About this opportunity
Engg lists this Senior Software Engineer (Android VMs) opportunity in bellevue, Washington. Review the employer’s description below for duties, qualifications and application requirements.
Job description
About the Team
Connected Warfare (CW): The Connected Warfare simulaivision builds systems to support global command and control missions. We create joint, time sensitive, multi domain, ubiquitous, connected mesh ecosystems. Our ecosystem enables connected warfare with disproportional impact by connecting every mac robot, human, and sensor in every domain, bringing together hundreds of thousands of end points across the globe. We are the substrate that provides the source of truth for time sensitive decision, effectively transforming the way that militaries close kills chains and enable mission autonomy.
Warfighter Systems (WS)
Warfighter Systems brings cutting-edge technology directly to those on the front lines. Wearable tech, immersive mission command tools, and seamlessly integrated software and hardware create an ecosystem that enhances situational awareness, survivability, and combat effectiveness. From training to battlefield operations, Anduril’s Warfighter Systems organization designs tools that move at the speed of war, ensuring that soldiers are better connected, more lethal, and more resilient.
About the Job
We're looking for a Senior Software Engineer to design, implement, and harden Android VMs running on crosvm and contribute to our platform security work. You'll work across the virtualization stack, from the VMM and guest kernel to secure boot and the platform security features that anchor them, to deliver production-quality, security-hardened Android VMs. You'll own hard problems end to end, collaborate with platform and security teams, and set the technical direction for how we run Android securely in a virtual machine.
What You’ll Do
Design, build, and maintain Android VMs running on crosvm, including VMM configuration, device models (virtio), and guest/host integration
Bring up and boot Android guest images inside a VM: kernel, bootloader, init, and Android framework layers
Harden the virtualization boundary: reduce attack surface, sandbox device backends, and reason about guest-to-host and host-to-guest threat models
Implement and validate secure boot and chain-of-trust for the VM (measured/verified boot, key management, rollback protection)
Analyze and mitigate Android VM security issues; contribute to threat modeling, security reviews, and vulnerability remediation
Debug across the stack — hypervisor/VMM, guest kernel, and Android userspace — using the appropriate tooling for each layer
Collaborate with platform, kernel, and security teams to isolate and resolve issues that span hardware, firmware, and software
Document architecture, security properties, trust boundaries, and design decisions
Required Qualifications
Strong systems programming in C/C++ and Rust, including low-level work with memory safety, concurrency, and performance under real constraints
Hands-on experience with crosvm (or a comparable VMM such as QEMU/rust-vmm/Firecracker): device models, virtio, VM lifecycle, and VMM configuration
Solid understanding of virtualization and hardware-assisted virtualization (KVM, guest/host memory management, vCPUs, MMIO/IOMMU, virtio transport)
Android VM security knowledge: guest/host isolation, sandboxing of VMM/device backends, and the guest-to-host attack surface
Android platform security fundamentals: SELinux/sandboxing, verified boot (AVB/dm-verity), keystore/KeyMint, and the Android trust model
Secure boot and chain-of-trust: measured vs. verified boot, signing and key management, rollback protection, and root-of-trust concepts
Comfortable working from specifications, kernel/driver source, and register-level documentation
Ability to debug low-level systems issues (kernel logs, ftrace/perf, gdb, VMM tracing/logging) across host and guest
Git proficiency
Eligibility: Must be eligible to obtain and maintain a U.S. Security Clearance
Preferred Qualifications
Experience with Android Virtualization Framework (AVF), pVM/protected VMs, or microdroid
Guest and host Linux kernel development: drivers, virtio backends/frontends, and kernel debugging
TEE / TrustZone experience and integration with a hardware root of trust
Bootloader work in the Android ecosystem (U-Boot, ABL, or equivalent) and secure boot bring-up
Cryptographic key provisioning, attestation, and lifecycle management for VMs and devices
Familiarity with fuzzing, sandboxing frameworks (seccomp/minijail), and hardening techniques for VMMs
CI for systems/kernel builds and automated VM image testing
Nice to have Qualcomm platform security experience: Secure Boot, QFPROM/eFuses, TrustZone/QTEE, and the Qualcomm secure boot chain (PBL/SBL/XBL)
Experience bringing up Qualcomm platform security from scratch: fuse provisioning, signing infrastructure, and enabling secure boot on new silicon or a new board
Familiarity with SoC-level root-of-trust, secure debug/authenticated debug, and anti-rollback on Qualcomm platforms
Contributions to AOSP, crosvm, rust-vmm, or the upstream Linux kernel
Experience with Android CTS/VTS or comparable platform compliance and validation
US Salary Range $191,000 - $253,000 USD The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experienc
#J-18808-Ljbffr
Worksite address
bellevue, WA, 98009, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.