Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
R&D Principal Software Engineer - Security Response Engineering image - Rise Careers
Job details

R&D Principal Software Engineer - Security Response Engineering

Please Note:

1. If you are a first time user, please create your candidate login account before you apply for a job. (Click Sign In > Create Account)

2. If you already have a Candidate Account, please Sign-In before you apply.

Job Description:

R&D Principal Software Engineer - Security Response Engineering The Elevator Pitch: Why will you enjoy this new opportunity?


Broadcom VMware Cloud Foundation (VCF) products and services are trusted by various organizations for their mission critical systems. Many of these systems demand the highest confidentiality and are of extreme interest to nation state actors. The vSECR team within the VCF Division at Broadcom is responsible for defending these products, services and their supply chains.
If helping find and fix security holes in these systems is your idea of a fun career, then you should come join this team. Working alongside other highly motivated and capable security engineers you will get first-hand experience in modern threats, attack, and defense techniques.
Success in the Role: What are the performance outcomes over the first 6-12 months you will work toward completing?


Security Engineers on the team are responsible for triage, investigation, management and communication of security vulnerabilities reported by external researchers. You will be responsible for assessing threats, analyzing externally reported vulnerabilities, supporting teams in providing vulnerability mitigations, virtual patches, workarounds and fix recommendations. You will maintain the highest quality of work while driving programs to completion, prioritizing incoming requests, contending priorities and managing high profile communications. You will work closely with a variety of teams across Broadcom to achieve our goal of protecting our customers. The role will focus on the growth and management of VCF products from a security perspective and will require involvement in the authoring of VMware Security Response Center (vSRC) communications including security advisories, blogs and knowledge base articles.


In the first 6mths, you will be expected to become intimately familiar with VCF products/components assigned to you. You should also be able to reproduce externally reported security issues in those components, engage with external reporters and drive fixes into patch releases, in collaboration with a member of your team. Within 1 year, you are expected to be fairly independent in doing security assessments and driving mitigations/remediation's with product development and release teams, while being proactive with security researcher engagement.
The Work: What type of work will you be doing? What assignments, requirements, or skills will you be performing on a regular basis?


● Oversee all aspects of the security response process from triage to remediation and communication of high profile externally reported vulnerabilities
● Reproduce externally reported vulnerabilities, assess for lateral impact and develop proof of concepts for those vulnerabilities
● Provide tools (Scripts/checklists) for development teams to verify if their products are impacted as well as validate fixes
● Work with tools such as Blackduck, Burp, Nessus, and Coverity for security defect discovery. Be familiar with OSS vulnerability discovery platforms like vulnhub, GHSA, openwall, etc.
● Assess OSS vulnerabilities for potential impact to VCF products
● Proficient in Python and at least one of C/C++ or Java
● Enable models and IOCs for SOC to detect similar families of TTPs
● Make entire kill-chain understandable to an engineering audience
● Partner with different business units across Broadcom to build and support processes to support a high profile response
● Build PSIRT expertise, creating, maintaining and enhancing process and policy documentation
● Define and report program roadmap, status, development issues and success metrics for High Profile process
● Perform RCCA and present on high profile vulnerabilities to executive staff
● Monitor and develop intelligence sources to maintain situational awareness of the cyber threat landscape
● Work with a diverse group of stakeholders from technical to executive level
● Bachelor's degree in Computer Science or related field and 12+ years of related experience or Masters degree in Computer Science or related field and 10+ years of related experience

Additional Job Description:

Compensation and Benefits 

The annual base salary range for this position is $141,000 - $225,000 

 

This position is also eligible for a discretionary annual bonus in accordance with relevant plan documents, and equity in accordance with equity plan documents and equity award agreements. 

 

Broadcom offers a competitive and comprehensive benefits package: Medical, dental and vision plans, 401(K) participation including company matching, Employee Stock Purchase Program (ESPP), Employee Assistance Program (EAP), company paid holidays, paid sick leave and vacation time. The company follows all applicable laws for Paid Family Leave and other leaves of absence. 

