Senior Software Security Engineer

oneberry technologies pte. ltd.

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Oneberry Technologies Pte. Ltd.

in Singapore seeks a Security Architect to own the appliance security architecture and secure-platform engineering for our devices and IP. You will design, implement, and defend the trusted boot chain, disk encryption, and hardware-backed key management while building tamper-resistant units.

Qualifications

  • 5+ years in security-focused systems engineering on Linux.

Responsibilities

  • Design and maintain the appliance trust architecture: UEFI Secure Boot key hierarchy and signing workflows, measured boot, and TPM-anchored secrets
  • Work with TPM 2.0 in production: key creation and attributes, PCR measurement and policy, sealed storage, remote attestation(quotes, verification chains), and LUKS/Clevis disk-encryption binding
  • Harden the Linux platform end to end: kernel configuration and lockdown, IMA appraisal policy, AppArmor confinement, sysctl and module-blacklist hardening, auditd, and systemd sandboxing
  • Own the secure build pipeline: hardened kernel builds, signed OS image assembly, reproducibility practices, and cryptographic verification at every stage
  • Implement applied-cryptography work flows correctly: signature schemes (RSA-PSS, OAEP), authenticated encryption(AES-GCM), canonical serialization for signed documents, key ceremonies, and key-compromise response
  • Build verification in frastructure: QEMU/OVMF/swTPM-based boot testing, self-tests with negative controls, andfail-closed validation gates
  • Contribute to threat modeling: define adversaries and trust boundaries, document what is in and out of scope, and defend architectural invariants through written decision records
  • Develop and debug within our media streaming stack (RTSP, ONVIF, media pipelines) as product work requires
  • Write operator-grade tooling (bash, Python, C)and the runbooks that go with it

Skills

UEFI Secure Boot
TPM 2.0
Linux hardening
LUKS2 encryption
Threat modeling
Security architecture
Python
C
Kernel development
Build pipeline

Tools

GStreamer
FFmpeg
QEMU

Job description

The Role

You will own the security architecture and secure-platform engineering of our appliance products: the trusted boot chain, disk and payload encryption, hardware-backed key management, attestation, OS hardening, and the build and provisioning systems that produce tamper-resistant units. The role also involves work on our media streaming stack and its integration with third-party platforms, but the center of gravity is software security — designing, implementing, and defending the mechanisms that keep our devices and our intellectual property protected in hostile environments.

What You Will Do
  • Design and maintain the appliance trust architecture: UEFI Secure Boot key hierarchy and signing workflows, measured boot, and TPM-anchored secrets
  • Work with TPM 2.0 in production: key creation and attributes, PCR measurement and policy, sealed storage, remote attestation(quotes, verification chains), and LUKS/Clevis disk-encryption binding
  • Harden the Linux platform end to end: kernel configuration and lockdown, IMA appraisal policy, AppArmor confinement, sysctl and module-blacklist hardening, auditd, and systemd sandboxing
  • Own the secure build pipeline: hardened kernel builds, signed OS image assembly, reproducibility practices, and cryptographic verification at every stage
  • Implement applied-cryptography work flows correctly: signature schemes (RSA-PSS, OAEP), authenticated encryption(AES-GCM), canonical serialization for signed documents, key ceremonies, and key-compromise response
  • Build verification in frastructure: QEMU/OVMF/swTPM-based boot testing, self-tests with negative controls, andfail-closed validation gates
  • Contribute to threat modeling: define adversaries and trust boundaries, document what is in and out of scope, and defend architectural invariants through written decision records
  • Develop and debug within our media streaming stack (RTSP, ONVIF, media pipelines) as product work requires
  • Write operator-grade tooling (bash, Python, C)and the runbooks that go with it
Required Experience
Software and platform security (core of the role):
  • 5+ years in security-focused systems engineering on Linux
  • UEFI Secure Boot: key hierarchy (PK/KEK/db),image signing, enrollment workflows
  • TPM 2.0 hands-on experience: key attributes, PCR policies, sealing, attestation concepts (EK, AK, quotes)
  • Disk encryption in production: LUKS2,cryptsetup, TPM binding (Clevis or equivalent)
  • Linux hardening: mandatory access control(AppArmor or SELinux), kernel lockdown, IMA/EVM or comparable integrity mechanisms, audit frameworks
  • Applied cryptography: correct use of asymmetric signatures, authenticated encryption, and verification chains — able to implement, review, and spot misuse; not expected to design primitives
  • Threat modeling and secure design review experience
Linux systems engineering:
  • Deep Linux internals: boot process (UEFI →bootloader → kernel → init), systemd, udev, initramfs
  • Building custom Linux images or distributions; kernel build and configuration
  • Expert-level bash and strong Python; Cproficiency for systems work
  • A quality bar of idempotent, fail-loud, self-tested tooling
Streaming and integration (working knowledge):
  • Familiarity with video streaming protocols(RTSP/RTP) and device-integration standards such as ONVIF
  • Exposure to media frameworks (GStreamer, FFmpeg, or equivalent) and debugging protocol-level issues with packet captures
  • Codec-agnostic: we care about sound engineering, not any specific video format
Nice to Have
  • Anti-tamper and reverse-engineering-resistance techniques: encrypted payloads, secure loaders, self-integrity checks
  • Experience with air-gapped orno-update-channel deployment models and the operational discipline they require
  • Secure provisioning at scale or in manufacturing contexts; per-unit key management
  • Reproducible builds; supply-chain security awareness
  • VMS/NVR platform integration experience
  • Performance engineering: profiling, optimization of systems or media code
  • Singapore work eligibility
How We Work
  • Small team, high trust, high ownership
  • Architecture decisions are written down; invariants are documented and changes go through review
  • Quality and paper trail matter: our units ship to security-critical deployments where compromise response is measured in recalled hardware, not hotfixes
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior/Software Developer (AMK)
Senior/Software Developer (AMK)

United States Digital Space LLC • Singapore

On-site
SGD 90,000 - 150,000
Senior/Software Developer (AMK)
Senior/Software Developer (AMK)

MAESTRO HUMAN RESOURCE PTE. LTD. • Singapore

On-site
SGD 90,000 - 120,000
Staff Product Security Engineer
Staff Product Security Engineer

Airwallex • Singapore

On-site
SGD 120,000 - 180,000
Software Engineer * Go/NodeJS/Python/Rust. (AMK)
Software Engineer * Go/NodeJS/Python/Rust. (AMK)

MAESTRO HUMAN RESOURCE PTE. LTD. • Singapore

On-site
SGD 90,000 - 160,000
Senior Security Engineer
Senior Security Engineer

Webot • Singapore

On-site
SGD 120,000 - 180,000
Software Engineer, Security Server Applications
Software Engineer, Security Server Applications

United States Digital Space LLC • Singapore

On-site
SGD 60,000 - 90,000
Security Engineer
Security Engineer

Simular • Singapore

On-site
SGD 80,000 - 120,000
Security Engineer
Security Engineer

Simular Inc. • Singapore

On-site
SGD 80,000 - 120,000
Security Full Stack Engineer
Security Full Stack Engineer

R Systems Singapore Pte Ltd • Singapore

On-site
SGD 120,000 - 180,000
Principal/Lead Cybersecurity Specialist
Principal/Lead Cybersecurity Specialist

CAPGEMINI SINGAPORE PTE. LTD. • Singapore

Hybrid
SGD 180,000 - 260,000