ARM

ARM

Cambridge, East of England

Principal Security Engineer Fuzzing Specialist

Full-Time£45,000 - 80,000 per yearavant-hierUnited Kingdom
IT

Job Description

Salary: £45,000 - 80,000 per year

Requirements:
  • 1+ years in application or product security with a deep focus on coverage-guided fuzzing.
  • Hands-on expertise with at least one modern fuzzing framework (e.g., libFuzzer, AFL++, Honggfuzz).
  • Proficiency in C/C++ plus strong scripting ability in Python for automation.
  • Solid understanding of memory-safety vulnerabilities, undefined behaviour, sanitisers, and compiler instrumentation.
  • Demonstrated ability to triage crashes using debuggers, profilers, and reverse-engineering tools (gdb/lldb, IDA/Ghidra).
  • Excellent written communication for documenting findings and influencing engineering teams.
  • Contributions to open-source fuzzing tools, sanitisers, or security research publications.
  • Knowledge of distributed fuzzing at scale (GCP/AWS, Kubernetes, or bare-metal clusters).
  • Familiarity with kernel, embedded, or firmware fuzzing (e.g., Syzkaller, QEMU-based harnesses).
  • Background in reverse engineering, static analysis or symbolic execution.
  • Experience integrating fuzzing into CI/CD pipelines and tracking coverage metrics.
Responsibilities:
  • Map and prioritise fuzzing surfaces across services, libraries, APIs, and protocols; maintain a living risk-based roadmap.
  • Design, build, and extend fuzzing harnesses (libFuzzer, AFL++, Honggfuzz, etc.) that improve code-path exploration and minimise false positives.
  • Continuously improve coverage by growing the seed corpus, deploying targeted mutation strategies, and integrating new instrumentation techniques.
  • Automate crash triage and root-cause analysis; distinguish exploitable vulnerabilities from benign faults and drive CVE-level findings to remediation.
  • Develop custom sanitisers to expose classes of bugs traditional fuzzing misses.
  • Validate fixes and guard against regressions through differential fuzzing and regression corpora.
  • Assess external disclosures (bug bounties, supply-chain advisories) to determine fuzzing detectability and refine harnesses when gaps are found.
  • Document, report, and share insights — from coverage metrics to post-mortems to create data-driven security.
Technologies:
  • ARM
  • AWS
  • CI/CD
  • Embedded
  • Firmware
  • GCP
  • Support
  • Kubernetes
  • Python
  • QEMU
  • Security
  • Cloud
  • AI

More:

At Arm, we believe progress happens when people are empowered to think bigger and push beyond what seems possible. Our 10x mindset is about curiosity, ambition and creating impact that will be used by millions. We learn fast, prioritise collaboration and turn bold ideas into real technology. We look for people who are inspired by this way of working and want to grow in an environment where bold ideas are welcomed. We offer hybrid working designed to support high performance and personal wellbeing, with team-specific patterns shared upon application. We are an equal opportunity employer committed to mutual respect and an inclusive environment for all applicants and colleagues. We also provide recruitment adjustments and accommodations where needed.

last updated 35 week of 2026

Interested in this role?

Submit your application now

How to Apply

Ready to apply for this position? Here's what you need:

  • An updated resume highlighting relevant experience
  • A compelling cover letter (if required)
  • Portfolio or work samples (for relevant positions)

About ARM

ARM

ARM

Cambridge

IT

Skills & Technologies

PythonC++AWSGCPKubernetesCI/CDAIUI

Inferred from job description

Salary Insight

£62,500

This role

£60,000

UK median

This salary is 4% above the UK median for Software Engineers60,000/yr).

Based on 2024–2025 UK technology sector benchmarks

Explore More UK Opportunities

Thousands of tech jobs across the United Kingdom