Broadcom is proud to be an equal opportunity employer.  We will consider qualified applicants without regard to race, color, creed, religion, sex, sexual orientation, gender identity, national origin, citizenship, disability status, medical condition, pregnancy, protected veteran status or any other characteristic protected by federal, state, or local law.  We will also consider qualified applicants with arrest and conviction records consistent with local law.

If you are located outside USA, please be sure to fill out a home address as this will be used for future correspondence.

Broadcom Glassdoor Company Review
3.7 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Broadcom DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Broadcom
Broadcom CEO photo
Hock E. Tan
Approve of CEO

Average salary estimate

$183000 / YEARLY (est.)
min
max
$141000K
$225000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About R&D Principal Software Engineer - Security Response Engineering, Broadcom

Are you ready to take the next step in your career as an R&D Principal Software Engineer - Security Response Engineering with Broadcom? If diving deep into cybersecurity excites you, you're in the right place! At Broadcom, specifically within our VMware Cloud Foundation (VCF) division, we're dedicated to defending mission-critical products and services that require the highest level of confidentiality. You'll be a key player in our vSECR team, where your responsibilities will include investigating and managing security vulnerabilities reported by external researchers. In this role, you’ll not only assess threats and analyze vulnerabilities but also lead teams as you provide essential vulnerability mitigations and drive communications surrounding high-profile security incidents. Your work will involve close collaboration with various teams, making it crucial to maintain high standards of quality while managing priorities. Throughout your first year, you’ll gain a deep understanding of the VCF products and components, reproduce reported issues, and engage with external security researchers to facilitate fixes. If you're proficient in Python and either C/C++ or Java, and you have a strong grasp of security tools and methodologies, we want you on our team! Add your expertise to our mission of safeguarding our customers and stay ahead of modern threats. You’ll contribute to our dynamic workspace while working on complex challenges in cybersecurity. Join us, and let’s make a difference together!

Frequently Asked Questions (FAQs) for R&D Principal Software Engineer - Security Response Engineering Role at Broadcom
What are the main responsibilities of the R&D Principal Software Engineer - Security Response Engineering at Broadcom?

As an R&D Principal Software Engineer - Security Response Engineering at Broadcom, you will oversee the entire security response process, manage high-profile vulnerabilities, assess threats, and work collaboratively with development teams to implement fixes. This role involves analyzing reported issues, creating proof of concepts for vulnerabilities, and developing tools to aid in the verification of product security.

Join Rise to see the full answer
What qualifications are required for the R&D Principal Software Engineer - Security Response Engineering position at Broadcom?

The ideal candidate for the R&D Principal Software Engineer - Security Response Engineering role at Broadcom should possess a Bachelor's degree in Computer Science or a related field with at least 12 years of experience, or a Master's degree with 10 years of experience. Proficiency in Python and knowledge of C/C++ or Java are also essential, alongside familiarity with tools like Blackduck, Burp, Nessus, and Coverity.

Join Rise to see the full answer
How does the R&D Principal Software Engineer - Security Response Engineering contribute to cybersecurity initiatives at Broadcom?

The R&D Principal Software Engineer - Security Response Engineering at Broadcom plays a pivotal role in enhancing the security posture of VMware Cloud Foundation products. By evaluating vulnerabilities, engaging with external researchers, and implementing mitigation strategies, you will directly contribute to protecting sensitive information and ensuring compliance with security standards.

Join Rise to see the full answer
What skills are crucial for the R&D Principal Software Engineer - Security Response Engineering role at Broadcom?

Key skills for the R&D Principal Software Engineer - Security Response Engineering role at Broadcom include strong analytical capabilities, excellent communication, and collaboration skills, along with a deep understanding of software security principles. Familiarity with vulnerability assessment tools and programming expertise in languages like Python, C/C++, or Java is also vital.

Join Rise to see the full answer
What can I expect in terms of career growth as an R&D Principal Software Engineer - Security Response Engineering at Broadcom?

Career growth as an R&D Principal Software Engineer - Security Response Engineering at Broadcom involves gaining profound expertise in cybersecurity and advancing through increasing responsibilities. You will have opportunities to lead initiatives, mentor junior engineers, and shape security strategies that align with organizational objectives, while also having the chance to present findings to executive stakeholders.

Join Rise to see the full answer
Common Interview Questions for R&D Principal Software Engineer - Security Response Engineering
Can you explain your experience with vulnerability assessment processes?

