New

Senior Cyber Software Engineer

Irvine, California, United States; Washington, District of Columbia, United States

Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.

 

ABOUT THE TEAM

The Air Defense team is responsible for the cryptographic foundation and platform trust that makes Anduril's Air Defense products deployable in the world's most demanding environments. The team owns everything from firmware and secure boot to key management, anti-tamper, and the compliance automation that keeps systems accredited — across a portfolio of proprietary hardware and software operating in contested, classified, and often disconnected conditions.

ABOUT THE JOB

Air Defense employs a variety of advanced proprietary software and hardware products to support global operations. The Cyber Engineer designs and implements the cryptographic and platform security that makes those products trustworthy in contested and classified environments — FIPS-validated encryption, secure and measured boot, full-disk encryption, anti-tamper and zeroization, and secure communications across degraded links.

This is a hands-on engineering role at the lowest levels of the stack. You will implement cryptography and key handling on constrained hardware, harden Linux and firmware, build the audit and validation tooling that proves the design behaves as specified, and automate the evidence accreditation requires. You will be the engineer government reviewers talk to when they want a real technical answer - but your output is code, firmware, and systems.

We are looking for depth in how systems actually fail: someone who has implemented or attacked crypto, boot chains, and protocols, and who reaches for a debugger and a specification rather than a checklist. Backgrounds in vulnerability research, reverse engineering, or national-security cryptographic engineering map directly onto this work. 

WHAT YOU'LL DO

  • Implement and improve FIPS 140-3 validated encryption across products — algorithm selection, module boundaries, entropy sources, key derivation, and the validation evidence that keeps certification current.
  • Own the platform trust chain: secure and measured boot (U-Boot/UEFI), TPM-backed attestation, firmware signing, and rollback protection on embedded and edge hardware.
  • Design and implement full-disk and data-at-rest encryption, key management and rotation, and key hierarchies that survive field conditions.
  • Build anti-tamper and zeroization: tamper detection and response, emergency erase, key destruction paths, and the tests that prove they work under adversarial conditions.
  • Engineer secure communications - protocol design and review, mTLS and workload identity, tunnels and gateways for cross-domain and air-gapped transport, and CNSA-compliant cipher suites.
  • Build audit and validation tooling: instrumentation that proves cryptographic and boot-time behavior, plus the harnesses, fuzzers, and adversarial tests that try to break your own designs.
  • Harden Linux, container, and firmware baselines - kernel configuration, SELinux/AppArmor, attack-surface reduction - and codify them so they hold across every deploy.
  • Automate the compliance surface so it stays out of everyone's way: express NIST 800-53, STIG, and CNSSI requirements as machine-readable policy evaluated in CI, generating accreditation evidence as build output - and when a control's intent is better met by a different implementation, make that argument to reviewers with evidence.

REQUIRED QUALIFICATIONS

  • You write production code, and we will evaluate you on it. Real fluency in C/C++, Rust, Golang, or Python — C or Rust strongly preferred for the firmware and cryptographic work — and the ability to read and modify the others.
  • 5-8 years of engineering experience with deep technical ownership of security-critical systems. Time spent primarily authoring policy, running scan tools, or coordinating artifacts will not substitute.
  • Applied cryptography in practice rather than theory: you have implemented or integrated cryptographic libraries, handled keys and entropy correctly, and can explain how a device proves its identity at boot and how that trust is revoked.
  • Low-level systems depth: the Linux kernel and userspace boundary, memory, filesystems, device drivers or firmware, and the ability to debug all of it with the tools you would expect — gdb, ftrace, and a logic analyzer when it comes to that.
  • Experience assessing and hardening firmware, embedded, or cyber-physical systems, and a demonstrated understanding of how skilled adversaries attack them.
  • Secure communications and network protocol work: TLS/PKI internals, tunneling, and what breaks in disconnected or degraded networks.
  • Experience building and sustaining CI/CD systems; you treat pipelines and infrastructure as software, with version control, review, and tests.
  • Working command of RMF and NIST 800-53 — enough to know exactly what an assessor needs and to automate producing it. You do not need to have been a full-time assessor.
  • Currently possesses and is able to maintain an active U.S. Top Secret security clearance; TS/SCI with polygraph preferred.

PREFERRED QUALIFICATIONS

  • 8+ years of relevant engineering experience, or equivalent depth from a national-security cryptographic or capabilities-development background.
  • Direct experience with FIPS 140-2/140-3 validation, CSfC, Type 1 encryption, HAIPE, or KMI.
  • CNSA 2.0 / Suite B implementation, or post-quantum cryptography migration work.
  • Vulnerability research, reverse engineering, exploit development, or hardware attack experience (fault injection, side channel, JTAG/SWD).
  • Anti-tamper, TEMPEST, or physical security engineering for deployed systems.
  • Embedded and edge depth: U-Boot/UEFI, TPM/TEE (OP-TEE, TrustZone), secure elements, and the realities of constrained or intermittently connected devices.
  • Rust or Golang shipped at production scale in a security-critical component, or took a system through ATO or IATT as the responsible engineer.
  • Policy-as-code at scale (OSCAL, OPA/Rego, OpenSCAP, InSpec), plus Terraform, Ansible or Nix, and Kubernetes hardening.
  • Degree in Computer Science, Computer Engineering, Cybersecurity, or a related discipline — or equivalent demonstrated experience. Familiarity with NISPOM (32 CFR Part 117), DAAPM, JSIG, and CNSSI 1253 is a plus.

US Salary Range

$191,000 - $253,000 USD

The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril's total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including: 

 

Benefits

At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you’re supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits.

 

Protecting Yourself from Recruitment Scams

Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. We've observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives, luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information.

To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind:

  • No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates.

  • Please always verify communications:
    • Direct from Anduril: If you receive an email from one of our recruiters, it will only come from an @anduril.com address.
    • Via Agency Partner: If contacted by a recruiting agency for an Anduril role, their email will clearly identify their agency. If you suspect any suspicious activity, please verify the agency's authenticity by reaching out to contact@anduril.com
  • Exercise Caution with Unsolicited Outreach: If you receive any communication that appears suspicious, contains grammatical errors, or makes unusual requests, do not engage. Always confirm the sender's email domain is @anduril.com before providing any personal information or clicking on links.

  • What to Do If You Suspect Fraud: Should you encounter any questionable or fraudulent outreach claiming to be from Anduril, please report it immediately to contact@anduril.com. Your proactive caution is invaluable in protecting your personal information and upholding the security and trustworthiness of our recruitment efforts.

 

Data Privacy

To view Anduril's candidate data privacy policy, please visit https://anduril.com/applicant-privacy-notice/. 

 

By submitting your application, you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists, adverse media, public-record information, and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology, intellectual property, and organizational security.

Create a Job Alert

Interested in building your career at Anduril Industries? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...

Do you presently hold an active U.S. security clearance, or are you eligible to obtain and maintain a U.S. security clearance?  

For more information about U.S. Security Clearances: click here

Select...
Select...

Are you any of the following “protected individual(s)” as defined in the Immigration and Naturalization Act, 8 U.S.C. 1324b(a)(3)?:

Select...

Are you authorized to work in the United States?

Select...
Select...

Have you previously applied to a position at Anduril?

Select...
Select...

Do you currently, or have you in the last 5 years, worked for the US government (e.g., Congressional staffer, member of the military, state, or federal agencies) and had oversight or similar responsibility over Anduril’s business or other interests?   

Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Anduril Industries’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 07/31/2029

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.