Senior Embedded Platform Security Engineer

L4B Software

Pune District

On-site

INR 1,800,000 - 3,200,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

L4B Software in Pune seeks a senior, hands-on Embedded Platform Security Engineer with strong experience securing Linux and Android platforms at system level.

You will design and implement security architectures across bootloaders, secure boot, kernel security, TEE and device integrity, then collaborate with BSP, validation and quality teams to turn security requirements into working, verifiable implementations.

Qualifications

  • Strong hands-on experience securing Embedded Linux products or platforms.
  • Hands-on Linux security at kernel, BSP and system level.
  • Experience with Android/AOSP platform security, not just app security.
  • Understanding of embedded boot flows from hardware root of trust to userspace.

Responsibilities

  • Design, implement and review security architecture for Embedded Linux and Android/AOSP platforms.
  • Integrate secure boot and chain-of-trust mechanisms from early boot through bootloader, kernel and OS.
  • Implement and maintain storage and filesystem-security mechanisms (dm-crypt, dm-verity, fs-verity, LUKS).
  • Integrate TEEs and hardware-backed security (ARM TrustZone, OP-TEE).
  • Work with secure key provisioning, secure storage, and cryptographic services.
  • Implement Android platform-security mechanisms (Verified Boot, KeyMint/Keymaster, SELinux).
  • Analyze interactions between bootloader, kernel, Device Tree, BSP, security firmware and TEE.

Skills

Embedded Linux security
Kernel security
Android/AOSP security
Bootloader security
Trusted Execution Environments
Secure storage/cryptography
C/C++
Root of trust analysis

Job description

About L4B Software

L4B Software develops secure, reliable operating-system platforms for embedded, regulated and mission-critical products. Our engineers work close to the operating system and hardware, where security, reliability and long-term maintainability matter.

About the role

We are looking for a senior, hands-on Embedded Platform Security Engineer with strong experience securing Linux and Android platforms at system level. This is an engineering and integration role, not primarily a governance, compliance or application-security position.

You will work across the platform security chain, including bootloaders, secure and verified boot, kernel security, trusted execution environments, encrypted storage, filesystem integrity, hardware-backed key management, secure storage and Android platform security. You should be comfortable investigating problems across BSP, bootloader, kernel, Device Tree, TEE, native services and userspace boundaries.

This role is for an engineer who can turn platform-security architecture into a working embedded implementation, and debug it when the layers do not behave as expected.

What you will do
  • Design, implement and review security architecture for Embedded Linux and Android/AOSP platforms.
  • Integrate and troubleshoot secure boot and chain-of-trust mechanisms from early boot through bootloader, kernel and operating system.
  • Implement and maintain storage and filesystem-security mechanisms such as dm-crypt, dm-verity, fs-verity, LUKS, encrypted partitions and authenticated system images.
  • Integrate Trusted Execution Environments and hardware-backed security mechanisms, including ARM TrustZone, OP-TEE or equivalent vendor technologies.
  • Work with secure key provisioning, hardware-backed key storage, secure storage, RPMB, cryptographic accelerators and root-of-trust mechanisms.
  • Implement and troubleshoot Android platform-security mechanisms such as Android Verified Boot, file-based encryption, KeyMint/Keymaster, hardware-backed keystores, SELinux, rollback protection and device-integrity mechanisms.
  • Analyze interactions between bootloader, Linux kernel, Device Tree, BSP components, security firmware, TEE and operating-system security services.
  • Debug low-level security integration issues using boot logs, kernel traces, source-code analysis and SoC/platform documentation.
  • Review Linux kernel and userspace configurations for security weaknesses, hardening opportunities and unnecessary attack surface.
  • Apply Linux security mechanisms such as capabilities, namespaces, seccomp, SELinux, AppArmor and other Linux Security Modules where appropriate.
  • Support vulnerability investigation, CVE triage and remediation at kernel, BSP, system-library and platform level.
  • Support SBOM, SCA, static analysis, fuzzing and security-verification activities.
  • Perform threat modeling and translate identified threats into concrete technical controls and verification criteria.
  • Work closely with platform, software, validation and quality teams to turn security requirements into implementation, tests and evidence.
What you bring
Must have
  • Strong professional experience developing, integrating or securing Embedded Linux products or platforms.
  • Strong hands-on Linux security experience at kernel, BSP and system level.
  • Hands-on Android/AOSP platform-security experience, not only Android application security.
  • Strong understanding of embedded boot flows from hardware root of trust and bootloader through kernel and userspace.
  • Practical experience implementing or debugging secure boot, verified boot or comparable chain-of-trust mechanisms.
  • Hands-on experience with dm-crypt, dm-verity or equivalent Linux storage and integrity technologies.
  • Experience with ARM TrustZone, OP-TEE or another Trusted Execution Environment.
  • Understanding of hardware-backed key management, secure storage and cryptographic services.
  • Experience working with ARM-based embedded SoCs and vendor-specific platform-security mechanisms.
  • Strong Embedded Linux build-system knowledge, ideally Yocto Project, OpenEmbedded and BitBake.
  • Strong C/C++ understanding and the ability to investigate platform-security issues at source-code level.
  • Ability to work across bootloader, kernel, BSP, Device Tree, TEE and userspace boundaries.
  • Experience with vulnerability analysis and remediation of low-level platform components.
  • Ability to read SoC, security and platform documentation and translate it into working implementations.
  • Strong debugging and root-cause-analysis skills.
Product-security engineering

