Embedded Systems Security Engineer
Core
Design and implement security solutions for next-generation embedded Linux platforms, bridging low-level hardware security, kernel hardening, and secure user-space application containment.
Role type
Senior IC embedded systems security engineer
Builds
Secure embedded Linux devices with hardware root of trust, secure boot, TEEs, and automated cryptographic signing pipelines
Domain
Embedded systems, cybersecurity, Linux kernel, hardware security
Deliverable
production ML models | product features
Required skills
Embedded Linux development, bootloader configuration (U-Boot, Barebox), Linux kernel security subsystems (dm-crypt, dm-verity), ARM TrustZone architecture, SELinux/AppArmor policies, embedded build automation (Yocto, Buildroot), C programming, Python/Bash scripting
Preferred skills
Cryptography (PKI, HSMs), manufacturing scale key injection, embedded container runtimes, anti-rollback protection design
Technologies
Linux, ARMv7-A/ARMv8-A, OP-TEE, GitLab CI, GitHub Actions, dm-verity, SELinux, AppArmor, cgroups, namespaces, seccomp, Yocto Project, Buildroot, HSM
Responsibilities
Design and implement Hardware Root of Trust and Secure Boot architecture; Implement dm-verity for verified root filesystems and data encryption; Develop and maintain TEEs and Secure Applications; Enforce user-space isolation using SELinux, AppArmor, cgroups, and seccomp; Build automated cryptographic signing pipelines in CI/CD; Collaborate with manufacturing to secure hardware provisioning and EOL testing; Architect multi-slot boot recovery layouts for system resilience
Seniority
Senior, hands-on IC
