Embedded Linux Security Engineer

ALTEN Technology USA

Foster City (CA)

On-site

USD 120,000 - 150,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

ALTEN Technology USA in Foster City, CA seeks an Embedded Linux Security Engineer to harden our next‑generation embedded platform. You will bridge hardware security, kernel hardening, and secure user‑space containment while collaborating with manufacturing teams to scale secure provisioning.

Responsibilities include designing the Hardware Root of Trust and Secure Boot, implementing dm‑verity and encryption, developing TEEs like OP‑TEE, enforcing SELinux/AppArmor, building DevSecOps pipelines,

Qualifications

  • Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, or related technical discipline (or equivalent practical experience).
  • 6+ years of Embedded Linux development, board bring-up, and BSP customization.
  • 3+ years deploying device-level security features into production hardware.
  • Expert knowledge of bootloaders (U-Boot, Barebox) and Linux kernel storage/security subsystems (dm-crypt, dm-verity).
  • Deep understanding of ARM TrustZone (ARMv7-A/v8-A, EL1–EL3).
  • Experience with SELinux/AppArmor, cgroups, namespaces, and seccomp.
  • Yocto/Buildroot-based build automation; strong C and scripting (Python/Bash).

Responsibilities

  • Platform Hardening & Architecture: Design Hardware Root of Trust and Secure Boot from bootloader through Linux kernel.
  • Storage & Integrity Management: Implement dm-verity and encryption for read-only root filesystems.
  • Trusted Execution Environments: Develop and integrate a TEE (OP-TEE) and Secure Applications.
  • Application Sandboxing: Enforce isolation using SELinux, AppArmor, cgroups, namespaces, and seccomp.
  • DevSecOps Automation: Build automated cryptographic signing pipelines in CI/CD for bootloaders and kernels.
  • Production Provisioning Support: Write scripts for secure eFuses/OTP programming and end-of-line security testing.
  • System Resilience: Design multi-slot boot recovery layouts to guarantee OTA failure resilience.

Skills

Embedded Linux development
Board bring-up
BSP customization
Security features deployment
Bootloader configurations
Linux containment tools
C programming
Python scripting

Education

Bachelor's degree in Computer Science/Engineering

Tools

U-Boot
Barebox
dm-verity
dm-crypt
OP-TEE
Yocto Project
Buildroot

Job description

We’re ALTEN Technology USA, an engineering company helping clients bring groundbreaking ideas to life—from advancing space exploration and life‑saving medical devices to building autonomous electric vehicles. With 3,000+ experts across North America, we partner with leading companies in aerospace, medical devices, robotics, automotive, commercial vehicles, EVs, rail, and more.

As part of the global ALTEN Group—57,000+ engineers in 30 countries—we deliver across the entire product development cycle, from consulting to full project outsourcing.

When you join ALTEN Technology USA, you’ll collaborate on some of the world’s toughest engineering challenges, supported by mentorship, career growth opportunities, and comprehensive benefits. We take pride in fostering a culture where employees feel valued, supported, and inspired to grow.

Workplace: On-Site, 5 days
Location: Foster City, CA

We are looking for an Embedded Linux Security Engineer to implement security solution to harden our next-generation embedded Linux platform. In this role, you will bridge the gap between low-level hardware security, kernel hardening, and secure user-space application containment. You will not only design cryptographic defense mechanisms but will also automate security pipelines in CI/CD and partner directly with manufacturing teams to ensure devices are provisioned securely and reliably at scale without production risks.

