Embedded SDE - Security, Silicon & Systems Group

Amazon· Software Development
Apply Now ↗
📍 Bengaluru, Karnataka, INDfull time
Software Developmentalexa-and-amazon-devices

About this role

Amazon's Silicon & Systems Group builds the custom Arm-based SoCs and low-level software that power Fire TV and Amazon's streaming media and smart-TV devices. We are looking for a Software Development Engineer II to join our Content Protection & DRM team.

In this role you will design, implement, and ship the security-critical software that protects premium content on our devices — including industry DRM systems (Widevine, PlayReady, FairPlay) and HDCP link protection (Transmit and Receive). You will write trusted-application (TA) and secure-world code running in a TrustZone/OP-TEE Trusted Execution Environment, integrate cryptographic key provisioning, and work closely with silicon, multimedia, and streaming-partner teams to take features from architecture to certified production.
This is a hands-on engineering role with high ownership. Your code runs at the lowest, most security-sensitive layers of the stack, and directly enables customers to watch the content they love in the highest available quality.

Key job responsibilities
- Design, implement, test, and maintain DRM and content-protection software (Widevine, PlayReady, FairPlay, HDCP 1.x/2.x Tx & Rx) in C/C++ for embedded Arm platforms.
- Develop trusted applications and secure-world components for a TrustZone/OP-TEE TEE, including applied cryptography (AES, RSA, ECC, SHA) and secure key handling.
- Implement and validate secure device key provisioning and factory/development provisioning flows.
- Integrate DRM stacks with the media pipeline and certify content playback with streaming partners (e.g., Prime Video, Netflix, YouTube).
- Debug complex, cross-layer issues spanning firmware, kernel drivers, TEE, and user space; analyze and resolve performance and security defects.
- Participate in security architecture reviews, threat modeling, code reviews, and compliance & robustness certification.
- Write clear design documents and contribute to team engineering standards.

A day in the life
You might start your day integrating a new version of a DRM library into the secure-world TA, then debug a decrypt failure that only appears under memory pressure on a specific device. In the afternoon you review a teammate's HDCP key-provisioning change, sync with the multimedia team on a playback certification blocker, and update the design doc for an upcoming SoC bring-up. You are trusted to own your components end to end, and you have direct access to hardware, senior engineers, and the partners who define the standards you implement.

About the team
The DRM team owns the full premium-content security stack across Amazon's device SoCs — DRM (Widevine/PlayReady/FairPlay), HDCP, and the secure video path built on OP-TEE. We are a small, high-ownership team of embedded and security engineers who take features from silicon bring-up to certified production, and we partner closely with the streaming apps that customers use every day.

Basic qualifications

- 5+ years of embedded firmware development experience
- Experience programming with at least one software programming language, or experience in embedded development in C/C++
- Bachelor's degree or above in computer science, electrical engineering, or related field
- Experience with Arm SoC bring-up, secure boot, or security co-processor firmware.
- Hands-on experience with TrustZone, OP-TEE, or another Trusted Execution Environment and trusted-application development.
- Experience with embedded Linux and low-level software (drivers, firmware, or system services).
- Experience debugging complex issues across firmware, kernel, and user space using tools such as JTAG, gdb, or trace/logging.

Preferred qualifications

- 5+ years of full software development life cycle, including coding standards, code reviews, source control management, build processes, testing, and operations experience
- Experience with content protection / DRM (Widevine, PlayReady, FairPlay) or HDCP.
- Experience developing or integrating trusted applications (TAs) and secure/non-secure world communication.
- Familiarity with secure key provisioning, or hardware root-of-trust and secure boot chains (e.g., DICE, attestation).
- Applied cryptography experience (AES, RSA, ECC, hashing, secure key management).
- Familiarity with the Yocto build system and multimedia/streaming pipelines.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Frequently Asked Questions

Is the salary disclosed for the Embedded SDE - Security, Silicon & Systems Group position at Amazon?
The salary for this Embedded SDE - Security, Silicon & Systems Group role at Amazon is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Embedded SDE - Security, Silicon & Systems Group position at Amazon located?
This Embedded SDE - Security, Silicon & Systems Group role at Amazon is based in Bengaluru, Karnataka, IND. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Embedded SDE - Security, Silicon & Systems Group role at Amazon full-time or part-time?
This is listed as a full time position. It is posted as a Embedded SDE - Security, Silicon & Systems Group role in the Software Development department at Amazon.
Which team or department does the Embedded SDE - Security, Silicon & Systems Group at Amazon belong to?
This Embedded SDE - Security, Silicon & Systems Group position is part of the Software Development department at Amazon. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Embedded SDE - Security, Silicon & Systems Group position at Amazon?
Click the "Apply Now" button on this page. You will be redirected to Amazon's official application portal hosted on amazonjobs where you can submit your application directly.
When was the Embedded SDE - Security, Silicon & Systems Group job at Amazon posted?
This Embedded SDE - Security, Silicon & Systems Group position at Amazon was posted on Aug 20, 2026. Apply as soon as possible — early applications are often reviewed first.
Embedded SDE - Security, Silicon & Systems Group
Amazon
Apply for this role ↗

You'll be redirected to Amazon's official application page on amazonjobs.