When answering this question, highlight specific methodologies you have employed in past roles, detailing your approach to triaging, investigating, and communicating vulnerabilities. Mention any tools you've used and any significant outcomes from assessments you conducted.

Join Rise to see the full answer
What programming languages are you proficient in and how have you used them in software security?

Provide examples of projects where you utilized programming languages like Python, C/C++, or Java to enhance security measures or develop security tools. Discuss your coding style and how it ensures production quality.

Join Rise to see the full answer
How do you stay updated with the latest cybersecurity threats and vulnerabilities?

Explain your methods for keeping abreast of the cybersecurity landscape, including following industry blogs, attending conferences, or engaging with security researcher communities. Mention how you incorporate this knowledge into your work.

Join Rise to see the full answer
Describe a time when you successfully mitigated a security threat.

Illustrate a specific scenario where you identified a security threat, implemented a mitigation strategy, and the results that followed. Highlight your problem-solving skills and ability to manage high-pressure situations.

Join Rise to see the full answer
How do you effectively communicate technical information to non-technical stakeholders?

Share examples of how you have tailored your communication strategy for different audiences, ensuring clarity while maintaining technical accuracy. Discuss the importance of collaboration across diverse teams in your work.

Join Rise to see the full answer
Can you elaborate on your experience with OSS vulnerability discovery?

Discuss your familiarity with open-source software (OSS) vulnerabilities and any specific tools or methodologies you have utilized to discover and assess these vulnerabilities in your previous roles.

Join Rise to see the full answer
What strategies do you employ to reproduce security vulnerabilities?

Explain your systematic approach to reproducing vulnerabilities, including methodologies for testing, collaboration with team members, and documenting findings to ensure clarity.

Join Rise to see the full answer
How have you contributed to developing security advisories or knowledge base articles?

Provide examples of your writing and documentation experience in the context of security advisories or knowledge base articles. Describe the importance of these documents in facilitating communication with users and stakeholders.

Join Rise to see the full answer
What is your experience with driving security programs to completion?

Share specific examples of security programs you have led, detailing your contributions to planning, execution, and the outcomes. Highlight your project management skills and ability to meet deadlines.

Join Rise to see the full answer
How do you assess the potential impact of reported vulnerabilities on products?

Discuss your method for evaluating the implications of vulnerabilities on product security, including collaboration with development teams and thorough analysis of reported issues to establish their potential impact.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Broadcom Remote United Kingdom-Remote Location
Posted 2 days ago

Join Broadcom as a Technical Support Engineer to leverage your technical knowledge in a remote setting and drive customer satisfaction.

Photo of the Rise User
Broadcom Remote USA-NH-Portsmouth SO Commerce Way
Posted 2 days ago

Join Broadcom Software as a Site Reliability Engineer to operationalize cloud infrastructure for an innovative SaaS platform.

Photo of the Rise User

Join Workday as a Senior Software Development Engineer to help design cutting-edge automation solutions for our U.S. Federal Government contracts.

Windsurf Hybrid Mountain View
Posted 8 days ago
Photo of the Rise User
PIMCO Hybrid San Diego, California, United States
Posted 14 days ago
Photo of the Rise User
Posted 6 days ago

Alan seeks passionate Senior Software Engineers to help transform healthcare experiences while working remotely.

Photo of the Rise User
Baxter Remote Skaneateles, NY
Posted yesterday

As a Sr. Manager at Baxter, you'll lead the development of cutting-edge medical device software that makes a real difference in patient care.

Photo of the Rise User
NICE Remote Atlanta, Georgia, United States
Posted 8 days ago
Photo of the Rise User
Posted 3 days ago

Join OneIMS as a Developer to transform business processes through AI-driven applications and intelligent agent automation.

Photo of the Rise User
Posted 43 minutes ago

Become part of the dynamic team at Visa as a Full Stack Java Engineer in Bangalore, focusing on innovative software solutions.

Broadcom harbors broad ambitions for its semiconductors' impact on broadband communications: it wants them to drive every part of the high-speed wired and wireless networks of the future. The core applications for its integrated circuits (ICs) are...

44 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
April 4, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!