Secure Embedded Systems Engineer - Kernel & Boot Hardening

dorle-controls-llc

Foster City (CA)

On-site

USD 140,000 - 190,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

dorle-controls-llc is seeking an Embedded Systems Security Engineer in Foster City, CA to harden its next‑generation embedded Linux platform. You will bridge hardware security, kernel hardening, and secure user-space containment while automating security pipelines in CI/CD.

You’ll collaborate with manufacturing to provision devices securely, implement hardware root of trust, secure boot, and OTA resilience, applying SELinux/AppArmor, U-Boot, and modern sandboxing techniques.

Qualifications

  • Bachelor's degree in CS/EE or related field.
  • 6+ years in Embedded Linux development, BSP, and board bring-up.
  • 3+ years deploying device-level security in production hardware.
  • Expertise in bootloaders (U-Boot/Barebox) and Linux kernel storage/security.
  • Knowledge of ARM TrustZone and Linux containment tools.

Responsibilities

  • Platform Hardening & Architecture: design Hardware Root of Trust and Secure Boot.
  • Storage & Integrity: implement dm-verity for verified read-only roots and encryption.
  • Trusted Execution Environments: develop and maintain OP-TEE and Secure Applications.
  • Application Sandboxing: enforce isolation with SELinux/AppArmor, cgroups, namespaces, and seccomp.
  • DevSecOps Automation: build cryptographic signing pipelines in CI/CD with HSMs.
  • Production Provisioning: write scripts for eFuses/OTP and end-of-line security tests.
  • System Resilience: design A/B partitioning for OTA update resilience.

Skills

Embedded Linux development
Board bring-up
BSP customization
Device security hardening
ARM TrustZone
SELinux/AppArmor
CI/CD security pipelines
C programming
Python scripting

Education

Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, or related field

Tools

U-Boot Verified Boot
Barebox
dm-verity
dm-crypt
OP-TEE
Yocto Project
Buildroot

Job description

dorle-controls-llc is seeking an Embedded Systems Security Engineer in Foster City, CA to harden its next‑generation embedded Linux platform. You will bridge hardware security, kernel hardening, and secure user-space containment while automating security pipelines in CI/CD.

You’ll collaborate with manufacturing to provision devices securely, implement hardware root of trust, secure boot, and OTA resilience, applying SELinux/AppArmor, U-Boot, and modern sandboxing techniques.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Embedded Systems Security Engineer: Hardware Trust
Embedded Systems Security Engineer: Hardware Trust

Dorleco • Foster City (CA)

On-site
USD 140,000 - 210,000
Embedded Systems Security Engineer - Secure Boot & TEE
Embedded Systems Security Engineer - Secure Boot & TEE

Dorle Controls • Foster (OK)

On-site
USD 120,000 - 160,000
S 105 - Embedded Systems Security Engineer
S 105 - Embedded Systems Security Engineer

Dorleco • Foster City (CA)

On-site
USD 140,000 - 210,000
S 105 - Embedded Systems Security Engineer
S 105 - Embedded Systems Security Engineer

dorle-controls-llc • Foster City (CA)

On-site
USD 140,000 - 190,000
Embedded Systems Security Engineer
Embedded Systems Security Engineer

RITWIK Infotech Inc • Foster City (CA)

On-site
USD 150,000 - 210,000
S 105 - Embedded Systems Security Engineer
S 105 - Embedded Systems Security Engineer

Dorle Controls • Foster (OK)

On-site
USD 120,000 - 160,000
Senior Embedded Linux Security Engineer
Senior Embedded Linux Security Engineer

ALTEN Technology USA • Foster City (CA)

On-site
USD 120,000 - 150,000
Embedded Security Architect: Hardware Trust & Secure Boot
Embedded Security Architect: Hardware Trust & Secure Boot

DeWinter Group • Foster City (CA)

On-site
USD 120,000 - 160,000
Embedded Systems Security Engineer
Embedded Systems Security Engineer

DeWinter Group • Foster City (CA)

On-site
USD 120,000 - 160,000
Embedded Security Engineer — Hardware Root of Trust
Embedded Security Engineer — Hardware Root of Trust

RITWIK Infotech Inc • Foster City (CA)

On-site
USD 150,000 - 210,000