About the job
Snap Inc is a technology company. We believe the camera presents the greatest opportunity to improve the way people live and communicate. Snap contributes to human progress by empowering people to express themselves, live in the moment, learn about the world, and have fun together. The Company operates Snapchat, a visual messaging app that enhances your relationships with friends, family, and the world, and Specs Inc., a wholly-owned subsidiary dedicated to making computing more human, in addition to Bitmoji, Saturn, and other digital services. Specs Inc. is a wholly-owned subsidiary of Snap Inc. dedicated to making computing more human. The company develops Specs, advanced eyewear that seamlessly integrates digital experiences into the physical world. Specs feature see-through lenses that place digital objects directly into three-dimensional space, powered by Snap OS, a proprietary, context-aware operating system designed for natural interaction with your hands and voice. Specs Inc. also provides Lens Studio, a full suite of advanced developer tools that powers immersive augmented reality experiences across Specs, Snapchat, and other services. We’re looking for a Security Engineer to join the Specs Security team at Snap Inc!
Responsibilities
Design, build, and harden on-device security systems for Specs, including permissions, access control, secure IPC, sandboxing, and trusted execution boundaries.
Develop security and privacy controls for on-device AI features, including model integrity, sensitive data handling, inference-time privacy protections, local policy enforcement, and secure access to sensors, user data, and system capabilities.
Research, design, and implement security features that improve the security posture of Specs across Snap OS, firmware, applications, system services, and cloud-connected device surfaces.
Improve fuzzing infrastructure, automated security testing, and continuous validation pipelines for OS components, IPC mechanisms, parsers, services, drivers, firmware interfaces, and AI-related data flows.
Qualifications
Minimum
Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, a related technical field, or equivalent practical experience.
5+ years of experience developing production software in one or more programming languages such as C, C++, Rust.
3+ years of experience building security, privacy, or platform protection features for Linux-based, embedded, mobile, wearable, or connected device systems.
Experience with applied cryptography, authentication, authorization, secure communications, key management, threat modeling, vulnerability assessment, or system security for embedded or Linux-based systems.
Preferred
Master’s degree or PhD in Computer Science, Computer Engineering, Electrical Engineering, or a related technical discipline.
Experience designing or building on-device permission systems, access control frameworks, sandboxing, secure IPC, service isolation, least-privilege architectures, or privacy-preserving controls for sensor-rich devices.
Experience securing on-device AI, ML, or assistant-like systems, including model integrity, sensitive data handling, inference-time privacy, AI feature permissions, local policy enforcement, and protection of model inputs and outputs.
Experience with trusted execution technologies, secure manufacturing, device provisioning, attestation, anti-rollback, secure debug, lifecycle state management, fuzzing, automated security validation, or platform-level vulnerability hardening for Linux-based systems.