Responsibilities
  • Platform Hardening & Architecture: Design and implement the Hardware Root of Trust and Secure Boot architecture from the first-stage bootloader through the Linux kernel.
  • Storage & Integrity Management: Implement dm-verity for cryptographically verified read-only root filesystems and secure data encryption at rest.
  • Trusted Execution Environments: Develop, integrate, and maintain a TEE (e.g., OP-TEE) and author Secure/Trusted Applications (TAs).
  • Application Sandboxing: Enforce strict user-space isolation and sandboxing strategies using SELinux, AppArmor, cgroups, namespaces, and seccomp filters to protect core systems from untrusted applications.
  • DevSecOps Automation: Build automated cryptographic signing pipelines within CI/CD infrastructure (e.g., GitLab CI, GitHub Actions) to securely sign bootloaders, kernels, and OTA payloads using HSMs or secure key vaults.
  • Production Provisioning Support: Collaborate with manufacturing teams to write robust scripts and tools for burning permanent hardware configuration fuses (eFuses / OTP memory) securely, designing end-of-line (EOL) test software to validate security features before shipping.
  • System Resilience: Architect multi-slot boot recovery layouts (e.g., A/B partitioning) to guarantee fail-safe resilience against failed OTA updates or corrupted boots.
Required Qualifications
  • Education: Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical discipline (or equivalent practical experience).
  • Core Experience: 6+ years of professional experience in Embedded Linux development, board bring-up, and Board Support Package (BSP) customization.
  • Security Focus: 3+ years of dedicated, hands‑on experience deploying device-level security features into physical production hardware.
  • Low‑Level Systems: Expert knowledge of bootloader configurations (e.g., U‑Boot Verified Boot, Barebox) and customizing the Linux kernel storage/security subsystem (dm‑crypt, dm‑verity).
  • Hardware Security Architecture: Deep understanding of modern processor security architectures, specifically ARM TrustZone (ARMv7‑A / ARMv8‑A, Exception Levels EL1–EL3).
  • Sandboxing & Access Controls: Proven track record implementing SELinux/AppArmor policies and utilizing standard Linux containment tools (cgroups, namespaces).
  • Build Automation: Proficiency with embedded Linux build automated frameworks like the Yocto Project (BitBake recipe design) or Buildroot.
  • Programming: Advanced proficiency in C and strong scripting skills in Python or Bash.
Preferred Qualifications
  • Cryptography Expertise: Strong foundational knowledge of symmetric/asymmetric cryptography, hashing algorithms (SHA‑256/384), public key infrastructure (PKI), and handling physical Hardware Security Modules (HSMs).
  • Manufacturing Scale: Prior experience working with Contract Manufacturers (CMs) or internal factory lines to deploy secure key‑injection and fuse‑burning protocols.
  • Advanced Sandboxing: Experience with embedded container runtimes (e.g., LXC, crun) or lightweight sandboxing frameworks tailored for resource‑constrained architectures.
  • Anti‑Rollback Protection: Experience designing secure versioning and hardware‑enforced anti‑rollback strategies for OTA updates.
Salary Range
  • $120,000 - 150,000
  • The actual salary offered is dependent on various factors including, but not limited to, location, the candidate’s combination of job‑related knowledge, qualifications, skills, education, training, and experience

All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, age, genetic information, or pregnancy.

Compliance Notice: Alten USA is a federal contractor subject to the requirements of the Vietnam Era Veterans’ Readjustment Assistance Act (VEVRAA) and Executive Order 11246. We are an Equal Opportunity Employer and consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

Drug Screening Requirement: As a federal contractor, Alten USA maintains a drug‑free workplace. All candidates selected for employment will be required to successfully complete a pre‑employment drug screening as a condition of hire.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Software Cybersecurity Engineer
Principal Software Cybersecurity Engineer

ALTEN Technology USA • Denver (CO)

On-site
USD 150,000 - 235,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

ALTEN Technology USA • Denver (CO)

On-site
USD 125,000 - 150,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

altentechnologyusa • Denver (CO)

On-site
USD 125,000 - 150,000
Embedded Software Engineer III
Embedded Software Engineer III

ALTEN Technology USA • Cleveland (OH)

On-site
USD 90,000 - 130,000
Embedded System Software Engineer
Embedded System Software Engineer

ALTEN Technology USA • Bartlesville (OK)

On-site
USD 110,000 - 150,000
Embedded Software Engineer - Qualcomm SoC / BSP & Hardware Bring-Up
Embedded Software Engineer - Qualcomm SoC / BSP & Hardware Bring-Up

Altentechnologyusa • Auburn Hills (MI)

On-site
USD 110,000 - 150,000
R &D Embedded Software Engineer
R &D Embedded Software Engineer

ALTEN Technology USA • Bartlesville (OK)

On-site
USD 85,000 - 120,000
Comprehensive benefits
Mentorship program
Career growth opportunities
S 105 - Embedded Systems Security Engineer
S 105 - Embedded Systems Security Engineer

Dorleco • Foster City (CA)

On-site
USD 140,000 - 210,000
S 105 - Embedded Systems Security Engineer
S 105 - Embedded Systems Security Engineer

Dorle Controls • Foster (OK)

On-site
USD 120,000 - 160,000
Embedded Linux Security Engineer: Secure Boot & TEE
Embedded Linux Security Engineer: Secure Boot & TEE

ALTEN Technology USA • Foster City (CA)

On-site
USD 120,000 - 150,000