Overview
As a Senior Security Engineer, contribute to Linux platform security through AI-driven automated fuzzing and continuous security assurance across embedded and mobile platforms. Design intelligent fuzzing infrastructure, develop fuzzing harnesses using agentic AI frameworks, perform security risk assessments, and conduct secure code reviews for Linux kernel and driver stacks.
What you'll do
- Design, develop, and deploy AI-agent-driven fuzzing harnesses targeting Linux kernel subsystems, device drivers, and system interfaces using frameworks such as LangChain, Agno, AutoGen, or similar agentic orchestration tools.
- Build and maintain continuous fuzzing pipelines, including OSS-Fuzz, QSS-Fuzz, and ClusterFuzz, integrated into CI/CD workflows for automated vulnerability detection.
- Develop and tune fuzzing campaigns using Syzkaller, libFuzzer, AFL++, and custom mutation strategies.
- Perform security risk assessments and threat modeling on Linux platform components, kernel modules, and firmware interfaces.
- Conduct secure code reviews to identify memory corruption, privilege escalation, race conditions, and other vulnerability classes (CWEs).
- Triage and analyze crash reports, root-cause security bugs, and coordinate patch development with owning teams.
- Research and prototype LLM-assisted harness generation to enable near-autonomous fuzzing target creation for new codebases.
- Collaborate with platform, kernel, and security teams to integrate security requirements across the Security Development Lifecycle (SDLC).
What you'll need
- Bachelor's degree in Engineering, Computer Science, Information Security, or related field and 2+ years of Software/Security Engineering experience, or Master's degree in Engineering, Computer Science, or related field and 2+ years of Software/Security Engineering experience, or PhD in Engineering, Computer Science, Information Security, or related field.
- 2+ years of hands-on experience with programming languages such as C, C++, Python, and scripting for automation.
- Demonstrated experience with Linux kernel development or security research.
- Strong knowledge of Linux kernel internals, including memory management, scheduling, IPC, syscall interface, and kernel security mechanisms such as LSM, seccomp, and namespaces.
- Deep expertise in Linux device driver development, including character devices, platform drivers, PCIe, USB, and UART, and driver debugging.
- Hands-on experience with agentic AI frameworks and the ability to build autonomous agents that reason over codebases to generate and evolve fuzz targets.
- Experience deploying continuous fuzzing infrastructure at scale, including job scheduling, corpus management, crash deduplication, and coverage-guided optimization.
- Proficiency with Syzkaller, including syscall description writing, syzbot integration, repro analysis, and custom grammar extension.
- Strong secure code review skills with the ability to identify vulnerability patterns in C/C++ codebases.
- Strong problem-solving, debugging, and cross-team communication skills.
- Ability to coordinate across stakeholders and manage security deliverables across multiple workstreams.
Nice to have
- Familiarity with firmware security, including UEFI, BIOS, TrustZone/TEE, and secure boot chains.
- 2+ years of Security Engineering experience with a focus on vulnerability research or offensive security tooling.
- Hands-on experience developing fuzzing harnesses for complex kernel or driver targets.
- Proficiency with Syzkaller and/or libFuzzer/AFL++ in production fuzzing campaigns.
- Experience building or contributing to AI/LLM-based code analysis or automated testing pipelines.
- Knowledge of ARM/RISC-V processor architectures, assembly language, and low-level debugging, including JTAG, GDB, and KGDB.
- Familiarity with static analysis tools, including Klocwork, CodeQL, and Semgrep, and integrating them into security pipelines.
- Experience with CVE research, bug bounty programs, or publishing security advisories.
- Understanding of embedded OS security, RTOS security hardening, and firmware attack surfaces.
- Exposure to OSS-Fuzz / ClusterFuzz infrastructure management and coverage reporting.
- Strong written and verbal communication skills with the ability to present security findings to both technical and non-technical audiences.
Details
- Location: Hyderabad, Telangāna, India.
Read the full description and apply on the company’s own careers page.