Embedded Linux Security Engineer (Kernel/Bootloader / Ramdisk)

Accord Technologies Inc

Atlanta (GA)

On-site

USD 100,000 - 135,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading technology firm is seeking an experienced Embedded Linux Security Engineer based in Atlanta, GA. The role focuses on kernel-level CVE remediation, U-Boot bootloader hardening, and firmware development for Xilinx Zynq-based platforms. Candidates should possess strong experience in Linux kernel patching, security vulnerability management, and cross-compilation. A Bachelor's or Master's degree in a relevant field is preferred, along with at least 8 years of embedded Linux development experience. This role offers an opportunity to work on critical security projects in a rewarding environment.

Qualifications

  • 8+ years of experience in Embedded Linux Development.
  • Hands-on experience with Xilinx PetaLinux or Vitis tools.
  • Experience hardening embedded Linux configurations.

Responsibilities

  • Identify and triage CVEs impacting the embedded software stack.
  • Apply kernel patches and backport security fixes.
  • Maintain documentation of vulnerabilities and validation results.

Skills

Linux kernel patching
CVE remediation
Buildroot build systems
U-Boot bootloader configuration
Embedded Linux development (ARM)
Cross-compilation toolchains
Kernel debugging
Vulnerability analysis
C programming
Shell scripting

Education

Bachelor's or Master's degree in Computer Science, Electrical Engineering, Cybersecurity, or a related field

Tools

Git
Buildroot
GDB
JIRA

Job description

Job Title

Embedded Linux Security Engineer (Kernel/Bootloader / Ramdisk)

Location

Atlanta, GA

Position Type

C2C

Experience

8 Years in Embedded Linux Development

Domain

Embedded Linux / Security / Kernel CVE Remediation / Firmware Hardening

Platform

Xilinx Zynq SoC (ARM-based)

Openings

2 Positions

Role

We are seeking a highly skilled Embedded Linux Security Engineer with deep expertise in kernel-level CVE remediation, U-Boot bootloader hardening, and Buildroot-based firmware development. This role is critical to ensuring the security and resilience of our Xilinx Zynq-based hardware platform running Linux kernels, U-Boot bootloaders, and Buildroot-generated ramdisk images. The ideal candidate will be responsible for identifying, analyzing, triaging, and patching security vulnerabilities (CVE-based) across the entire embedded software stack — from the Linux kernel and bootloader through to user‑space applications, libraries, and services. This is a hands‑on, technically demanding role requiring expertise in kernel patching, cross‑compilation toolchains, secure boot mechanisms, and embedded system hardening.

