← Tillbaka till jobb

Senior Embedded Platform Security Engineer

  • Distans
  • Sverige
  • Engelska
  • Publicerad 18.09.26 12:28

⚠️ Please read before applying:Minimum 5 years of professional experience required, with strong hands-on Linux/Android platform security engineering. This is a senior role, not a fresher position.This is Full-Time employment only — no B2B/contract engagements.Short-notice/immediate joiners preferred, though strong candidates with the right depth are still encouraged to apply.This is not primarily an Android application-development role (Kotlin/Java/application-layer work) — it's system-level platform security engineering.This is also not a GRC, audit, compliance, or pure SOC/vulnerability-management role. You'll need to get hands-on inside bootloader, kernel, BSP, and TEE layers, not just write policy or triage tickets. About L4B SoftwareL4B Software develops secure, reliable operating-system platforms for embedded, regulated, and mission-critical products. Our engineers work close to the operating system and hardware, where security, reliability, and long-term maintainability matter.About the RoleWe're looking for a senior, hands-on Embedded Platform Security Engineer with strong experience securing Linux and Android platforms at system level. You'll work across the full platform security chain — bootloaders, secure/verified boot, kernel security, trusted execution environments, encrypted storage, filesystem integrity, hardware-backed key management, and Android platform security — and be comfortable investigating problems across BSP, bootloader, kernel, Device Tree, TEE, native services, and userspace boundaries.This role is for an engineer who can turn platform-security architecture into a working embedded implementation, and debug it when the layers don't behave as expected.Key ResponsibilitiesDesign, implement, and review security architecture for Embedded Linux and Android/AOSP platformsIntegrate and troubleshoot secure boot and chain-of-trust mechanisms from early boot through bootloader, kernel, and OSImplement and maintain storage/filesystem-security mechanisms (dm-crypt, dm-verity, fs-verity, LUKS, encrypted partitions, authenticated system images)Integrate TEEs and hardware-backed security mechanisms (ARM TrustZone, OP-TEE, or equivalent)Work with secure key provisioning, hardware-backed key storage, RPMB, cryptographic accelerators, and root-of-trust mechanismsImplement and troubleshoot Android platform-security mechanisms (AVB, file-based encryption, KeyMint/Keymaster, hardware-backed keystores, SELinux, rollback protection, device-integrity)Analyze interactions between bootloader, kernel, Device Tree, BSP, security firmware, TEE, and OS security servicesDebug low-level security integration issues using boot logs, kernel traces, source-code analysis, and SoC/platform documentationReview Linux kernel and userspace configurations for security weaknesses and hardening opportunitiesApply Linux security mechanisms — capabilities, namespaces, seccomp, SELinux, AppArmor, and other LSMsSupport vulnerability investigation, CVE triage, and remediation at kernel, BSP, system-library, and platform levelSupport SBOM, SCA, static analysis, fuzzing, and security-verification activitiesPerform threat modeling and translate threats into concrete technical controls and verification criteriaWork closely with platform, software, validation, and quality teams to turn security requirements into implementation, tests, and evidenceMust-Have SkillsStrong professional experience developing, integrating, or securing Embedded Linux products/platformsStrong hands-on Linux security experience at kernel, BSP, and system levelHands-on Android/AOSP platform-security experience — not just Android application securityStrong understanding of embedded boot flows, from hardware root of trust and bootloader through kernel and userspacePractical experience implementing or debugging secure boot, verified boot, or comparable chain-of-trust mechanismsHands-on experience with dm-crypt, dm-verity, or equivalent Linux storage/integrity technologiesExperience with ARM TrustZone, OP-TEE, or another TEEUnderstanding of hardware-backed key management, secure storage, and cryptographic servicesExperience with ARM-based embedded SoCs and vendor-specific platform-security mechanismsStrong Embedded Linux build-system knowledge — ideally Yocto Project, OpenEmbedded, and BitBakeStrong C/C++ understanding, with ability to investigate platform-security issues at source-code levelAbility to work across bootloader, kernel, BSP, Device Tree, TEE, and userspace boundariesExperience with vulnerability analysis and remediation of low-level platform componentsStrong debugging and root-cause-analysis skillsExperience with threat modeling, attack-surface analysis, vulnerability management, CVE remediation, SBOM/SCA, and secure-development lifecycle activitiesGood to HaveExperience securing multiple ARM-based SoC families or vendor BSPsDeep Android BSP or AOSP platform-development experienceBSP bring-up and Device Tree experienceU-Boot or UEFI/EDK2 development experienceTPM 2.0, secure elements, or device-identity provisioningOTA and secure firmware-update architecturePKI, certificates, and manufacturing/device provisioning flowsStatic analysis, fuzzing, or penetration-testing experienceIEC 62443, IEC 81001-5-1, IEC 62304, or comparable standards experienceExperience with regulated, safety-critical, or long-lifecycle products If you can move confidently between Linux, Android, bootloader, kernel, TEE, and SoC security mechanisms — and turn security architecture into a secure, testable embedded platform — apply and let's talk.