Research Intern - Firmware Security

Microsoft Microsoft · Big Tech · Redmond, WA +1 · Research Sciences

Research intern role focused on applying LLMs to improve firmware code reviews and static analysis workflows. The role involves prototyping techniques that combine traditional static analysis with LLM reasoning, including correlating findings, deduplicating results, and prioritizing issues. It also explores agentic workflows to enhance signal quality.

What you'd actually do

  1. Research and prototype ways to apply LLMs to firmware-focused code review, including summarization of findings, reasoning over call stacks, and generating actionable reviewer guidance.
  2. Integrate and evaluate LLM-driven approaches alongside existing static analysis tools used in firmware pipelines, with attention to false positives, deduplication, and explainability.
  3. Experiment with “agentic” or multi-step workflows that combine tool outputs (e.g., static analysis) with LLM reasoning to verify or refute findings and improve signal quality.
  4. Collaborate with firmware, security, and systems engineers to define success metrics and validate prototypes on representative firmware codebases and workflows.
  5. Document results and present recommendations that help scale secure firmware development and review practices.

Skills

Required

  • Python
  • C/C++
  • Rust
  • systems-level code
  • firmware/OS/hardware-adjacent code

Nice to have

  • static analysis concepts and outputs
  • firmware or embedded systems development
  • secure boot/update pipelines
  • security review methods used for privileged code
  • applying LLMs to security engineering problems
  • vulnerability discovery and remediation workflows

What the JD emphasized

  • firmware code reviews
  • static analysis workflows
  • LLM reasoning
  • agentic workflows

Other signals

  • applying LLMs to firmware code reviews
  • combining static analysis with LLM reasoning
  • agentic workflows for security analysis