Staff Product Security Engineer

Company: Anduril Industries
Apply for the Staff Product Security Engineer
Location: London
Job Description:

Overview

In this role you will strengthen Anduril’s product security across its AI, autonomy, and embedded systems portfolio. You’ll work with engineering and operations teams to embed secure-by-design practices, conduct architecture reviews, and mitigate vulnerabilities. Your work supports cutting-edge defense tech, from AI systems to hardware-enabled platforms. This is a chance to shape security tooling and documentation for mission-critical systems.

Pay / Benefits

  • equity grants
  • comprehensive benefits
  • competitive compensation
  • health coverage
  • training and development
  • focus on employee well-being

Responsibilities

  • Own the development and maturation of security features for Anduril’s products
  • Authors and maintains security documentation including System Security Plans, Threat Analysis and Risk Assessments, and compliance evidence
  • Collaborates with engineering teams to meet and exceed industry-standard security goals
  • Collaborates with manufacturing and operations teams to develop secure handling and operational processes
  • Engages with teams to remediate uncovered weaknesses in designs, implementations, integrations, and processes
  • Integrates and matures Product Securitys suite of tooling across Anduril’s products
  • Conducts security assessments including architecture review, source code analysis, configuration auditing, and adversarial testing

Key requirements

  • Proficient with one or more programming languages (e.g. C/C++, Golang, Rust, Python)
  • Experience assessing security of firmware, applications, network, IoT, or embedded systems
  • Experience developing features for and improving security of firmware, applications, network, or embedded systems
  • Experience building, testing, and delivering production-ready systems, especially for embedded and/or Linux systems
  • Experience with structured threat modelling and risk assessment methodologies
  • Experience in building and security autonomous systems and their unique threat model
  • Experience in any previous military or defence domain; land, air, sea desirable but not mandatory
  • Familiarity with anti-tamper and reverse engineering hardware and software mechanisms
  • Strong and professional communication skills (written and verbal)
  • Must be eligible to obtain and maintain a UK Security Clearance to a minimum of SC level
  • Must be a UK citizen
  • Preferred Qualifications:
  • Experience with UK Ministry of Defence Cyber Security Model, including
  • UK Government Security Classifications
  • DefStans (05-138 at a minimum)
  • Cyber Secure by Design (including JSP 440’s Cyber Secure by Design guidance and/or JSPs 453 and 604)
  • Defence Information Protection Notices (DIPNs)
  • Industry Security Notices (ISNs)
  • Familiarity with aviation cyber security standards such as DO-326A/ED-202A
  • Experience with SORA or CAA Type Certification cyber requirements
  • Experience engaging with certification bodies like the CAA or MAA/DE&S
  • Familiarity with RF Emanation Protection (including TEMPEST)
  • Experience of Network Security Devices (including Inter-Domain Gateways and Cross Domain Solutions)
  • Familiarity with security architectures of embedded, aerospace, or cyber-physical systems
  • Experience with programmable logic devices and their development tools
  • Regularly builds, tests, and delivers production-ready systems, especially for embedded and/or Linux systems
  • Ideally a sole UK National (i.e. hold no other citizenships)
  • Strong written and verbal communication
  • Collaborative cross-functional work
  • Security-minded problem solving
  • C/C++, Golang, Rust, Python
  • Firmware and embedded system security
  • Architecture reviews and threat modelling

…

Posted: October 1st, 2026