Principal Security Engineer – Fuzzing Specialist

Company: ARM
Apply for the Principal Security Engineer – Fuzzing Specialist
Location: Cambridge
Job Description:

Overview

In this role, you develop and advance Arm’s coverage-guided fuzzing program to uncover hard-to-reach security flaws and drive fixes. You’ll design high-performance fuzzing harnesses, build custom sanitisers, and lead data-driven security assessments that scale across products. You work with cross-functional teams to expose attack surfaces and deliver measurable coverage gains and actionable crash reports. Your work supports resilient software and helps products ship with provable security.

Responsibilities

  • Map fuzzing surfaces across services, libraries, APIs, and protocols and maintain a risk-based roadmap
  • Design, build, and extend fuzzing harnesses (libFuzzer, AFL++, Honggfuzz) to improve code-path exploration and reduce false positives
  • Grow seed corpus, apply targeted mutation strategies, and add instrumentation to improve coverage
  • Automate crash triage and root-cause analysis, differentiate exploitable crashes from benign faults, drive CVE-level remediation
  • Develop custom sanitisers to reveal bugs missed by traditional fuzzing
  • Validate fixes and guard against regressions via differential fuzzing and regression corpora
  • Assess external disclosures to refine fuzzing coverage and harnesses
  • Document and share insights from coverage metrics and post-mortems to enable data-driven security

Key requirements

  • 1+ years in application or product security with a deep focus on coverage-guided fuzzing
  • Hands-on experience with at least one modern fuzzing framework (libFuzzer, AFL++, Honggfuzz)
  • Proficient in C/C++ with strong Python scripting for automation
  • Solid understanding of memory-safety vulnerabilities, undefined behaviour, sanitisers, and compiler instrumentation
  • Experience triaging crashes using debuggers/profilers and reverse-engineering tools (gdb/lldb, IDA/Ghidra)
  • Excellent written communication for documenting findings and influencing engineering teams
  • written communication
  • cross-functional collaboration
  • analytical thinking
  • coverage-guided fuzzing
  • libFuzzer
  • AFL++

…

Posted: September 30th, 2026