S 105 - Embedded Systems Security Engineer

Dorle Controls

Foster (OK)

On-site

USD 120,000 - 160,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Dorle Controls is seeking an Embedded Systems Security Engineer to harden our next-generation embedded Linux platform, bridging hardware security, kernel hardening, and secure user-space containment. You will design cryptographic defenses and automate security pipelines in CI/CD for secure OTA updates.

You will collaborate with manufacturing to provision devices securely at scale and lead DevSecOps practices, including secure boot, TEE integration, and sandboxing.

Qualifications

  • Bachelor's degree or equivalent practical experience in a technical field
  • 6+ years in Embedded Linux development, board bring-up, BSP customization
  • 3+ years deploying device-level security features in production hardware
  • Deep knowledge of bootloaders (U-Boot, Barebox) and Linux kernel storage/security subsystems
  • Strong understanding of ARM TrustZone and modern processor security architectures
  • Experience with Linux containment tools (SELinux/AppArmor, cgroups, namespaces, seccomp)
  • Proficiency in C and scripting (Python/Bash)

Responsibilities

  • Design and implement Hardware Root of Trust and Secure Boot across bootloaders to Linux kernel
  • Implement dm-verity for verified read-only root filesystems and data encryption at rest
  • Develop and maintain a TEE (e.g., OP-TEE) and Secure/Trusted Applications
  • Enforce sandboxing and containment in user space (SELinux, AppArmor, namespaces, cgroups, seccomp)
  • Build automated cryptographic signing pipelines in CI/CD (GitLab CI, GitHub Actions)
  • Collaborate with manufacturing to burn hardware configuration fuses securely and validate security features pre-shipment
  • Design multi-slot boot recovery layouts (A/B) for OTA resilience

Skills

Embedded Linux
Board bring-up
BSP customization
C programming
Python scripting
Shell scripting
Security design
OTA updates security

Education

Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering

Tools

U-Boot
Barebox
dm-crypt
dm-verity
SELinux
AppArmor
cgroups
namespaces
seccomp
Yocto Project
Buildroot

Job description

Job Title - Embedded Systems Security Engineer

Location - Onsite in Foster City, CA | 5 days in office

We are looking for an Embedded Systems Security Engineer to implement security solution to harden our next-generation embedded Linux platform. In this role, you will bridge the gap between low-level hardware security, kernel hardening, and secure user-space application containment. You will not only design cryptographic defense mechanisms but will also automate security pipelines in CI/CD and partner directly with manufacturing teams to ensure devices are provisioned securely and reliably at scale without production risks.

Roles & Responsibilities:
  • Platform Hardening & Architecture: Design and implement the Hardware Root of Trust and Secure Boot architecture from the first-stage bootloader through the Linux kernel.
  • Storage & Integrity Management: Implement dm-verity for cryptographically verified read-only root filesystems and secure data encryption at rest.
  • Trusted Execution Environments: Develop, integrate, and maintain a TEE (e.g., OP-TEE) and author Secure/Trusted Applications (TAs).
  • Application Sandboxing: Enforce strict user-space isolation and sandboxing strategies using SELinux, AppArmor, cgroups, namespaces, and seccomp filters to protect core systems from untrusted applications.
  • DevSecOps Automation: Build automated cryptographic signing pipelines within CI/CD infrastructure (e.g., GitLab CI, GitHub Actions) to securely sign bootloaders, kernels, and OTA payloads using HSMs or secure key vaults.
  • Production Provisioning Support: Collaborate with manufacturing teams to write robust scripts and tools for burning permanent hardware configuration fuses (eFuses / OTP memory) securely, designing end-of-line (EOL) test software to validate security features before shipping.
  • System Resilience: Architect multi-slot boot recovery layouts (e.g., A/B partitioning) to guarantee fail-safe resilience against failed OTA updates or corrupted boots.
Qualifications:
  • Education: Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical discipline (or equivalent practical experience).
  • Core Experience: 6 years of professional experience in Embedded Linux development, board bring-up, and Board Support Package (BSP) customization.
  • Security Focus: 3 years of dedicated, hands-on experience deploying device-level security features into physical production hardware.
  • Low-Level Systems: Expert knowledge of bootloader configurations (e.g., U-Boot Verified Boot, Barebox) and customizing the Linux kernel storage/security subsystem (dm-crypt, dm-verity).
  • Hardware Security Architecture: Deep understanding of modern processor security architectures, specifically ARM TrustZone (ARMv7-A / ARMv8-A, Exception Levels EL1--EL3).
  • Sandboxing & Access Controls: Proven track record implementing SELinux/AppArmor policies and utilizing standard Linux containment tools (cgroups, namespaces).
  • Build Automation: Proficiency with embedded Linux build automated frameworks like the Yocto Project (BitBake recipe design) or Buildroot.
  • Programming: Advanced proficiency in C and strong scripting skills in Python or Bash.
Preferred Qualifications:
  • Cryptography Expertise: Strong foundational knowledge of symmetric/asymmetric cryptography, hashing algorithms (SHA-256/384), public key infrastructure (PKI), and handling physical Hardware Security Modules (HSMs).
  • Manufacturing Scale: Prior experience working with Contract Manufacturers (CMs) or internal factory lines to deploy secure key-injection and fuse-burning protocols.
  • Advanced Sandboxing: Experience with embedded container runtimes (e.g., LXC, crun) or lightweight sandboxing frameworks tailored for resource-constrained architectures.
  • Anti-Rollback Protection: Experience designing secure versioning and hardware-enforced anti-rollback strategies for OTA updates.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

S 105 - Embedded Systems Security Engineer
S 105 - Embedded Systems Security Engineer

Dorleco • Foster City (CA)

On-site
USD 140,000 - 210,000
Embedded Systems Security Engineer
Embedded Systems Security Engineer

RITWIK Infotech Inc • Foster City (CA)

On-site
USD 150,000 - 210,000
Embedded Systems Security Engineer
Embedded Systems Security Engineer

DeWinter Group • Foster City (CA)

On-site
USD 120,000 - 160,000
Embedded Systems Security Engineer: Hardware Trust
Embedded Systems Security Engineer: Hardware Trust

Dorleco • Foster City (CA)

On-site
USD 140,000 - 210,000
Embedded Linux Security Engineer
Embedded Linux Security Engineer

Altentechnologyusa • Foster City (CA)

On-site
USD 120,000 - 150,000
Mentorship
Career growth opportunities
On-site work
Senior Embedded Linux Platform Engineer
Senior Embedded Linux Platform Engineer

Futurex Inc. • Bulverde (TX), Northern (KY)

Hybrid
USD 150,000 - 190,000
Health insurance
Retirement plan with match
Paid time off
Senior Embedded Linux Platform Engineer
Senior Embedded Linux Platform Engineer

Futurex • Bulverde (TX)

On-site
USD 120,000 - 180,000
Product Security Engineer
Product Security Engineer

Cypress HCM • Irvine (CA)

On-site
USD 130,000 - 180,000
Embedded Software Engineer - Security
Embedded Software Engineer - Security

Ambiq • Austin (TX)

On-site
USD 80,000 - 120,000
Embedded Linux Security Engineer
Embedded Linux Security Engineer

ALTEN Technology USA • Foster City (CA)

On-site
USD 120,000 - 150,000