- Job type
- Full-time
- Work mode
- On-site
- Level
- Not listed
- Department
- Engineering
- Experience
- 6+ years experience
- Posted
- Aug 12, 2026
About the role
We are looking for an Embedded Systems Security Engineer to implement security solutions to harden our next-generation embedded Linux platform. You will bridge low-level hardware security, kernel hardening, secure user-space application containment, CI/CD security automation, and secure manufacturing provisioning.
Responsibilities
- Design and implement Hardware Root of Trust and Secure Boot architecture from the first-stage bootloader through the Linux kernel.
- Implement dm-verity and secure data encryption at rest.
- Develop, integrate, and maintain a TEE such as OP-TEE and author Secure/Trusted Applications.
- Enforce user-space isolation using SELinux, AppArmor, cgroups, namespaces, and seccomp.
- Build automated cryptographic signing pipelines in CI/CD using HSMs or secure key vaults.
- Collaborate with manufacturing teams on secure fuse programming and end-of-line security testing.
- Architect multi-slot boot recovery layouts for failed OTA updates or corrupted boots.
Required Qualifications
- Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical discipline, or equivalent practical experience.
- 6+ years of professional experience in Embedded Linux development, board bring-up, and BSP customization.
- 3+ years of hands-on experience deploying device-level security features into production hardware.
- Expert knowledge of U-Boot Verified Boot or Barebox and Linux storage/security subsystems.
- Deep understanding of ARM TrustZone and ARMv7-A or ARMv8-A exception levels EL1–EL3.
- Experience implementing SELinux or AppArmor policies and Linux containment tools.
- Proficiency with Yocto Project, BitBake, or Buildroot.
- Advanced proficiency in C and strong Python or Bash scripting skills.
Preferred Qualifications
- Knowledge of symmetric and asymmetric cryptography, hashing algorithms, PKI, and HSMs.
- Experience with contract manufacturers or factory lines deploying secure key-injection and fuse-burning protocols.
- Experience with embedded container runtimes such as LXC or crun.
- Experience designing hardware-enforced anti-rollback strategies for OTA updates.
Benefits
- Mentorship, career growth opportunities, and comprehensive benefits.
- All qualified applicants will receive consideration without discrimination.
- Selected candidates must successfully complete a pre-employment drug screening.