Firmware Security Engineer

AMD AMD · Semiconductors · Bangalore, India · Engineering

This role focuses on firmware security engineering for AMD server products, involving architecting, designing, and integrating security solutions, evaluating and addressing vulnerabilities, and drafting CVE/CVSS scores. It requires experience in embedded firmware, pre-boot environments, and vulnerability detection/mitigation.

What you'd actually do

  1. Evaluate and address security vulnerabilities as they are detected, architecting and developing the resolution, as well as drafting the CVE and determining accurate CVSS scores
  2. Design, develop, debug, verify and/or validate firmware/ BIOS, software and/or hardware
  3. Participant in day-to-day firmware/Software development work
  4. Provide consultation to internal and external customers regarding AMD features and programming requirements
  5. Partner with Platform team to bring-up the BIOS and firmware during Embedded SOC bring-up.

Skills

Required

  • firmware security solutions
  • firmware attack points
  • security vulnerabilities
  • CVE/CVSS descriptions and scores
  • embedded firmware
  • pre-boot environment (eg: UEFI, CoreBoot)
  • vulnerability detection and mitigation
  • firmware/ BIOS, software and/or hardware development
  • BIOS and firmware bring-up
  • security threat modelling

Nice to have

  • server platforms
  • software engineering practices
  • DDR, SPI, eSPI, I2C, LPC, and PCIe
  • tight deadlines
  • security threat modelling
  • recent public industry security exploits
  • Excellent communications skills: verbal, written and interpersonal

What the JD emphasized

  • critical
  • security vulnerabilities
  • security threat modelling
  • security exploits