ALTEN Technology USA logo
ALTEN Technology USA

Embedded Systems Security Engineer

Foster City, USAOn-sitePosted 1 month ago

Apply opens ALTEN Technology USA's site. When you're back, we'll ask whether you applied.

Job type
Full-time
Work mode
On-site
Level
Not listed
Department
Engineering
Experience
6+ years experience
Posted
Aug 12, 2026

About the role

We are looking for an Embedded Systems Security Engineer to implement security solutions to harden our next-generation embedded Linux platform. You will bridge low-level hardware security, kernel hardening, secure user-space application containment, CI/CD security automation, and secure manufacturing provisioning.

Responsibilities

  • Design and implement Hardware Root of Trust and Secure Boot architecture from the first-stage bootloader through the Linux kernel.
  • Implement dm-verity and secure data encryption at rest.
  • Develop, integrate, and maintain a TEE such as OP-TEE and author Secure/Trusted Applications.
  • Enforce user-space isolation using SELinux, AppArmor, cgroups, namespaces, and seccomp.
  • Build automated cryptographic signing pipelines in CI/CD using HSMs or secure key vaults.
  • Collaborate with manufacturing teams on secure fuse programming and end-of-line security testing.
  • Architect multi-slot boot recovery layouts for failed OTA updates or corrupted boots.

Required Qualifications

  • Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical discipline, or equivalent practical experience.
  • 6+ years of professional experience in Embedded Linux development, board bring-up, and BSP customization.
  • 3+ years of hands-on experience deploying device-level security features into production hardware.
  • Expert knowledge of U-Boot Verified Boot or Barebox and Linux storage/security subsystems.
  • Deep understanding of ARM TrustZone and ARMv7-A or ARMv8-A exception levels EL1–EL3.
  • Experience implementing SELinux or AppArmor policies and Linux containment tools.
  • Proficiency with Yocto Project, BitBake, or Buildroot.
  • Advanced proficiency in C and strong Python or Bash scripting skills.

Preferred Qualifications

  • Knowledge of symmetric and asymmetric cryptography, hashing algorithms, PKI, and HSMs.
  • Experience with contract manufacturers or factory lines deploying secure key-injection and fuse-burning protocols.
  • Experience with embedded container runtimes such as LXC or crun.
  • Experience designing hardware-enforced anti-rollback strategies for OTA updates.

Benefits

  • Mentorship, career growth opportunities, and comprehensive benefits.
  • All qualified applicants will receive consideration without discrimination.
  • Selected candidates must successfully complete a pre-employment drug screening.