Back to jobs
New

Principal Security Architect

Austin, Texas, United States; Milpitas, California, United States

About Graphcore

Graphcore is a global leader in artificial intelligence computing systems. We design advanced semiconductors, software, and data center infrastructure that provide the specialized processing power needed to advance AI while improving the efficiency required for broad adoption.

As part of SoftBank Group, Graphcore belongs to a family of companies developing progressive technologies. Our teams bring together AI researchers, silicon designers, software engineers, and systems architects to solve sophisticated technical problems across the computing stack.

The Opportunity

As Principal Security Architect, you will define and lead the end-to-end hardware and firmware security strategy for Graphcore's next-generation AI server systems powered by Arm technology.   You will establish security architecture across the system, from the system-on-chip and management controllers through firmware, virtualization, and container environments.

Working within Advanced Architecture, you will protect AI models, training data, inference workloads, and platform intellectual property against remote, physical, and supply-chain threats. You will set technical direction, translate threat models into engineering requirements, and guide teams in delivering hardware-backed isolation, verified boot, secure lifecycle management, and attestation.

What You Will Do

  • Define the hardware and firmware security architecture for Arm-based AI server platforms and maintain a coherent security model across silicon, boards, firmware, virtualization, and system software.
  • Lead the build and integration of Arm's secure computing framework and Realm Management Extension technologies to protect AI models and data in use from operating systems, hypervisors, and other tenants.  
  • Define platform, Baseboard Management Controller, and Rack Management Controller trust anchors, including secure boot, secure firmware update, device identity, provisioning, cryptographic key management, and lifecycle controls.  
  • Specify security requirements for high-speed interfaces and interconnects, including PCIe Gen5 and Gen6 and NVMe Storage Integrity and Data Encryption, to protect data moving among CPUs, AI accelerators, storage, and memory.
  • Lead system-level threat modeling and define mitigations for side-channel attacks, fault injection, privilege escalation, physical tampering, and supply-chain risks.
  • Guide the design and hardening of UEFI, Arm Trusted Firmware, OpenBMC, and related low-level software, including device authentication based on the Security Protocol and Data Model.
  • Architect runtime audit, measurement, and remote attestation frameworks that provide verifiable evidence of platform identity, configuration, and software state.
  • Translate security goals into clear engineering specifications, design requirements, assurance criteria, and review processes for hardware and software teams.
  • Partner with silicon, hardware, firmware, networking, and systems teams to resolve security tradeoffs, review designs, and incorporate security requirements into technology roadmaps.
  • Evaluate emerging threats, standards, and technologies, and represent Graphcore's technical requirements in relevant open-source and industry communities where appropriate.

What You Will Bring

  • An advanced degree or equivalent experience in computer science, computer engineering, cryptography, cybersecurity, or a related technical field, or equivalent practical experience.
  • Extensive experience in hardware security, system-on-chip security, platform architecture, or a closely related field, including technical leadership at Principal, Staff, or Lead Architect scope.
  • Deep knowledge of Arm architecture and security technologies, including Armv9, TrustZone, Confidential Compute Architecture, and the Realm Management Extension feature.  
  • Demonstrated experience in crafting server or platform security frameworks that use trusted platform modules, roots of trust, hardware cryptography, secure provisioning, and lifecycle management.  
  • Strong understanding of how hardware security primitives interact with firmware and system software, including Linux kernel internals, KVM, containers, and trusted execution environments.
  • Expert knowledge of hardware and platform threats, physical attack methods, side-channel risks, fault injection, and supply-chain vulnerabilities.
  • Experience with secure boot, firmware update security, cryptographic key management, device identity, attestation, and audit design.
  • Ability to convert complex security concepts and threat analyses into precise, testable engineering requirements and architecture decisions.
  • Proven track record to lead multi-functional technical work and influence senior engineers and leaders without direct authority.
  • Clear written and verbal communication skills, including the ability to explain risk, tradeoffs, and recommended controls to technical and executive audiences.

Preferred Qualifications

These qualifications are helpful, not required. We encourage you to apply even if you do not meet every preferred qualification.

  • Experience designing security architectures that protect machine learning weights, intellectual property, and datasets during distributed training and inference.
  • Participation in or contributions to security standards and industry groups such as the Trusted Computing Group, Open Compute Project Security Project, Linux Foundation, Confidential Computing Consortium, or Arm security working groups.
  • Knowledge of SmartNIC security and the use of network devices to enforce network or storage isolation within server systems.
  • Understanding of post-quantum cryptography and its implications for hardware lifecycle, trusted startup processes, firmware, and silicon build.  
  • Experience applying emerging confidential-computing technologies to AI training or inference use cases.

United States Benefits Overview

Graphcore offers competitive compensation and benefits designed to support employees' health, financial well-being, work-life needs, and professional growth. Benefits and programs for eligible U.S. employees may include:

  • Medical, dental, and vision coverage, with options that may extend to eligible dependents.
  • Mental health, wellness, and employee assistance resources.
  • Retirement savings benefits and company contributions where applicable.
  • Paid vacation, sick time, company holidays, and parental or family leave in accordance with relevant plans and policies.  
  • Life insurance and short-term or long-term disability coverage.
  • Flexible working hours and hybrid working arrangements where compatible with the role and team requirements.
  • Professional-development resources, learning programs, office amenities, and team-led activities.

Benefits vary by work location, employment status, scheduled hours, and plan eligibility and are subject to the terms of the applicable plans and company policies. This overview is not a contract or guarantee of benefits.

Equal Opportunity and Accommodations

Graphcore is an equal opportunity employer. We consider qualified applicants without regard to race, color, religion, creed, sex, pregnancy, sexual orientation, gender identity or expression, national origin, ancestry, age, disability, genetic information, veteran status, or any other status protected by applicable law.

Graphcore is committed to an inclusive and accessible hiring process. If you need a reasonable accommodation to participate in the application or interview process, please let the recruiting team know.

Candidate Privacy

Personal information submitted during the recruiting process will be handled in accordance with Graphcore's applicable candidate privacy notices.

Create a Job Alert

Interested in building your career at Graphcore? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Graphcore’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...