Remote Embedded Security Architect: Secure Boot & TEEs

BairesDev

United States

Remote

MXN 2,037,000 - 3,055,000

Full time

29 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Remote work
Flexible hours
Remote setup
Competitive compensation

Job summary

BairesDev is seeking an Embedded Security Engineer to architect Secure Boot and a hardware root of trust across the boot chain, from bootloader to kernel, and to harden storage with dm-verity/dm-crypt. You will build a Trusted Execution Environment, enable sandboxing, automate signing in CI/CD, and apply OP-TEE, TrustZone, and Yocto workflows on embedded Linux hardware.

Join a fully remote, flexible team and contribute to foundational security for connected devices while collaborating with

Qualifications

  • 5+ years of experience in embedded systems engineering with a security focus.
  • Strong expertise in embedded Linux security, including dm-verity, dm-crypt, and ARM TrustZone EL1-EL3.
  • Proven experience designing hardware root of trust and Secure Boot from scratch, including U-Boot Verified Boot from bootloader through kernel.
  • Experience with embedded Linux board bring-up and BSP customization using Yocto.
  • Background with TEE development and trusted application authoring using OP-TEE.
  • Strong C skills with Python or Bash scripting.
  • Advanced proficiency in English.

Responsibilities

  • Architect and implement Secure Boot from bootloader through kernel, building a hardware root of trust from scratch.
  • Harden storage using dm-verity and dm-crypt.
  • Stand up a Trusted Execution Environment and author trusted applications.
  • Enforce user-space sandboxing and access control mechanisms.
  • Automate cryptographic signing pipelines in CI/CD against a signing backend.

Skills

Secure Boot
Embedded Linux security
dm-verity
dm-crypt
TrustZone
U-Boot
Yocto
OP-TEE
C programming
Python scripting
English

Tools

Yocto
OP-TEE
U-Boot

Job description

BairesDev is seeking an Embedded Security Engineer to architect Secure Boot and a hardware root of trust across the boot chain, from bootloader to kernel, and to harden storage with dm-verity/dm-crypt. You will build a Trusted Execution Environment, enable sandboxing, automate signing in CI/CD, and apply OP-TEE, TrustZone, and Yocto workflows on embedded Linux hardware.

Join a fully remote, flexible team and contribute to foundational security for connected devices while collaborating with

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Embedded Systems Security Engineer - Secure Boot & TEE
Embedded Systems Security Engineer - Secure Boot & TEE

Dorle Controls • Foster (OK)

On-site
USD 120,000 - 160,000
Embedded Security Engineer - Remote Work | REF#303891
Embedded Security Engineer - Remote Work | REF#303891

BairesDev • United States

Remote
MXN 2,037,000 - 3,055,000
Remote work
Flexible hours
Remote setup
+1
S 105 - Embedded Systems Security Engineer
S 105 - Embedded Systems Security Engineer

Dorle Controls • Foster (OK)

On-site
USD 120,000 - 160,000
S 105 - Embedded Systems Security Engineer
S 105 - Embedded Systems Security Engineer

Dorleco • Foster City (CA)

On-site
USD 140,000 - 210,000
Embedded Linux Security Engineer: Hardware Root of Trust
Embedded Linux Security Engineer: Hardware Root of Trust

Altentechnologyusa • Foster City (CA)

On-site
USD 120,000 - 150,000
Mentorship
Career growth opportunities
On-site work
Embedded Systems Security Engineer: Hardware Trust
Embedded Systems Security Engineer: Hardware Trust

Dorleco • Foster City (CA)

On-site
USD 140,000 - 210,000
Senior Embedded Security Engineer: TrustZone, Secure Boot & Linux
Senior Embedded Security Engineer: TrustZone, Secure Boot & Linux

GlobalLogic • Belmont (CA)

On-site
USD 140,000 - 150,000
Exciting Projects
Collaborative Environment
Work-Life Balance
+2
Principal Embedded Software Engineer
Principal Embedded Software Engineer

Colossus Technologies Group • Melbourne (FL)

On-site
USD 120,000 - 160,000
Senior Embedded Linux Security Engineer
Senior Embedded Linux Security Engineer

ALTEN Technology USA • Foster City (CA)

On-site
USD 120,000 - 150,000
Embedded Security Engineer: Secure Boot & Crypto
Embedded Security Engineer: Secure Boot & Crypto

Ambiq • Austin (TX)

On-site
USD 80,000 - 120,000