Senior Software Security Engineer (Linux Appliances)

Total Integrated Resources Pte Ltd

Taguig

Hybrid

PHP 1,800,000 - 2,400,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Total Integrated Resources Pte Ltd is seeking a Senior Security Architect to own the security architecture of appliance platforms, including trusted boot, disk encryption, and hardware-backed key management. You will strengthen OS hardening, build pipelines, and attestation mechanisms while supporting media streaming stack integration.

Ideal candidates bring 5+ years in security-focused Linux environments, extensive cryptography experience, and hands-on TPM 2.0 and UEFI Secure Boot exposure.

Qualifications

  • 5+ years in security-focused systems engineering on Linux.
  • UEFI Secure Boot: key hierarchy, image signing; TPM 2.0 concepts.
  • Disk encryption in production: LUKS2, cryptsetup, TPM binding.
  • Linux hardening: AppArmor/SELinux, kernel lockdown, IMA/EVM, audit frameworks.
  • Applied cryptography: signatures, AES-GCM, verification chains.
  • Threat modeling and secure design review experience.

Responsibilities

  • Design and maintain appliance trust architecture and signing workflows.
  • Work with TPM 2.0 in production: PCR policies, sealing, attestation.
  • Harden the Linux platform end to end: lockdown, IMA, AppArmor, auditd.
  • Own the secure build pipeline: signed OS image assembly and reproducibility.
  • Implement cryptography workflows: RSA-PSS, OAEP, AES-GCM.
  • Build verification infra: QEMU/OVMF/tests and failure-safe gates.
  • Contribute to threat modeling and architectural invariants.
  • Develop and debug media streaming stack as product needs.
  • Write operator-grade tooling (bash, Python, C) and runbooks.

Skills

Security architecture
Linux security
Threat modeling
Cryptography basics
Scripting: Bash/Python

Tools

QEMU
OVMF
swTPM
GStreamer
FFmpeg

Job description

About the role

You will own the security architecture and secure-platform engineering of appliance products: the trusted boot chain, disk and payload encryption, hardware-backed key management, attestation, OS hardening, and the build and provisioning systems that produce tamper-resistant units. The role also involves work on media streaming stack and its integration with third-party platforms, but the center of gravity is software security — designing, implementing, and defending the mechanisms that keep devices and intellectual property protected in hostile environments.

Key responsibilities
  • Design and maintain the appliance trust architecture: UEFI Secure Boot key hierarchy and signing workflows, measured boot, and TPM-anchored secrets

  • Work with TPM 2.0 in production: key creation and attributes, PCR measurement and policy, sealed storage, remote attestation (quotes, verification chains), and LUKS/Clevis disk-encryption binding

  • Harden the Linux platform end to end: kernel configuration and lockdown, IMA appraisal policy, AppArmor confinement, sysctl and module-blacklist hardening, auditd, and systemd sandboxing

  • Own the secure build pipeline: hardened kernel builds, signed OS image assembly, reproducibility practices, and cryptographic verification at every stage

  • Implement applied-cryptography workflows correctly: signature schemes (RSA-PSS, OAEP), authenticated encryption (AES-GCM), canonical serialization for signed documents, key ceremonies, and key-compromise response

  • Build verification infrastructure: QEMU/OVMF/swTPM-based boot testing, self-tests with negative controls, and fail-closed validation gates

  • Contribute to threat modeling: define adversaries and trust boundaries, document what is in and out of scope, and defend architectural invariants through written decision records

  • Develop and debug within media streaming stack (RTSP, ONVIF, media pipelines) as product work requires

  • Write operator-grade tooling (bash, Python, C) and the runbooks that go with it

Required Experience
Software and Platform Security (Core of the Role):
  • 5+ years in security-focused systems engineering on Linux;

  • UEFI Secure Boot: key hierarchy (PK/KEK/db), image signing, enrollment workflows;

  • TPM 2.0 hands-on experience: key attributes, PCR policies, sealing, attestation concepts (EK, AK, quotes);

  • Disk encryption in production: LUKS2, cryptsetup, TPM binding (Clevis or equivalent);

  • Linux hardening: mandatory access control (AppArmor or SELinux), kernel lockdown, IMA/EVM or comparable integrity mechanisms, audit frameworks;

  • Applied cryptography: correct use of asymmetric signatures, authenticated encryption, and verification chains (able to implement, review, and spot misuse); not expected to design primitives;

  • Threat modeling and secure design review experience.

Linux Systems Engineering
  • Deep Linux internals: boot process (UEFI → bootloader → kernel → init), systemd, udev, initramfs;

  • Building custom Linux images or distributions; kernel build and configuration;

  • Expert-level bash and strong Python; C proficiency for systems work;

  • A quality bar of idempotent, fail-loud, self-tested tooling.

Streaming and Integration (Working Knowledge):
  • Familiarity with video streaming protocols (RTSP/RTP) and device-integration standards such as ONVIF;

  • Exposure to media frameworks (GStreamer, FFmpeg, or equivalent) and debugging protocol-level issues with packet captures;

  • Codec-agnostic: we care about sound engineering, not any specific video format.

Nice to Have
  • Anti-tamper and reverse-engineering-resistance techniques: encrypted payloads, secure loaders, self-integrity checks;

  • Experience with air-gapped or no-update-channel deployment models and the operational discipline they require;

  • Secure provisioning at scale or in manufacturing contexts; per-unit key management;

  • Reproducible builds; supply-chain security awareness;

  • VMS/NVR platform integration experience;

  • Performance engineering: profiling, optimization of systems or media code;

  • Singapore work eligibility.

How We Work
  • Small team, high trust, high ownership;

  • Architecture decisions are written down; invariants are documented and changes go through review;

  • Quality and paper trail matter: our units ship to security-critical deployments where compromise response is measured in recalled hardware, not hotfixes.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Linux Security Engineer - Trusted Appliance Platforms
Senior Linux Security Engineer - Trusted Appliance Platforms

Total Integrated Resources Pte Ltd • Taguig

Hybrid
PHP 1,800,000 - 2,400,000
Platform Security Engineer
Platform Security Engineer

Causa Prima • España

On-site
PHP 3,075,031 - 4,612,546
Embedded SDE - Security, Silicon & Systems Group
Embedded SDE - Security, Silicon & Systems Group

Amazon • Hinoba-an

On-site
PHP 1,339,000 - 2,455,000
Product Security Engineer
Product Security Engineer

GoMining • España

On-site
USD 120,000 - 180,000
Professional growth support
Remote or hybrid format
Flexible hours
+2
Information Security Analyst
Information Security Analyst

Satellite Office • Pasig

On-site
PHP 1,000,000 - 2,000,000
Product Security Engineer – Build Secure, Scalable Cloud
Product Security Engineer – Build Secure, Scalable Cloud

GoMining • España

On-site
USD 120,000 - 180,000
Professional growth support
Remote or hybrid format
Flexible hours
+2
Application Security Engineer (OWASP, SAST, DAST, SCA)
Application Security Engineer (OWASP, SAST, DAST, SCA)

Comrise • Taguig

On-site
PHP 1,200,000 - 2,400,000
Security Engineer
Security Engineer

Azeus Systems Limited • Pasig

On-site
PHP 558,000 - 781,200
Security Engineer - Offensive Security
Security Engineer - Offensive Security

Thrive • Quezon City

On-site
PHP 600,000 - 1,000,000
Permanent WFH: Security Developer - Full Stack
Permanent WFH: Security Developer - Full Stack

Nowcom Global Services, LLC • Pasig

On-site
PHP 900,000 - 1,800,000
Permanent Work From Home
Full-Time Positions
Competitive Salary
+9