Overview
In this role you will strengthen Anduril’s product security across its AI, autonomy, and embedded systems portfolio. You’ll work with engineering and operations teams to embed secure-by-design practices, conduct architecture reviews, and mitigate vulnerabilities. Your work supports cutting-edge defense tech, from AI systems to hardware-enabled platforms. This is a chance to shape security tooling and documentation for mission-critical systems.
Pay / Benefits
- equity grants
- comprehensive benefits
- competitive compensation
- health coverage
- training and development
- focus on employee well-being
Responsibilities
- Own the development and maturation of security features for Anduril’s products
- Authors and maintains security documentation including System Security Plans, Threat Analysis and Risk Assessments, and compliance evidence
- Collaborates with engineering teams to meet and exceed industry-standard security goals
- Collaborates with manufacturing and operations teams to develop secure handling and operational processes
- Engages with teams to remediate uncovered weaknesses in designs, implementations, integrations, and processes
- Integrates and matures Product Securitys suite of tooling across Anduril’s products
- Conducts security assessments including architecture review, source code analysis, configuration auditing, and adversarial testing
Key requirements
- Proficient with one or more programming languages (e.g. C/C++, Golang, Rust, Python)
- Experience assessing security of firmware, applications, network, IoT, or embedded systems
- Experience developing features for and improving security of firmware, applications, network, or embedded systems
- Experience building, testing, and delivering production-ready systems, especially for embedded and/or Linux systems
- Experience with structured threat modelling and risk assessment methodologies
- Experience in building and security autonomous systems and their unique threat model
- Experience in any previous military or defence domain; land, air, sea desirable but not mandatory
- Familiarity with anti-tamper and reverse engineering hardware and software mechanisms
- Strong and professional communication skills (written and verbal)
- Must be eligible to obtain and maintain a UK Security Clearance to a minimum of SC level
- Must be a UK citizen
- Preferred Qualifications:
- Experience with UK Ministry of Defence Cyber Security Model, including
- UK Government Security Classifications
- DefStans (05-138 at a minimum)
- Cyber Secure by Design (including JSP 440’s Cyber Secure by Design guidance and/or JSPs 453 and 604)
- Defence Information Protection Notices (DIPNs)
- Industry Security Notices (ISNs)
- Familiarity with aviation cyber security standards such as DO-326A/ED-202A
- Experience with SORA or CAA Type Certification cyber requirements
- Experience engaging with certification bodies like the CAA or MAA/DE&S
- Familiarity with RF Emanation Protection (including TEMPEST)
- Experience of Network Security Devices (including Inter-Domain Gateways and Cross Domain Solutions)
- Familiarity with security architectures of embedded, aerospace, or cyber-physical systems
- Experience with programmable logic devices and their development tools
- Regularly builds, tests, and delivers production-ready systems, especially for embedded and/or Linux systems
- Ideally a sole UK National (i.e. hold no other citizenships)
- Strong written and verbal communication
- Collaborative cross-functional work
- Security-minded problem solving
- C/C++, Golang, Rust, Python
- Firmware and embedded system security
- Architecture reviews and threat modelling
…
