Embedded SDE - Security, Silicon & Systems Group
Technology, Data & Digital · Software & Web Development · Embedded Systems · Software Engineering
In short
Amazon's Silicon & Systems Group is hiring an Embedded Software Development Engineer II to focus on content protection and DRM. You will design, implement, and ship critical security software, including industry DRM systems and HDCP, on embedded Arm platforms. This role involves working with trusted applications, cryptographic keys, and collaborating with cross-functional teams to ensure secure content playback.
Responsibilities
- Design, implement, test, and maintain DRM and content-protection software (Widevine, PlayReady, FairPlay, HDCP 1.x/2.x Tx & Rx) in C/C++ for embedded Arm platforms.
- Develop trusted applications and secure-world components for a TrustZone/OP-TEE TEE, including applied cryptography (AES, RSA, ECC, SHA) and secure key handling.
- Implement and validate secure device key provisioning and factory/development provisioning flows.
- Integrate DRM stacks with the media pipeline and certify content playback with streaming partners (e.g., Prime Video, Netflix, YouTube).
- Debug complex, cross-layer issues spanning firmware, kernel drivers, TEE, and user space; analyze and resolve performance and security defects.
- Participate in security architecture reviews, threat modeling, code reviews, and compliance & robustness certification.
- Write clear design documents and contribute to team engineering standards.
Requirements
- 5+ years of embedded firmware development experience
- Experience programming with at least one software programming language, or experience in embedded development in C/C++
- Bachelor's degree or above in computer science, electrical engineering, or related field
- Experience with Arm SoC bring-up, secure boot, or security co-processor firmware.
- Hands-on experience with TrustZone, OP-TEE, or another Trusted Execution Environment and trusted-application development.
- Experience with embedded Linux and low-level software (drivers, firmware, or system services).
- Experience debugging complex issues across firmware, kernel, and user space using tools such as JTAG, gdb, or trace/logging.
Desired Qualifications
- 5+ years of full software development life cycle, including coding standards, code reviews, source control management, build processes, testing, and operations experience
- Experience with content protection / DRM (Widevine, PlayReady, FairPlay) or HDCP.
- Experience developing or integrating trusted applications (TAs) and secure/non-secure world communication.
- Familiarity with secure key provisioning, or hardware root-of-trust and secure boot chains (e.g., DICE, attestation).
- Applied cryptography experience (AES, RSA, ECC, hashing, secure key management).
- Familiarity with the Yocto build system and multimedia/streaming pipelines.
Benefits
- Inclusive culture empowers Amazonians to deliver the best results for our customers.
- Workplace accommodation and adjustment during the application and hiring process.
#Embedded Systems#Security#SoC#DRM#Content Protection