Title: Software Design Engineer 4Location: Redmond, WA (3 days - Hybrid)Summary:- Build and advance a next-generation firmware security analysis platform within Azure Hardware Security.
- This system combines large language models (LLMs), compiler technology, and automated fuzzing to identify security vulnerabilities in firmware at scale, significantly reducing the effort required for manual security assessments.
- The project addresses a critical industry challenge: much of today's firmware is developed by third parties and has not historically been analyzed with the same rigor as first-party software.
- By automating key aspects of firmware security review, this platform enables repeatable, scalable analysis that improves overall security posture while supporting a broader ecosystem of hardware and firmware providers.
- As a member of the engineering team, you will work directly with security researchers, compiler engineers, and platform developers to build production-quality tooling spanning LLVM, fuzzing infrastructure, static analysis, AI-assisted automation, and open-source engineering practices.
Responsibilities:Build and Enhance Security Analysis Pipelines
- Develop preprocessing pipelines that compile C/C++ firmware code into LLVM Intermediate Representation (IR).
- Implement and maintain LLVM-based transformations to make firmware suitable for off-target analysis and fuzzing.
- Create and improve code-analysis workflows, including call-graph extraction, metadata generation, and static-analysis integrations.
- Design and maintain systems that generate and execute fuzzing campaigns using modern fuzzing frameworks and AI-assisted techniques.
- Improve crash triage systems that automatically identify, deduplicate, and analyze security findings.
- Develop automated mechanisms to classify code semantics and improve analysis accuracy.
Security Automation and Tooling
- Build scalable automation that combines compiler infrastructure, security tooling, and AI-driven workflows.
- Enhance vulnerability detection pipelines and help reduce false positives through improved analysis techniques.
- Improve reporting systems that transform raw security findings into actionable engineering insights.
- Validate analysis approaches across multiple firmware targets and environments.
Open-Source Readiness
- Improve system reliability, modularity, test coverage, and CI/CD automation.
- Create developer documentation, onboarding guides, and architectural references.
- Support dependency review, reproducible builds, and general open-source readiness activities.
- Help establish contribution workflows, issue triage practices, and release processes for external contributors.
Engineering Excellence
- Write clean, maintainable, and well-tested code.
- Participate in design reviews and technical architecture discussions.
- Collaborate closely with engineers across security, hardware, and platform teams.
- Contribute to long-term technical strategy and platform evolution.
Required Qualifications:- Bachelor's degree in Computer Science, Computer Engineering, or a related technical field, or equivalent practical experience.
- Strong professional experience developing software in C/C++.
- Hands-on experience with compiler technologies, LLVM, or low-level systems programming.
- Experience working with fuzzing frameworks such as libFuzzer, AFL, AFL++, or similar technologies.
- Strong understanding of software security principles, including memory-safety vulnerabilities and root-cause analysis.
- Proficiency with Python for automation and tooling development.
- Experience using Git-based development workflows.
- Demonstrated ability to write well-tested, maintainable, and documented production code.
Preferred Qualifications:- Experience with firmware, embedded systems, device software, or bare-metal development.
- Knowledge of hardware abstraction layers (HALs), MMIO, emulation, rehosting, or cross-compilation techniques.
- Experience with static-analysis platforms such as CodeQL.
- Familiarity with program-analysis concepts such as call graphs, data-flow analysis, or IR transformations.
- Experience integrating AI, machine learning, or LLM technologies into engineering workflows.
- Previous open-source contributor or maintainer experience.
- Experience building CI/CD pipelines and release automation.
- Familiarity with Azure DevOps, GitHub, or similar development platforms.
Explain a typical day in the role:- A typical day on Project Talonera involves building and improving AI-driven firmware security analysis pipelines that automatically discover vulnerabilities in third-party firmware. Engineers spend their time developing low-level tooling in C++, Python, and LLVM, transforming firmware source code into analyzable LLVM IR, creating compiler passes, generating and refining fuzzing harnesses, and improving automated vulnerability detection workflows.
- Daily work may include debugging firmware rehosting issues, investigating crashes discovered during fuzzing campaigns, reducing false positives in security findings, and enhancing LLM-based systems that classify firmware functionality and generate analysis artifacts.
- Team members collaborate closely with security researchers, compiler engineers, and project leadership to review architecture, prioritize new capabilities, and validate analysis results across diverse firmware targets.
- As Talonera moves toward open-source release, engineers also contribute to code quality improvements, CI/CD automation, testing, documentation, dependency reviews, developer onboarding experiences, and release-readiness activities, helping transform advanced security research into a production-grade platform that can be used and extended by the broader security community.
What is the ideal background of a candidate for this role?- The ideal candidate for Project Talonera is a systems software engineer with a strong security mindset who enjoys working at the intersection of compiler technology, firmware analysis, fuzzing, and AI-assisted automation.
- They likely have several years of professional experience developing low-level software in C/C++, are comfortable working directly with LLVM and LLVM IR, and have hands-on experience building or modifying compiler passes, analysis tools, or developer tooling.
The strongest candidates will come from backgrounds such as:- Compiler and Program Analysis Engineering - experience with LLVM, code transformation, static analysis, CodeQL, call-graph analysis, dataflow analysis, or language tooling.
- Security Engineering and Research - experience with fuzzing (libFuzzer, AFL/AFL++), vulnerability discovery, crash triage, exploit mitigation, sanitizer technologies (ASan, UBSan, MSan), and root-cause analysis.
- Firmware or Embedded Systems Development - familiarity with firmware architectures, hardware abstraction layers (HALs), MMIO interfaces, cross-compilation, bare-metal systems, or rehosting techniques.
- Developer Platform and Tooling Engineering - experience building scalable automation pipelines, CI/CD systems, code-generation tools, testing frameworks, and production-quality open-source software.
- In short: Talonera is ideal for candidates who want to work on cutting-edge security challenges, leverage modern AI techniques, contribute to open source, and build technology that has meaningful impact on the security of hardware and firmware ecosystems at scale.
Top 3 Must-Have HARD Skills & years of experience for each:- LLVM / Compiler Engineering - 5+ years
- C/C++ Systems Programming - 7+ years
- Security Fuzzing & Vulnerability Research - 3-5+ years
Salary Range:$1,70,000 - $1,80,000 Annually -Factors that may affect pay within this range may include geography/market, skills, education, experience, and other qualifications of the successful candidate.
Benefits:The Company offers the following benefits for this position, subject to applicable eligibility requirements: [medical insurance] [dental insurance] [vision insurance] [401(k) retirement plan] [long-term disability insurance [short-term disability insurance] [5 personal days accrued each calendar year. The Paid time off benefits meet the paid sick and safe time laws that pertain to the City/ State] [10-15 days of paid vacation time] [6 paid holidays and 1 floating holiday per calendar year]
Want to change the world? Let us know.
Tell us about your experiences, education, and ambitions. Bring your knowledge, unique viewpoint, and creativity to the table. Let's talk!
Preferred Skills C/C++ Systems Programming
Job details Job ID 332890
Role Software Design Engineer
Location Redmond, Washington, US
Job type Direct Hire
Recruiter Aman
Email
[email protected]