Key Responsibilities
  • Vulnerability Assessment & CVE Remediation
  • Identify, analyze, and triage CVEs impacting the Xilinx Linux kernel, ramdisk packages, U-Boot, and embedded software stack using NVD, AMD/Xilinx Security Bulletins, and OSS tooling.
  • Apply kernel patches, backport security fixes from upstream LTS kernels (e.g., 5.x LTS, Xilinx downstream), or implement mitigation workarounds.
  • Patch vulnerabilities in U-Boot, kernel modules, device drivers, and user‑space packages (BusyBox, OpenSSL, etc.) — primarily focused on version upgrades and CVE-specific patches.
  • Maintain detailed documentation of vulnerabilities, root cause analysis, mitigation steps, patch sources, and validation results.
  • Track and report CVE remediation progress to stakeholders and external auditors.
  • Buildroot-Based Embedded Linux System Maintenance
  • Configure, customize, and maintain the Buildroot build environment used to compile U-Boot, Linux kernel, and ramdisk/root filesystem images.
  • Ensure secure configuration of Buildroot-generated packages, system services, and network daemons.
  • Optimize build configurations for minimal attack surface and reduced package footprint.
  • Manage cross-compilation toolchains, package dependencies, and library versions.
  • Secure Boot & Firmware Hardening
  • Implement and validate secure boot mechanisms on Zynq platforms using Xilinx PetaLinux / Vitis toolchain.
  • Harden the Linux OS, kernel configuration (kconfig), and boot chain against common attack vectors.
  • Implement kernel module signing and enforce boot chain integrity.
Required Skills & Experience
Core Technical Skills
  • Strong hands‑on experience with Linux kernel patching, including CVE remediation, patch backporting, and diff/patch workflows.
  • Deep knowledge of Buildroot build systems — package configuration, filesystem generation, and toolchain management.
  • Expertise in U-Boot bootloader configuration, customization, secure boot implementation, and boot chain hardening.
  • Proficiency in Embedded Linux development for ARM platforms, specifically Xilinx Zynq or similar SoCs.
  • Familiarity with Xilinx‑specific kernel and bootloader repositories; experience with PetaLinux or Vitis toolchain is a strong plus.
  • Solid understanding of cross‑compilation toolchains (gcc-arm, Buildroot toolchain, Yocto SDK).
  • Kernel debugging skills using JTAG, GDB, kernel logs, and tracing tools.
  • Knowledge of the target Linux kernel version family (Xilinx downstream / LTS 5.x or later).
Security & Vulnerability Management Skills
  • Proven experience in CVE analysis, CVSS scoring, vulnerability triage, and remediation prioritization.
  • Familiarity with vulnerability databases and tools: NVD, AMD/Xilinx Security Bulletins, Trivy, or similar.
  • Knowledge of secure boot mechanisms and kernel module signing.
  • Experience hardening embedded Linux OS configurations.
Programming & Scripting Skills
  • Proficiency in C for kernel module development, patching, low‑level debugging, and userspace‑kernel interaction.
  • Shell scripting (Bash) for build automation and patch workflows.
Tools & Technologies
  • Version control: Git, GitHub workflows, patch management.
  • Build systems: Buildroot, Make, CMake, Yocto (familiarity).
  • Debugging & analysis: GDB, JTAG debuggers, strace, valgrind.
  • Documentation & tracking: Confluence, JIRA.
  • Security tooling: NVD, CodeSonar, CodeSentry
Preferred Qualifications
  • Bachelor's or Master's degree in Computer Science, Electrical Engineering, Cybersecurity, or a related field.
  • 5+ years of professional experience in Embedded Linux development with a security focus.
  • Hands‑on experience with Xilinx PetaLinux or Vitis tools on Zynq-7000 or Zynq UltraScale+ platforms.
  • Experience with Yocto Project as an alternative embedded Linux build system.
  • Proficiency in C for kernel module development, patching, low‑level debugging, and userspace‑kernel interaction.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Embedded Linux Security Engineer - Kernel & Bootloader
Embedded Linux Security Engineer - Kernel & Bootloader

Accord Technologies Inc • Atlanta (GA)

On-site
USD 100,000 - 135,000
Embedded Linux (Xilinx MPSoC Platforms)
Embedded Linux (Xilinx MPSoC Platforms)

Swirl DSP • Los Altos (CA)

On-site
USD 120,000 - 190,000
Staff Firmware Engineer - Core Compute
Staff Firmware Engineer - Core Compute

Contract Professionals, Inc • Sterling Heights (MI)

On-site
USD 120,000 - 170,000
Embedded Software Engineer
Embedded Software Engineer

6AM City, LLC • Town of Florida (NY)

On-site
USD 90,000 - 120,000
Senior Software Engineer (Embedded Linux)
Senior Software Engineer (Embedded Linux)

Delaney Group • United States

Remote
USD 100,000 - 130,000
Senior Engineer - Linux Kernel
Senior Engineer - Linux Kernel

ALTEN • Austin (TX)

Remote
USD 100,000 - 130,000
Embedded Software Engineer (Hybrid- Aberdeen, Maryland)
Embedded Software Engineer (Hybrid- Aberdeen, Maryland)

Fairwinds Technologies • United States

Hybrid
USD 120,000 - 190,000
Embedded Software Engineer - Security
Embedded Software Engineer - Security

Ambiq • Austin (TX)

On-site
USD 80,000 - 120,000
Embedded Systems Security Engineer
Embedded Systems Security Engineer

DeWinter Group • Foster City (CA)

On-site
USD 120,000 - 160,000
Senior Embedded Development Engineer
Senior Embedded Development Engineer

Intrepid Control Systems • Troy (MI)

On-site
USD 110,000 - 130,000
401(k) matching
Medical
Dental
+4