Stand out for this role — generate a tailored resume and cover letter in about a minute.
Total Integrated Resources Pte Ltd is seeking a Senior Security Architect to own the security architecture of appliance platforms, including trusted boot, disk encryption, and hardware-backed key management. You will strengthen OS hardening, build pipelines, and attestation mechanisms while supporting media streaming stack integration.
Ideal candidates bring 5+ years in security-focused Linux environments, extensive cryptography experience, and hands-on TPM 2.0 and UEFI Secure Boot exposure.
You will own the security architecture and secure-platform engineering of appliance products: the trusted boot chain, disk and payload encryption, hardware-backed key management, attestation, OS hardening, and the build and provisioning systems that produce tamper-resistant units. The role also involves work on media streaming stack and its integration with third-party platforms, but the center of gravity is software security — designing, implementing, and defending the mechanisms that keep devices and intellectual property protected in hostile environments.
Design and maintain the appliance trust architecture: UEFI Secure Boot key hierarchy and signing workflows, measured boot, and TPM-anchored secrets
Work with TPM 2.0 in production: key creation and attributes, PCR measurement and policy, sealed storage, remote attestation (quotes, verification chains), and LUKS/Clevis disk-encryption binding
Harden the Linux platform end to end: kernel configuration and lockdown, IMA appraisal policy, AppArmor confinement, sysctl and module-blacklist hardening, auditd, and systemd sandboxing
Own the secure build pipeline: hardened kernel builds, signed OS image assembly, reproducibility practices, and cryptographic verification at every stage
Implement applied-cryptography workflows correctly: signature schemes (RSA-PSS, OAEP), authenticated encryption (AES-GCM), canonical serialization for signed documents, key ceremonies, and key-compromise response
Build verification infrastructure: QEMU/OVMF/swTPM-based boot testing, self-tests with negative controls, and fail-closed validation gates
Contribute to threat modeling: define adversaries and trust boundaries, document what is in and out of scope, and defend architectural invariants through written decision records
Develop and debug within media streaming stack (RTSP, ONVIF, media pipelines) as product work requires
Write operator-grade tooling (bash, Python, C) and the runbooks that go with it
5+ years in security-focused systems engineering on Linux;
UEFI Secure Boot: key hierarchy (PK/KEK/db), image signing, enrollment workflows;
TPM 2.0 hands-on experience: key attributes, PCR policies, sealing, attestation concepts (EK, AK, quotes);
Disk encryption in production: LUKS2, cryptsetup, TPM binding (Clevis or equivalent);
Linux hardening: mandatory access control (AppArmor or SELinux), kernel lockdown, IMA/EVM or comparable integrity mechanisms, audit frameworks;
Applied cryptography: correct use of asymmetric signatures, authenticated encryption, and verification chains (able to implement, review, and spot misuse); not expected to design primitives;
Threat modeling and secure design review experience.
Deep Linux internals: boot process (UEFI → bootloader → kernel → init), systemd, udev, initramfs;
Building custom Linux images or distributions; kernel build and configuration;
Expert-level bash and strong Python; C proficiency for systems work;
A quality bar of idempotent, fail-loud, self-tested tooling.
Familiarity with video streaming protocols (RTSP/RTP) and device-integration standards such as ONVIF;
Exposure to media frameworks (GStreamer, FFmpeg, or equivalent) and debugging protocol-level issues with packet captures;
Codec-agnostic: we care about sound engineering, not any specific video format.
Anti-tamper and reverse-engineering-resistance techniques: encrypted payloads, secure loaders, self-integrity checks;
Experience with air-gapped or no-update-channel deployment models and the operational discipline they require;
Secure provisioning at scale or in manufacturing contexts; per-unit key management;
Reproducible builds; supply-chain security awareness;
VMS/NVR platform integration experience;
Performance engineering: profiling, optimization of systems or media code;
Singapore work eligibility.
Small team, high trust, high ownership;
Architecture decisions are written down; invariants are documented and changes go through review;
Quality and paper trail matter: our units ship to security-critical deployments where compromise response is measured in recalled hardware, not hotfixes.