You should understand how low-level platform implementation connects to broader product-security activities. Experience with threat modeling, attack-surface analysis, vulnerability management, CVE remediation, SBOM/SCA, security requirements, security verification and secure-development lifecycle activities is important.

Experience applying IEC 62443, IEC 81001-5-1 or a comparable product-cybersecurity standard is valuable, particularly when engineering controls must be translated into requirements, tests and evidence.

Nice to have
  • Experience securing multiple ARM-based SoC families or vendor BSPs.
  • Deep Android BSP or AOSP platform-development experience.
  • BSP bring-up and Device Tree experience.
  • Linux kernel configuration, hardening or debugging experience.
  • U-Boot or UEFI development experience.
  • TPM 2.0, secure elements or device-identity provisioning.
  • OTA and secure firmware-update architecture.
  • PKI, certificates and manufacturing/device provisioning flows.
  • Static analysis, fuzzing or penetration-testing experience.
  • IEC 62443, IEC 81001-5-1, IEC 62304 or comparable standards experience.
  • Experience with regulated, safety-critical, mission-critical or long-lifecycle products.
What this role is not
  • Not primarily an Android application-development role focused on Kotlin, Java or application-layer features.
  • Not primarily a GRC, audit or cybersecurity-compliance position.
  • Not a pure vulnerability-management or SOC role.
  • You do not need to spend your time writing device drivers, but you must be technically comfortable going deep enough into the BSP, kernel, bootloader and hardware-security architecture to resolve platform-security integration problems.

The successful candidate can move confidently between Linux, Android, bootloader, kernel, TEE and SoC security mechanisms and turn security architecture into a secure, testable and maintainable embedded platform.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Android Security Engineer (CoreOS: BSP/Security)
Android Security Engineer (CoreOS: BSP/Security)

Pi Square Technologies • Bengaluru

On-site
INR 2,800,000 - 4,000,000
Android Platform Engineer - India - Pune
Android Platform Engineer - India - Pune

L4B Software • Pune District

On-site
INR 350,000 - 550,000
AOSP Platform Engineer - India - Pune
AOSP Platform Engineer - India - Pune

L4B Software • Pune District

On-site
INR 3,500,000 - 6,000,000
Senior Platform Security Engineer
Senior Platform Security Engineer

Vyntrapro Innovations • Bengaluru

On-site
INR 1,200,000 - 1,600,000
Principal software engineer
Principal software engineer

NXP Semiconductors • Dadri

On-site
INR 5,000,000 - 7,000,000
Sr Staff SW Engineer - OS
Sr Staff SW Engineer - OS

Gigamon • Chennai District

On-site
INR 2,500,000 - 4,200,000
Embedded Linux Firmware Developer
Embedded Linux Firmware Developer

Axisindia • India

On-site
INR 850,000 - 1,200,000
Security Android Engineer (AOSP) | Bangalore
Security Android Engineer (AOSP) | Bangalore

JobCubby • Bengaluru

On-site
INR 1,800,000 - 3,200,000
All corporate Benefits
Embedded Linux Engineer
Embedded Linux Engineer

Kairos Technologies • Bengaluru

On-site
INR 1,200,000 - 1,600,000
Security Android Engineer (AOSP) | Bangalore
Security Android Engineer (AOSP) | Bangalore

Erbity • Bengaluru

On-site
INR 2,800,000 - 4,800,000
All corporate Benefits