×
Register Here to Apply for Jobs or Post Jobs. X

S - Embedded Systems Security Engineer

Job in Foster, Stephens County, Oklahoma, 73434, USA
Listing for: Dorle Controls
Full Time position
Listed on 2026-08-30
Job specializations:
  • IT/Tech
    Unix/Linux, Cybersecurity
Salary/Wage Range or Industry Benchmark: 120000 - 160000 USD Yearly USD 120000.00 160000.00 YEAR
Job Description & How to Apply Below
Position: S 105 - Embedded Systems Security Engineer
Location: Foster

Job Title - Embedded Systems Security Engineer

Location - Onsite in Foster City, CA | 5 days in office

We are looking for an Embedded Systems Security Engineer to implement security solution to harden our next-generation embedded Linux platform. In this role, you will bridge the gap between low-level hardware security, kernel hardening, and secure user-space application containment. You will not only design cryptographic defense mechanisms but will also automate security pipelines in CI/CD and partner directly with manufacturing teams to ensure devices are provisioned securely and reliably at scale without production risks.

Roles & Responsibilities :
  • Platform Hardening & Architecture:
    Design and implement the Hardware Root of Trust and Secure Boot architecture from the first-stage boot loader through the Linux kernel.
  • Storage & Integrity Management:
    Implement dm-verity for cryptographically verified read-only root file systems and secure data encryption at rest.
  • Trusted Execution Environments:
    Develop, integrate, and maintain a TEE (e.g., OP-TEE) and author Secure/Trusted Applications (TAs).
  • Application Sandboxing:
    Enforce strict user-space isolation and sandboxing strategies using SELinux, App Armor, cgroups, name spaces, and seccomp filters to protect core systems from untrusted applications.
  • Dev Sec Ops  Automation:
    Build automated cryptographic signing pipelines within CI/CD infrastructure (e.g., Git Lab CI, Git Hub Actions) to securely sign bootloaders, kernels, and OTA payloads using HSMs or secure key vaults.
  • Production Provisioning Support:
    Collaborate with manufacturing teams to write robust scripts and tools for burning permanent hardware configuration fuses (eFuses / OTP memory) securely, designing end-of-line (EOL) test software to validate security features before shipping.
  • System Resilience:
    Architect multi-slot boot recovery layouts (e.g., A/B partitioning) to guarantee fail-safe resilience against failed OTA updates or corrupted boots.
Qualifications:
  • Education:

    Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical discipline (or equivalent practical experience).
  • Core

    Experience:

    6 years of professional experience in Embedded Linux development, board bring-up, and Board Support Package (BSP) customization.
  • Security Focus: 3 years of dedicated, hands-on experience deploying device-level security features into physical production hardware.
  • Low-Level Systems:
    Expert knowledge of boot loader configurations (e.g., U-Boot Verified Boot, Barebox) and customizing the Linux kernel storage/security subsystem (dm-crypt, dm-verity).
  • Hardware Security Architecture:
    Deep understanding of modern processor security architectures, specifically ARM Trust Zone (ARMv7-A / ARMv8-A, Exception Levels EL1--EL3).
  • Sandboxing & Access Controls:
    Proven track record implementing SELinux/App Armor policies and utilizing standard Linux containment tools (cgroups, name spaces).
  • Build Automation:
    Proficiency with embedded Linux build automated frameworks like the Yocto Project (Bit Bake recipe design) or Buildroot.
  • Programming:
    Advanced proficiency in C and strong scripting skills in Python or Bash.
Preferred Qualifications:
  • Cryptography Expertise:
    Strong foundational knowledge of symmetric/asymmetric cryptography, hashing algorithms (SHA-256/384), public key infrastructure (PKI), and handling physical Hardware Security Modules (HSMs).
  • Manufacturing Scale:
    Prior experience working with Contract Manufacturers (CMs) or internal factory lines to deploy secure key-injection and fuse-burning protocols.
  • Advanced Sandboxing:
    Experience with embedded container runtimes (e.g., LXC, crun) or lightweight sandboxing frameworks tailored for resource-constrained architectures.
  • Anti-Rollback Protection:
    Experience designing secure versioning and hardware-enforced anti-rollback strategies for OTA updates.
#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary