Principal Security Architect
Quick Summary
About Graphcore Graphcore is a global leader in artificial intelligence computing systems. We design advanced semiconductors, software,
Graphcore is a global leader in artificial intelligence computing systems. We design advanced semiconductors, software, and data center infrastructure that provide the specialized processing power needed to advance AI while improving the efficiency required for broad adoption.
As part of SoftBank Group, Graphcore belongs to a family of companies developing progressive technologies. Our teams bring together AI researchers, silicon designers, software engineers, and systems architects to solve sophisticated technical problems across the computing stack.
As Principal Security Architect, you will define and lead the end-to-end hardware and firmware security strategy for Graphcore's next-generation AI server systems powered by Arm technology. You will establish security architecture across the system, from the system-on-chip and management controllers through firmware, virtualization, and container environments.
Working within Advanced Architecture, you will protect AI models, training data, inference workloads, and platform intellectual property against remote, physical, and supply-chain threats. You will set technical direction, translate threat models into engineering requirements, and guide teams in delivering hardware-backed isolation, verified boot, secure lifecycle management, and attestation.
Responsibilities
~3 min read- →Define the hardware and firmware security architecture for Arm-based AI server platforms and maintain a coherent security model across silicon, boards, firmware, virtualization, and system software.
- →Lead the build and integration of Arm's secure computing framework and Realm Management Extension technologies to protect AI models and data in use from operating systems, hypervisors, and other tenants.
- →Define platform, Baseboard Management Controller, and Rack Management Controller trust anchors, including secure boot, secure firmware update, device identity, provisioning, cryptographic key management, and lifecycle controls.
- →Specify security requirements for high-speed interfaces and interconnects, including PCIe Gen5 and Gen6 and NVMe Storage Integrity and Data Encryption, to protect data moving among CPUs, AI accelerators, storage, and memory.
- →Lead system-level threat modeling and define mitigations for side-channel attacks, fault injection, privilege escalation, physical tampering, and supply-chain risks.
- →Guide the design and hardening of UEFI, Arm Trusted Firmware, OpenBMC, and related low-level software, including device authentication based on the Security Protocol and Data Model.
- →Architect runtime audit, measurement, and remote attestation frameworks that provide verifiable evidence of platform identity, configuration, and software state.
- →Translate security goals into clear engineering specifications, design requirements, assurance criteria, and review processes for hardware and software teams.
- →Partner with silicon, hardware, firmware, networking, and systems teams to resolve security tradeoffs, review designs, and incorporate security requirements into technology roadmaps.
- →Evaluate emerging threats, standards, and technologies, and represent Graphcore's technical requirements in relevant open-source and industry communities where appropriate.
- →An advanced degree or equivalent experience in computer science, computer engineering, cryptography, cybersecurity, or a related technical field, or equivalent practical experience.
- →Extensive experience in hardware security, system-on-chip security, platform architecture, or a closely related field, including technical leadership at Principal, Staff, or Lead Architect scope.
- →Deep knowledge of Arm architecture and security technologies, including Armv9, TrustZone, Confidential Compute Architecture, and the Realm Management Extension feature.
- →Demonstrated experience in crafting server or platform security frameworks that use trusted platform modules, roots of trust, hardware cryptography, secure provisioning, and lifecycle management.
- →Strong understanding of how hardware security primitives interact with firmware and system software, including Linux kernel internals, KVM, containers, and trusted execution environments.
- →Expert knowledge of hardware and platform threats, physical attack methods, side-channel risks, fault injection, and supply-chain vulnerabilities.
- →Experience with secure boot, firmware update security, cryptographic key management, device identity, attestation, and audit design.
- →Ability to convert complex security concepts and threat analyses into precise, testable engineering requirements and architecture decisions.
- →Proven track record to lead multi-functional technical work and influence senior engineers and leaders without direct authority.
- →Clear written and verbal communication skills, including the ability to explain risk, tradeoffs, and recommended controls to technical and executive audiences.
Requirements
~1 min readThese qualifications are helpful, not required. We encourage you to apply even if you do not meet every preferred qualification.
- Experience designing security architectures that protect machine learning weights, intellectual property, and datasets during distributed training and inference.
- Participation in or contributions to security standards and industry groups such as the Trusted Computing Group, Open Compute Project Security Project, Linux Foundation, Confidential Computing Consortium, or Arm security working groups.
- Knowledge of SmartNIC security and the use of network devices to enforce network or storage isolation within server systems.
- Understanding of post-quantum cryptography and its implications for hardware lifecycle, trusted startup processes, firmware, and silicon build.
- Experience applying emerging confidential-computing technologies to AI training or inference use cases.
What We Offer
~1 min readGraphcore offers competitive compensation and benefits designed to support employees' health, financial well-being, work-life needs, and professional growth. Benefits and programs for eligible U.S. employees may include:
Graphcore is an equal opportunity employer. We consider qualified applicants without regard to race, color, religion, creed, sex, pregnancy, sexual orientation, gender identity or expression, national origin, ancestry, age, disability, genetic information, veteran status, or any other status protected by applicable law.
Graphcore is committed to an inclusive and accessible hiring process. If you need a reasonable accommodation to participate in the application or interview process, please let the recruiting team know.
Personal information submitted during the recruiting process will be handled in accordance with Graphcore's applicable candidate privacy notices.
Location & Eligibility
Listing Details
- Posted
- October 7, 2026
- First seen
- October 7, 2026
- Last seen
- October 7, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 67%
- Scored at
- October 7, 2026
Signal breakdown
Graphcore makes the Intelligence Processing Unit
View company profile4 other jobs at
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.
