- Ensure all SFRs are testable, verified, and validated at pre- and post-silicon stages.
- Ensure security issues are triaged, resolved, and systematically looped back into the SDL process for continuous improvement.
- Support security assessments, penetration testing, and certification activities (PSA Certified, FIPS 140-3, ISO/SAE 21434).