26 Aug
|
Advanced Micro Devices (AMD)
|
Bengaluru
26 Aug
Advanced Micro Devices (AMD)
Bengaluru
Job Summary
SDE/MTS Software System Design Engineer
The right engineer will drive the success of power IP (intellectual property) and features in AMD (Advanced Micro Devices) products through leadership & coordination, resolution of technical dependencies, and achievement of schedule commits. This is a high-visibility and widely multi-functional role, spanning pre-silicon architecture to post-silicon implementation & product delivery.
The Person
Your curiosity will drive your learning and innovation to improve how we as a group and an organisation can get better every day. Your peers will provide you a results-orientated and encouraging environment for your career growth, fuelling your opportunity to be a part of Delighting Our Customers.
Key Responsibilities
- Conduct black-box and grey-box security assessments across web applications, REST APIs, single-page applications (SPAs), browser-based management consoles, and thick-client/desktop applications, including Windows-based management utilities, agents, and configuration tools.
- Test modern web attack surfaces, including authentication and session management, access control (IDOR/BOLA), CORS, SSRF, injection vulnerabilities, and LLM/AI-assisted features (e.g., prompt injection, sensitive data disclosure).
- Evaluate thick-client applications for insecure IPC, local privilege escalation, DLL hijacking, insecure storage of credentials and configuration data, unsafe deserialisation, and client-server trust boundary weaknesses.
- Perform static and dynamic analysis of Windows drivers (KMDF/WDM), firmware interfaces, and IOCTL attack surfaces.
- Identify and document vulnerabilities such as broken access control, injection flaws, sensitive information disclosure, privilege escalation, memory corruption, arbitrary kernel write, and insecure IOCTLs.
- Develop proof-of-concept (PoC)
exploits - ranging from HTTP request chains and API abuse scripts to thick-client exploitation chains and kernel-level triggers - to validate findings and demonstrate their severity.
- Build custom tooling and automation scripts (Python, PowerShell, C/C++) to accelerate reconnaissance, fuzzing, IOCTL enumeration, and repeatable exploit validation across engagements.
- Contribute to internal threat models and security architecture reviews for new product features.
- Stay current on emerging CVEs, web/API exploitation techniques (OWASP Top 10, OWASP API Top 10, OWASP LLM Top 10), publicly disclosed driver exploits, and other attack trends relevant to AMD products.
Preferred Experience
- 3-10 years of experience in application or product security, with substantial hands-on assessment work.
- Solid foundation in web application security, including the OWASP Top 10, API security testing, authentication/authorisation bypass, injection, insecure deserialisation, and misconfigurations (CORS, security headers, exposed documentation or endpoints).
- End-to-end experience assessing REST APIs, web management interfaces, and thick-client/desktop applications-from reconnaissance and manual testing through reporting.
- Solid scripting and automation skills (Python, PowerShell, or C/C++) for building custom test harnesses, PoC exploits, and repeatable assessment tooling, going beyond reliance on off-the-shelf tools like Burp Suite or Nmap.
- Familiarity with Windows internals, including the driver model, kernel/user boundary, privilege levels, and IOCTL handling.
- Experience developing and reviewing threat models.
- Working knowledge of digital certificates, symmetric and asymmetric encryption, authentication, and authorisation concepts.
- Experience with security-related hardware such as ARM TrustZone is a plus.
Academic Credentials
- Bachelor s or masters degree in computer or electrical engineering or equivalent
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Security Vulnerability Testing/Assessment Engineer (Bengaluru)
🏢 Advanced Micro Devices (AMD)
📍 Bengaluru