Senior Software Engineer (Embedded Security)
Overview:
We are seeking a full-time Senior Software Engineer (Embedded Secruirty) at Garmin's Cary, North Carolina location. In this role, you will be responsible for providing technical leadership and project planning for software development for products, applications, or systems new to Garmin as an individual contributor. You will develop and maintain production embedded software and automated security test capabilities, review product designs and vulnerabilities, and support cybersecurity regulatory compliance efforts, including the European Union Cyber Resilience Act and similar initiatives. A substantial portion of this role will remain focused on hands-on software development.
This position is well-suited to an experienced embedded software engineer with a strong interest in product security who wants to expand their responsibilities into security analysis, defensive testing, risk assessment, and cybersecurity regulatory compliance. Prior formal cybersecurity compliance experience is beneficial but not required.
Responsibilities:
Essential Functions
Serves in a leadership capacity as an individual contributor, developing embedded software in C, C++, Python, Assembly language, or other selected languages for new and existing products, systems, and engineering tools
May serve as a Lead Software Engineer for complex projects and reviews software architectures, modules, and systems supporting new technology or improving the capability, performance, reliability, or security of existing functionality
Provides technical ownership for selected security-critical software components, potentially including services associated with hardware roots of trust, secure elements, cryptographic functions, key management, or Trusted Execution Environments
Decomposes functional, security, and regulatory requirements into well-defined engineering tasks and develops appropriate software solutions based on product architecture, operating environment, and identified risks
Performs peer technical assessments and reviews embedded software and system designs for security weaknesses, regulatory concerns, appropriate use of security controls, and sound engineering practices.
Analyzes product attack surfaces, vulnerabilities, trust boundaries, and potential misuse to determine realistic impact and recommend appropriate remediation, mitigation, or risk treatment.
Develops and maintains automated security, robustness, penetration, and fuzzing test capabilities for Marine products within laboratory and continuous-testing environments.
Assists with cybersecurity compliance analysis, risk assessments, technical documentation, and evidence development for major regulatory initiatives such as the European Union Cyber Resilience Act
Participates in project leadership and program planning, including evaluating technical feasibility, identifying risk, setting schedules, and providing input to product development and cybersecurity plans
Communicates technical security and compliance conclusions across engineering and business organizations and constructively challenges designs, assumptions, or proposed risk decisions when the available evidence does not support them
Plans and manages complex technical assignments with a high degree of independence while balancing software development, analysis, documentation, and compliance deliverables
Mentors less-experienced engineers, contributes to advanced technical research, and recommends improvements to engineering and product-security processes
Qualifications:
Basic Qualifications
Bachelor’s Degree in Computer Science, Electrical Engineering, Computer Engineering, Software Engineering, Aerospace Engineering, Math, Physics or related field AND a minimum of 5 years relevant experience OR an equivalent combination of education and experience
Excellent academics (cumulative GPA greater than or equal to 3.0 as a general rule)
Demonstrated proficiency with designing well architectured software systems and modules that support new technology or improve capability/performance of existing functionality
Demonstrated competence with researching fundamental problems and implementing appropriate algorithmic solutions
Demonstrated ability to serve as a lead software engineer for a complex software project
Ability to decompose functional requirements into well-defined tasks while balancing quality, quantity, and complexity in work output
Demonstrated capability to offer peer technical assessments in areas of expertise, new technologies and software designs
Mastered proficiency in writing software in C, C++, C# or Java and relevant experience and/or training in data structures or object-oriented design methodology
Demonstrated strong and effective verbal, written, and interpersonal communication skills
Must be positive, detail oriented, organized, team oriented and a driven problem solver, multi-tasker, and self-starter with the ability to prioritize and lead in a fast paced, deadline-driven environment
Desired Qualifications
Outstanding academics (cumulative GPA greater than or equal to 3.5)
Experience developing security-critical embedded software, privileged system services, and software associated with secure elements, hardware roots of trust, cryptographic services, key management, secure boot, secure storage, or Trusted Execution Environments
Experience with embedded Linux security mechanisms, inter-process communication, privilege separation, networking protocols, and hardware-access control
Experience performing security design reviews, threat modeling, vulnerability analysis, and product-security risk assessments
Experience developing automated security, adversarial, protocol-robustness, penetration, and fuzzing tests for embedded and network-connected products
Experience with Python for test automation, analysis tools, and engineering infrastructure
Familiarity with software composition analysis, software bills of materials, open-source vulnerability management, and cybersecurity regulations and standards applicable to connected products
Experience working across multiple engineering organizations and within a regulated, safety-related, high-reliability, and process-disciplined product environment.
Garmin International is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, citizenship, sex, sexual orientation, gender identity, veteran’s status, age or disability.
This position is eligible for Garmin's benefit program. Details can be found here: Garmin Benefits