Security Firmware Engineer
SandiskAbout the role
Company Description
Sandisk understands how people and businesses consume data and we relentlessly innovate to deliver solutions that enable today’s needs and tomorrow’s next big ideas. With a rich history of groundbreaking innovations in Flash and advanced memory technologies, our solutions have become the beating heart of the digital world we’re living in and that we have the power to shape.
Sandisk meets people and businesses at the intersection of their aspirations and the moment, enabling them to keep moving and pushing possibility forward. We do this through the balance of our powerhouse manufacturing capabilities and our industry-leading portfolio of products that are recognized globally for innovation, performance and quality.
Sandisk has two facilities recognized by the World Economic Forum as part of the Global Lighthouse Network for advanced 4IR innovations. These facilities were also recognized as Sustainability Lighthouses for breakthroughs in efficient operations. With our global reach, we ensure the global supply chain has access to the Flash memory it needs to keep our world moving forward.
Job Description
We are seeking a Security Firmware Engineer to join Sandisk Security Platform team and contribute to the development of firmware‑level security features across our product lines.
This role requires hands‑on experience with security firmware and/or applied cryptography. It is suitable for early‑career engineers with direct security firmware exposure as well as mid‑level engineers who have already delivered security or crypto‑related features in production firmware.
The engineer will work closely with firmware, silicon, and security architecture teams on secure boot, secure update, and device attestation mechanisms, contributing across design, implementation, debug, and validation.
ESSENTIAL DUTIES AND RESPONSIBILITIES:
- Design, implement, and integrate cryptographic functionality and security‑critical firmware features, such as secure boot, secure update, encryption, attestation, and key management.
- Collaborate with firmware, hardware, and system security architects to define and implement trust boundaries and root‑of‑trust designs.
- Debug, optimize, and validate security firmware on Simulation/ ASIC / FPGA platforms.
- Investigate security‑related firmware issues, perform root‑cause analysis, and drive fixes to closure.
- Support security validation, vulnerability testing, and certification or audit activities as required.
- Participate in secure development lifecycle activities, including threat modeling, security design reviews, and secure code reviews.
Qualifications
REQUIRED:
- Bachelor’s or Master’s degree in Computer Engineering, Electrical Engineering, Computer Science, or related field.
- 2–6 years of embedded firmware experience, with demonstrated hands‑on experience in at least one of the following:
- Security firmware features (e.g., secure boot, authentication, secure update, device identity, key management), or
- Implementation or integration of cryptographic functionality in embedded or firmware environments.
- Strong proficiency in C and/or C++ and/or RUST for low‑level firmware development.
- Experience debugging firmware using JTAG, logs, hardware bring‑up tools, or simulators.
- Practical understanding of security fundamentals, such as:
- Roots of trust and boot chains
- Cryptographic primitives (hashes, symmetric/asymmetric crypto, certificates)
- Firmware trust boundaries and privilege levels
- Ability to reason about security impact, correctness, and failure modes in low‑level systems.
Preferred / Additional Qualifications
- Experience with secure boot, measured boot, or attestation implementations.
- Familiarity with key provisioning, secure storage, or certificate chains.
- Experience with SoC architecture, ROM/FW interaction, or storage firmware.
- Exposure to security vulnerabilities and mitigations in embedded systems.
- Experience with Python or scripting for security testing, validation, or tooling.
- Familiarity with secure coding guidelines and industry best practices.
Additional Information
Sandisk is committed to providing equal opportunities to all applicants and employees and will not discriminate against any applicant or employee based on their race, color, ancestry, religion (including religious dress and grooming standards), sex (including pregnancy, childbirth or related medical conditions, breastfeeding
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s