- Robot type
- Drone · Defense
- Location
- IrvineCaliforniaUSA
- Job type
- Software
- Posted
- Sep 18, 2026
- Salary
- $220,000–$292,000 a year
Senior Software Engineer, Embedded Product Security
Job description
The Sentry Tower Software team develops robotic systems that provide force protection capabilities, monitoring the perimeter of secure areas, land or sea, for approaching people, vehicles, and vessels. We live in a world where security officers are increasingly overwhelmed by sensor data feeds. Our products leverage advanced sensor fusion and autonomy to seamlessly render activity in the environment to Lattice’s common operating picture.
Sentry Towers are deployed to secure perimeters, some in contexts where the tower itself is a sensitive asset and physical access by an adversary is a realistic threat.
You’ll own the trusted boot chain top to bottom, on NVIDIA Jetson compute across several…
Job responsibilities
- Own the signed boot chain across compute generations: firmware and bootloader signing, UEFI Secure Boot key hierarchies, signed kernel and initrd, and full-disk encryption with automated unlock.
- Own signing key management and the infrastructure behind it: HSM-backed keys, separation of development and production trust roots, key rotation, and build-time enforcement that the right keys sign the right artifacts.
- Define and implement the platform’s hardening postures, spanning network exposure and firewall policy, privilege and sudo restriction, serial console and USB lockdown, and the difference between a locked-down fielded…
- Drive vulnerability management for the fielded fleet: track CVEs (Common Vulnerabilities and Exposures) against our kernel and userspace, own the patching strategy for hardware approaching vendor end-of-life, and keep…
- Partner with our product security organization to turn security requirements into shippable implementations, act as our team’s security liaison, and support program-specific accreditation efforts.
Job requirements
- 4+ years of professional software engineering with a security focus on Linux or embedded systems.
- Hands-on experience implementing a secure boot chain: code signing, chain of trust, UEFI Secure Boot or an equivalent vendor secure boot implementation.
- Practical cryptographic engineering skills: PKI and certificate hierarchies, HSM or PKCS#11-backed signing, key lifecycle management, and full-disk encryption.
- Strong Linux internals knowledge, particularly in patching, boot flow, kernel and initrd, systemd, privilege boundaries, and filesystem and device access control.
- Proficiency in C or Rust, plus the ability to work fluently in shell.
- Practical hardening and vulnerability-management experience on real systems: attack-surface reduction, CVE triage on a deployed fleet, and live patching strategies that don’t break the product.
- Ability to explain a security decision to engineers who need to implement it, and to a program stakeholder who needs to accept the residual risk.
- US person status required. Active US Secret clearance, or a previously granted Secret clearance eligible for reactivation.
Similar jobs
Anduril · Software
Staff Software Engineer, Discovery
Boston, Massachusetts · Costa Mesa, California
Anduril · Software
Senior Forward Deployed Software Engineer, Strategic Defense
Costa Mesa, California · Seattle, Washington
Anduril · Software
Technical Recruiter, Software - Air Dominance and Strike (Contract)
Boston, Massachusetts · Costa Mesa, California
Anduril · Software
Technical Recruiter, Software - Air Dominance and Strike (Contract)
Seattle, Washington · Costa Mesa, California
