workinengineering
BrowseField notes
workinengineering

Curated engineering jobs in Europe. Built to support the career path of engineering people at European companies across the EU, UK and EMEA.

Jobs

  • Browse all jobs
  • Remote jobs
  • Jobs in Germany
  • Jobs in Netherlands
  • Jobs in the UK
  • Field notes

About us

  • About
  • Contact
  • Privacy
  • Terms
  • Cookies

© 2026 workinengineering.eu — Made in Europe.

  • Email
workinengineering
BrowseField notes
  1. All roles
  2. Arm Holdings
  3. Senior Principal Platform Security Architect
Arm Holdings logo
Arm Holdings

Senior Principal Platform Security Architect

HybridPrincipalCambridge, the United KingdomApplications closedPlatformInfrastructureSecurity

Our Take

Architect security for next-gen data center platforms, integrating firmware and boot chain security.

What you’ll do

  • Design board and rack platform security architecture
  • Develop end-to-end platform threat models
  • Evolve cryptographic foundations of the platform
  • Define and assess security mechanisms for firmware
  • Collaborate with hardware and firmware teams

What they’re looking for

  • Firmware or platform security architecture design
  • Secure boot chains and firmware trust models
  • Firmware signing systems and key hierarchies
  • Secure firmware update mechanisms
  • Platform management firmware security
  • Platform trust architectures with hardware roots of trust
  • Applied cryptography in systems

What you get

  • Relocation package
  • Visa sponsorship support
  • Hybrid working model
  • Equal opportunities employer

Skills & Focus Areas

  • firmware security architecture
  • applied cryptography
  • system-level threat modelling
  • secure boot chains
  • firmware signing
  • platform trust architectures
  • hardware roots of trust
  • Linux security

As posted by Arm Holdings

Job Description:

We are looking for a Platform Security Architect to help shape the security architecture of next-generation data center platforms.

This role focuses on how security is integrated into systems above the silicon, spanning firmware, boot chains, management planes, and platform lifecycle controls.

You will collaborate closely with hardware and firmware teams to help ensure the platform has a coherent and resilient security architecture from board to rack scale.

The role requires strong experience in firmware security architecture, applied cryptography, and system-level threat modelling.

Responsibilities:

  • Platform Security Architecture : Design the security architecture for board and rack platforms, including: Extension of root of trust beyond the SoC, Secure and measured boot chains, Firmware signing and verification architecture, Device identity and provisioning models, Debug and lifecycle security mechanisms.
  • Platform Threat Modeling : Create and maintain the end-to-end platform threat model covering : Firmware and boot chains, Management plane components (BMC, controllers) Rack-level attack paths.
  • Design and help evolve the cryptographic foundations of the platform, including: Firmware signing hierarchy, Key ownership and trust anchors, Certificate and device identity models, Key rotation and revocation strategies.
  • Firmware Security Requirements. Work closely with firmware teams to define and assess security mechanisms for BIOS, BMC, and device firmware. 

Required Skills and Experience :

  • Experience designing firmware or platform security architectures
  • Deep understanding of secure boot chains and firmware trust models
  • Experience designing firmware signing systems and key hierarchies
  • Experience designing secure firmware update mechanisms for platform firmware such as BIOS, BMC, or device firmware, including rollback protection and recovery flows
  • Experience with security architectures for platform management firmware (e.g., BMC or similar controllers)
  • Experience designing platform trust architectures using hardware roots of trust (e.g., TPM, DICE, secure elements) 
  • Solid understanding of applied cryptography in systems (signing, certificates, key hierarchies) 
  • Working knowledge of Linux security fundamentals

“Nice To Have” Skills and Experience :

  • Experience with BMC platforms or ecosystems such as OpenBMC
  • Experience working with PCIe or other device firmware ecosystems
  • Familiarity with secure manufacturing and provisioning flows, including device identity injection or key provisioning
  • Experience reviewing or designing firmware security testing or validation strategies

Please note that a relocation package (including visa sponsorship support) is available for this role, for candidates who require it.

Accommodations at Arm

At Arm, we want to build extraordinary teams. If you need an adjustment or an accommodation during the recruitment process, please email accommodations@arm.com. To note, by sending us the requested information, you consent to its use by Arm to arrange for appropriate accommodations. All accommodation or adjustment requests will be treated with confidentiality, and information concerning these requests will only be disclosed as necessary to provide the accommodation. Although this is not an exhaustive list, examples of support include breaks between interviews, having documents read aloud, or office accessibility. Please email us about anything we can do to accommodate you during the recruitment process.

Hybrid Working at Arm

Arm’s approach to hybrid working is designed to create a working environment that supports both high performance and personal wellbeing. We believe in bringing people together face to face to enable us to work at pace, whilst recognizing the value of flexibility. Within that framework, we empower groups/teams to determine their own hybrid working patterns, depending on the work and the team’s needs. Details of what this means for each role will be shared upon application. In some cases, the flexibility we can offer is limited by local legal, regulatory, tax, or other considerations, and where this is the case, we will collaborate with you to find the best solution. Please talk to us to find out more about what this could look like for you.

Equal Opportunities at Arm

Arm is an equal opportunity employer, committed to providing an environment of mutual respect where equal opportunities are available to all applicants and colleagues. We are a diverse organization of dedicated and innovative individuals, and don’t discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Heads up: this role is no longer open for new applications.

We keep the page live for context and search continuity, but the apply action has been disabled.

Location
Cambridge, the United Kingdom
Work mode
Hybrid
Track
IC (Individual Contributor)
Seniority
Principal
Type
FULL_TIME
PostedJun 24
Arm Holdings logo
Arm Holdings
arm.com
View all 46 Arm Holdings roles →

Was this listing helpful?