Senior Product Security Engineer Audio Tech
Framingham, MA - USA
Job Summary
At Bose Corporation we believe sound is the most powerful force on earth and for over 60 years we have been a company built on innovation excellence and independence. Privately owned fiercely customer-focused and driven by our values we continue to lead industries and transform lives through sound.
Today Bose Corporation is entering an exciting new era. Across multiple global Business Units and Global Functions we are shaping the future of audio technology automotive luxury and premium experiences. We invite you to join us in this transformation.
At Bose security and stability are the two pillars of our product innovation. We are seeking a Security Engineer to support the product security initiatives of our growing Audio Technology business. You will play a central role in securing Boses proprietary audio technologies. As Bose continues to innovate there is a constant need to protect our intellectual property and embed security throughout the development lifecycle. The ideal candidate has extensive experience in secure software development within a fast-paced agile product environment. Join our Product Security team to help power the next wave of innovation at Bose.
As a Security Engineer you will work as an integral part of the Product Security team to embed security practices into every aspect of the secure development pipeline from concept through release of licensed IP. Our development philosophy is to enable developers to write secure code faster.
Responsibilities for this job include:
Architecting and implementing protections for intellectual property including anti-reverse engineering secure firmware distribution and debug interface lockdown
Collaborating with cross-functional teams including product firmware Audio Technology DevOps cloud engineering manufacturing and program management
Architecting and designing products to guarantee secure practices data confidentiality and system integrity
Engineering and implementing ARM TrustZone secure applets implementing a cryptographic IoT device identity and root of trust
Streamlining secrets key management cryptography and credential management
Defining security requirements and conducting security assessments
Implementing firmware and intellectual property (IP) protection mechanisms to safeguard proprietary software and embedded technologies
Performing obfuscation of firmware and algorithm binaries to protect against reverse engineering and unauthorized modification
Integrating firmware encryption digital signing and integrity verification into embedded software and secure update processes
Ensure compliance with applicable security regulations and standards (e.g. EU CRA ETSI EN 303 645 NIST) and support audits and certifications
Advising engineering peers on security matters in the form of architectural guidance code/design reviews and solution development
Improving vulnerability discovery patching processes and leading responses to external security threats
Performing security testing on products and supporting security fix implementations
Designing and maintaining private X.509 and JWK chains of trust used for validating the authenticity of portable audio devices
Stay up-to-date on security news relevant technologies user groups industry trends and emerging security opportunities
Be a stakeholder on interdisciplinary teams advocating for security
Experience delivering licensed software that runs on customer products and systems where you do not trust the system it runs on.
Hands-on experience implementing firmware protection mechanisms including secure boot firmware encryption digital signing secure firmware distribution and anti-tamper controls
Experience implementing binary obfuscation and anti-reverse engineering techniques for embedded firmware or proprietary algorithm binaries
Experience implementing IP protection and anti-tamper mechanisms in embedded systems including secure boot enforcement firmware encryption and hardware debug port protection
Experience developing for embedded systems and Linux platforms in C/C.
Strong knowledge of cryptographic theory and engineering including encryption hashing signing digital certificates and hardware security modules (HSMs)
Experience collaborating with cross-functional engineering teams to integrate security controls into embedded products throughout the development lifecycle
Bachelors degree in Computer Science or equivalent. A masters degree is beneficial
6 or more years of industry experience working in firmware development with a focus on security. An advanced degree can contribute toward experience
Experience aligning embedded product security practices with regulatory and compliance requirements (EU CRA NIST ISO 27001 IEC 62443 or similar frameworks)
Building internal security applications with cryptographic guarantees such as firmware encryption and signing custom developer enablement tools secure asset provisioning etc
Experience developing for mobile applications (IOS or Android)
Experience mitigating dependency or code-level defects including memory management issues input validation timing attacks broken authentication and side-channel attacks
Working with wicked smart super cool people
A business commitment to security stability and quality
Competitive salary benefits and pension
A culture of excellence respect opportunity and passion for innovation
Required Experience:
Senior IC
About Company
Find customer support services and authorized resellers available in your location.