HamburgerMenu
hirist

Sigmasoft - Senior Firmware Vulnerability Management Engineer

Posted on: 23/09/2025

Job Description

Senior Firmware Vulnerability Management Engineer

We are seeking an experienced Senior Firmware Vulnerability Management Engineer to lead the identification, assessment, and mitigation of security vulnerabilities within firmware and embedded systems across our products and infrastructure. In this role, you will drive the development and implementation of secure firmware practices, vulnerability scanning and patch management, and collaborate with cross-functional teams to enhance the security posture of our hardware platforms.

Key Responsibilities :


- Lead the end-to-end vulnerability management lifecycle for firmware and embedded systems, including discovery, risk analysis, remediation tracking, and reporting.

- Conduct firmware vulnerability assessments using static and dynamic analysis tools.

- Coordinate firmware scanning, reverse engineering, and binary analysis to identify security flaws, misconfigurations, and outdated components (e.g., open-source libraries, third-party firmware).

- Work closely with firmware development, hardware engineering, and product security teams to embed secure coding and patching practices.

- Track and analyze CVEs, vendor advisories, and emerging threats related to firmware and embedded components.

- Develop and maintain automated workflows for firmware vulnerability scanning and remediation tracking.

- Contribute to the development and enforcement of secure firmware lifecycle processes, including secure boot, trusted execution, and update mechanisms.

- Collaborate with internal red/blue teams and respond to internal/external audits or security assessments.

- Provide technical guidance on secure hardware and firmware architecture.

Required Qualifications :

- Bachelor's or Masters degree in Computer Engineering, Electrical Engineering, Cybersecurity, or related field.

- Experience in firmware development, reverse engineering, or embedded security.

- Deep understanding of firmware architectures (UEFI, BIOS, RTOS, SoC platforms) and embedded hardware interfaces.

- Strong experience with firmware vulnerability management, CVE tracking, and remediation processes.

- Familiarity with tools such as Binwalk, Ghidra, IDA Pro, QEMU, Firmware Analysis Toolkit (FAT), or similar.

- Solid knowledge of secure coding practices in C/C++, low-level hardware interactions, and memory management.

- Experience with threat modeling, security risk assessments, and vulnerability scoring (CVSS).

- Strong understanding of secure boot, chain of trust, firmware update mechanisms, and TPM/TEE technologies.


info-icon

Did you find something suspicious?