Embedded Linux Security Engineer: Secure Boot & TEE

ALTEN Technology USA

Foster City (CA)

On-site

USD 120,000 - 150,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

ALTEN Technology USA in Foster City, CA seeks an Embedded Linux Security Engineer to harden our next‑generation embedded platform. You will bridge hardware security, kernel hardening, and secure user‑space containment while collaborating with manufacturing teams to scale secure provisioning.

Responsibilities include designing the Hardware Root of Trust and Secure Boot, implementing dm‑verity and encryption, developing TEEs like OP‑TEE, enforcing SELinux/AppArmor, building DevSecOps pipelines,

Qualifications

  • Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, or related technical discipline (or equivalent practical experience).
  • 6+ years of Embedded Linux development, board bring-up, and BSP customization.
  • 3+ years deploying device-level security features into production hardware.
  • Expert knowledge of bootloaders (U-Boot, Barebox) and Linux kernel storage/security subsystems (dm-crypt, dm-verity).
  • Deep understanding of ARM TrustZone (ARMv7-A/v8-A, EL1–EL3).
  • Experience with SELinux/AppArmor, cgroups, namespaces, and seccomp.
  • Yocto/Buildroot-based build automation; strong C and scripting (Python/Bash).

Responsibilities

  • Platform Hardening & Architecture: Design Hardware Root of Trust and Secure Boot from bootloader through Linux kernel.
  • Storage & Integrity Management: Implement dm-verity and encryption for read-only root filesystems.
  • Trusted Execution Environments: Develop and integrate a TEE (OP-TEE) and Secure Applications.
  • Application Sandboxing: Enforce isolation using SELinux, AppArmor, cgroups, namespaces, and seccomp.
  • DevSecOps Automation: Build automated cryptographic signing pipelines in CI/CD for bootloaders and kernels.
  • Production Provisioning Support: Write scripts for secure eFuses/OTP programming and end-of-line security testing.
  • System Resilience: Design multi-slot boot recovery layouts to guarantee OTA failure resilience.

Skills

Embedded Linux development
Board bring-up
BSP customization
Security features deployment
Bootloader configurations
Linux containment tools
C programming
Python scripting

Education

Bachelor's degree in Computer Science/Engineering

Tools

U-Boot
Barebox
dm-verity
dm-crypt
OP-TEE
Yocto Project
Buildroot

Job description

ALTEN Technology USA in Foster City, CA seeks an Embedded Linux Security Engineer to harden our next‑generation embedded platform. You will bridge hardware security, kernel hardening, and secure user‑space containment while collaborating with manufacturing teams to scale secure provisioning.

Responsibilities include designing the Hardware Root of Trust and Secure Boot, implementing dm‑verity and encryption, developing TEEs like OP‑TEE, enforcing SELinux/AppArmor, building DevSecOps pipelines,

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Embedded Systems Security Engineer - Secure Boot & TEE
Embedded Systems Security Engineer - Secure Boot & TEE

Dorle Controls • Foster (OK)

On-site
USD 120,000 - 160,000
Embedded Linux Security Engineer
Embedded Linux Security Engineer

ALTEN Technology USA • Foster City (CA)

On-site
USD 120,000 - 150,000
S 105 - Embedded Systems Security Engineer
S 105 - Embedded Systems Security Engineer

Dorleco • Foster City (CA)

On-site
USD 140,000 - 210,000
Embedded Systems Security Engineer: Hardware Trust
Embedded Systems Security Engineer: Hardware Trust

Dorleco • Foster City (CA)

On-site
USD 140,000 - 210,000
S 105 - Embedded Systems Security Engineer
S 105 - Embedded Systems Security Engineer

Dorle Controls • Foster (OK)

On-site
USD 120,000 - 160,000
Senior DevSecOps Engineer – Embedded Linux Security
Senior DevSecOps Engineer – Embedded Linux Security

ALTEN Technology USA • Denver (CO)

On-site
USD 125,000 - 150,000
Senior Embedded Security Architect — Remote & OS Hardening
Senior Embedded Security Architect — Remote & OS Hardening

GlobalLogic • Belmont (CA)

On-site
USD 140,000 - 150,000
Exciting projects
Collaborative environment
Work‑life balance
+2
Senior DevSecOps Engineer – Secure Embedded Platform
Senior DevSecOps Engineer – Secure Embedded Platform

Altentechnologyusa • Denver (CO)

Hybrid
USD 125,000 - 150,000
Embedded Security Engineer: Firmware, Hardware & Secure Boot
Embedded Security Engineer: Firmware, Hardware & Secure Boot

Attic Research • Dayton (OH)

On-site
USD 110,000 - 150,000
10% 401k contribution (fully vested on
4 weeks PTO + 11 paid Federal Holidays
100% employer paid healthcare, dental,
+4
Senior Embedded Security Engineer: TrustZone, Secure Boot & Linux
Senior Embedded Security Engineer: TrustZone, Secure Boot & Linux

GlobalLogic • Belmont (CA)

On-site
USD 140,000 - 150,000
Exciting Projects
Collaborative Environment
Work-Life Balance
+2