Software Engineer (L6), Platform Security
Software Engineering
United States · Remote
At Netflix, our mission is to entertain the world. Together, we are writing the next episode - pushing the boundaries of storytelling, global fandom and making the unimaginable a reality. We are a dream team obsessed with the uncomfortable excitement of discovering what happens when you merge creativity, intuition and cutting-edge technology. Come be a part of what’s next.
At Netflix, we want to entertain the world and are constantly innovating on how entertainment is imagined, created and delivered to a global audience. We currently stream content in more than 30 languages in 190 countries, topping over 250 million paid subscribers and are expanding into new forms of entertainment such as gaming.
Open Connect (OC) is a critical group within Netflix that builds and manages a content delivery network (CDN) that delivers all of Netflix’s streaming video. In addition to streaming video, we work on projects within Netflix that leverage physical infrastructure, such as our Cloud Games and Live initiatives. According to a 2023 Sandvine report, data delivered by OC accounts for approximately 15% of all downstream traffic volume across the entire internet. Most of this traffic is delivered by our edge cache servers.
A small team of talented software engineers develops and maintains the operating system and platform that run the content caches. These appliances run a heterogeneous, deeply integrated stack, including Linux, FreeBSD, firmware, BMC, FPGAs, BIOS/UEFI, and containers. Because of the important role these caches serve, it is critical that they be both efficient and secure from the hardware up.
We are looking for a Security Software Engineer to architect and implement system-level security for the OC edge and gaming appliances, serving as the in-house home for hardware and low-level OS security assurance, with the opportunity to directly impact a critical area of the business.
In this role, you will:
Define and evolve the security architecture of the full compute stack, from hardware interfaces (FPGA, BIOS/UEFI, BMC) through dual operating systems (FreeBSD and Linux).
Implement security enhancements using a variety of methods such as kernel and user-space development, configuration changes, or leveraging hardware-based security features such as TPMs and hardware offload.
Drive platform integrity work including measured/secure boot for appliances and improved BMC access controls and auditability.
Analyze and triage new system-level security bugs, including hardware/GPU and OS isolation issues and provide appliance security expertise during incident response.
Partner with stakeholders in different organizations to build secure architecture for binary ingestion and execution..
Develop automated systems and low-level tooling to perform vulnerability research and reduce manual security overhead in build, test, and release workflows.
Act as a security liaison between OC and other organizations, and stay plugged into the right external groups (silicon/firmware vendors, OS communities, disclosure partners).
Demonstrate versatility by learning and adapting to new architectures and features as they evolve.
Qualifications:
Proven track record of architecting and implementing security features that meaningfully improve system security.
Deep expertise in low-level systems and hardware security across a heterogeneous stack (kernels, firmware, BMC, BIOS/UEFI, FPGA).
Experience using operating system execution environments such as containers or virtual machines to enhance security.
Success at partnering with others to improve the security posture through cross-functional changes.
Experience using AI agents to automate security research.
You will be successful in this role if you:
Have the ability to define and self-manage cross-functional projects fueled by ambiguous questions.
Able to partner with business and product stakeholders to translate their goals into security requirements and technical design and implementation.
Are a self-starter, curious and not afraid to ask when in doubt.
Are a quick learner and excited about learning new technologies.
Advocate thoughtful collaboration, take pride in your work and enjoy taking full ownership of projects from conception to production.
Nice to have:
Experience conducting security research, with published materials to show for it.
Experience conducting penetration tests which found meaningful opportunities for improvement and identified security gaps.
Kernel development experience.
Experience successfully using TPMs/HSMs, trusted execution environments, and other hardware features.
Experience with measured/secure boot and hardware roots of trust.
Experience working on highly distributed systems and fuzzing complex systems.
Experience securing FreeBSD, Linux; familiarity with GPU/virtualization isolation.
Experience with C, Golang, Python.
Generally, our compensation structure consists solely of an annual salary; we do not have bonuses. You choose each year how much of your compensation you want in salary versus stock options. To determine your personal top of market compensation, we rely on market indicators and consider your specific job family, background, skills, and experience to determine your compensation in the market range. The range for this role is $499,000.00 - $900,000.00. This compensation range will vary based on location.
Netflix provides comprehensive benefits including Health Plans, Mental Health support, a 401(k) Retirement Plan with employer match, Stock Option Program, Disability Programs, Health Savings and Flexible Spending Accounts, Family-forming benefits, and Life and Serious Injury Benefits. We also offer paid leave of absence programs. Full-time hourly employees accrue 35 days annually for paid time off to be used for vacation, holidays, and sick paid time off. Full-time salaried employees are immediately entitled to flexible time off. See more details about our Benefits here.
Netflix is a unique culture and environment. Learn more here.
Inclusion is a Netflix value and we strive to host a meaningful interview experience for all candidates. If you want an accommodation/adjustment for a disability or any other reason during the hiring process, please send a request to your recruiting partner.
We are an equal-opportunity employer and celebrate diversity, recognizing that diversity builds stronger teams. We approach diversity and inclusion seriously and thoughtfully. We do not discriminate on the basis of race, religion, color, ancestry, national origin, caste, sex, sexual orientation, gender, gender identity or expression, age, disability, medical condition, pregnancy, genetic makeup, marital status, or military service.
Job is open for no less than 7 days and will be removed when the position is filled.