The Staff Security Engineer will identify security risks within our IoT device ecosystem, communicate those risks to management, and assist with the mitigation efforts. This role requires hands-on experience with reverse engineering, networking, operating systems, and programming. The ideal engineer will bring these skills to bear on complex IoT security challenges. The Senior Security Engineer will also document security policies and procedures and ensure they remain up to date with applicable industry standards and compliance requirements.
🏢 About Alarm.com
Alarm.com is the leading platform for intelligently connected properties. Millions of homeowners and businesses rely on Alarm.com's technology to secure, monitor, and manage their environments from anywhere. Our comprehensive suite of solutions—including security, video surveillance, access control, active shooter detection, intelligent automation, energy management, and wellness—is delivered exclusively through a trusted network of thousands of professional service providers and commercial integrators across North America and worldwide. Alarm.com's common stock is traded on Nasdaq under the ticker symbol ALRM. Alarm.com delivers serious security for serious people.
🎯 The Role
The Staff Security Engineer primary job responsibilities include:
✅ Key Responsibilities
Perform IoT penetration testing, including firmware extraction, reverse engineering, and vulnerability discovery
Perform security research, analysis, and testing via threat modeling, vulnerability assessment, penetration testing, and/or social engineering across a wide variety of applications, platforms and systems
Use a combination of manual and automated techniques to assess risks and circumvent security mechanisms of devices and application
Oversee and manage the deployment, integration, and configuration of security solutions and enhancements to existing IoT infrastructure and the enterprise’s security documents
Select and acquire additional security solutions or enhancements to existing security solutions to improve overall IoT enterprise security
Clearly outline and document risk impacts of test findings in reports
Test, triage, and drive remediation of security issues reported by external parties
Actively partner with infrastructure, application, product, and other stakeholders to ensure deployed solutions minimize security and privacy risks
Other duties as assigned
📌 Required Qualifications
B.A. or B.S. (or higher) in Computer Science, Electrical Engineering, or a related engineering program with strong academic performance preferred
10+ years of information security experience, with a strong focus on offensive security, penetration testing, or vulnerability research
Prior experience performing security testing and assessment in IoT, embedded, or firmware based environments
Working knowledge of embedded system design and constraints (development experience a plus, but not required)
Familiarity with using hardware debugging equipment such as oscilloscopes, logic analyzer and other tools
Familiarity with interface protocols such as UART, I2C, SPI, JTAG, and related tooling.
Experience analyzing embedded Linux systems and firmware images.
Familiarity with ARM CPU architectures with exposure to x86, RISC-V, or others as a plus
Experience with reverse-engineering tools such as IDA Pro, Ghidra, and/or Binary Ninja
Certification in one or more Information Security disciplines is preferred or ability to obtain certifications.
Self-starter, analytical, tenacious problem solver
Strong verbal and written communication skills for a highly collaborative environment
Rigorous attention to detail and focus on quality of deliverables
Proven team experience and comfort in a team-oriented environment
Passion for working with technology and excitement for creating high quality consumer technology product
⭐ Desirable Experience
If you feel like you don’t meet all the requirements for this role, we encourage you to apply. We don’t want a few of them to get in the way of meeting a great candidate like you!
🎁 Benefits
Our total rewards package is designed to support you holistically—in your health, your finances, and your life outside of work. The package includes medical plans with company subsidies, a Health Savings Account (HSA) with a company contribution, and a 401(k) with an employer match. We encourage a healthy work-life balance with paid vacation that increases with tenure, paid holidays, wellness time, and paid maternity and bonding leave. To complete the package, we also provide company-paid disability and life insurance, all within a collaborative and casual work environment.
🛂 Visa & Eligibility
Please note that sponsorship of new applicants for employment authorization, or any other immigration-related support, is not available for this position at this time.
Please let Alarm.com know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.