Principal Firmware Engineer

Summary

Principal Firmware Engineer designs and implements security features for Azure's server and rack infrastructure firmware, working with hardware, firmware, and cross-functional teams to ensure secure, scalable cloud services.

Overview
The Azure Silicon Cloud Hardware Infrastructure and Engineering (SCHIE) team is instrumental in defining and delivering operational success for Azure that exceeds our customers’ expectations. The HW Security Center of Excellence within the SCHIE organization is responsible for the design and development of Security Solutions (Silicon, Firmware, Hardware) for Server and Rack Infrastructure Firmware for Microsoft's global Azure business. We work closely with Microsoft product groups, industry partners, and researchers to architect and develop security features and solutions that meet the requirements for our cloud services platforms at the lowest possible cost of ownership (TCO). We need to be always learning and curious. We need to be comfortable navigating uncertainty, exploring new ideas, and learning from challenges, recognizing that growth comes through continuous learning and development. We need to be open to the ideas of others and celebrate the success of our teammates as part of our shared success.
We are looking for a Principal Firmware Engineer with a background in security to work on securing Azure Infrastructure, both for the existing Azure fleet and incoming new portfolio. You will be responsible for working with architects to understand the security requirements, and for designing and implementing security features for hardware and firmware systems that power Azure today. You have a interest in security and enjoy seeing your code enable features that help secure Azure infrastructure. You have expertise in coding, debugging, and troubleshooting, with experience in firmware development. Additionally, experience with some or all of the following would be beneficial: firmware development, SoC bring-up, security primitives, bootloaders, platform initialization, board support package porting, peripherals such as PCIe, I2C, SPI, USB, UARTs, operating system primitives, memory management, scheduling, interrupts, and multithreading.


Responsibilities
  • Responsible for the architecture, design, and/or implementation of various security firmware components, including driver interfaces, bring-up, and security feature development.
  • Responsible for end-to-end feature delivery, from design to production.Responsible for incorporating Security Development Lifecycle (SDL) practices throughout the development process with a quality-first, test-driven development mindset.
  • Perform system-level debugging and troubleshooting to identify and resolve complex hardware and firmware-related issues while collaborating with cross-functional teams.
  • Collaborate with cross-functional teams, including hardware architects and engineers, software developers, validation and integration teams, and product managers, to define firmware requirements and specifications.
  • Stay up to date with industry trends and advancements in cloud firmware technologies and provide recommendations for improvement.
  • Work closely with Microsoft product groups, industry partners, and researchers to architect and develop server hardware solutions that meet the requirements of our cloud services platforms at the lowest possible cost of ownership (TCO).


Qualifications
  • Bachelor’s or Master’s degree in Computer Science, Computer Engineering, Electronics Engineering, or a related field.
  • 12+ years of professional experience in firmware development, embedded software development in a multicore environment, or hardware and firmware security.
  • 10+ years of programming experience in C, C++, and/or Rust.
  • Demonstrated experience in hardware and firmware architecture, design, and coding for solutions at scale.
  • Experience with SoC bring-up, security primitives, bootloaders, platform initialization, board support package porting, peripherals such as PCIe, I2C, SPI, USB, and UARTs, operating system primitives, memory management, scheduling, interrupts, and multithreading.
  • Experience with secure boot, secure firmware updates, attestation, secure recovery, and secure debug workflows at scale.
  • Solid understanding of computer architectures, including processors, buses, and memory systems.
  • Experience working across multiple teams on root cause analysis, troubleshooting, and debugging, resulting in the resolution of complex hardware and firmware interface issues.
  • Demonstrated problem-solving and analytical skills.
  • Ability to work independently and effectively manage priorities.
  • Effective communication and collaboration skills, with the ability to work effectively in cross-functional teams.

Preferred Qualifications

  • Security-related certifications or qualifications.
  • Experience architecting or implementing industry-standard security protocols, including secure communications, cryptographic algorithms, public key infrastructure, and key management technologies.
  • Familiarity with and understanding of supply chain security.
  • Experience with firmware vulnerability assessment.
  • Experience with penetration testing.
  • Experience with security primitives, cryptographic ciphers, threat vectors, and security mitigation strategies to address identified vulnerabilities.
  • Experience with (RT)OS scheduling and firmware development in multithreaded SMP and heterogeneous computing environments.

This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled.




Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.