Job Description
Senior Embedded Linux Security Engineer – Firmware & Platform Security
\n
Location: Foster City, CA
\n
Employment Type: Contract
\n
Work Arrangement: Onsite 4 days per week
\n
Compensation: $225,000–$300,000 annualized base compensation, plus benefits
\n
Work Status: Candidates must be currently authorized to work in the United States. This position is not eligible for new or future employer-sponsored work authorization.
\n
\n
Note: No C2C arrangements will be considered.
\n
\n
Third-party recruiters and agencies: Do not contact StratITech employees or representatives using personal contact information. Any attempt to use personal or information is strictly prohibited and will be reported to LinkedIn.
\n
\n
About the Role
\n
StratITech Services is supporting a highly specialized engineering team developing next-generation embedded systems and seeking a Senior Embedded Linux Security Engineer to help design and implement security across the device lifecycle.
\n
\n
This is a deeply hands-on role working at the intersection of embedded Linux, firmware, hardware security, boot architecture, and platform security.
\n
\n
The engineer will help establish hardware-backed trust from initial boot through the Linux operating system, trusted execution environment, secure software delivery, OTA updates, and manufacturing provisioning.
\n
\n
Responsibilities
\n
- \n
- Design and implement security architecture for next-generation Embedded Linux systems.
- Develop and maintain Secure Boot and verified boot chains rooted in hardware trust.
- Work with bootloaders and early-boot components to establish and maintain system integrity.
- Integrate and develop around Trusted Execution Environments (TEEs) and secure-world architectures.
- Develop security-critical software in C across firmware, bootloader, kernel, and platform layers.
- Implement and maintain Linux platform security controls, including policy enforcement and process isolation.
- Implement filesystem integrity and encryption using technologies such as dm-verity and dm-crypt.
- Design secure signing pipelines for bootloaders, kernels, firmware, and OTA software.
- Implement secure OTA update mechanisms, including A/B recovery, version enforcement, and anti-rollback protection.
- Support hardware-backed key management, certificates, secure storage, and cryptographic operations.
- Support manufacturing security processes including device provisioning, key injection, eFuses/OTP, and end-of-line validation.
- Collaborate closely with hardware, firmware, systems, security, DevOps, and manufacturing teams.
- Troubleshoot complex issues across hardware, firmware, bootloader, kernel, and user-space boundaries.
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
Must-Have Qualifications
\n
- \n
- 6+ years of professional experience in Embedded Linux, firmware, BSP, kernel, or low-level systems software development.
- 3+ years of device-level security experience working with physical production hardware or embedded systems.
- Advanced programming experience in C for embedded, firmware, kernel, BSP, or other low-level development.
- Deep understanding of Secure Boot, verified boot chains, chain of trust, and hardware Root of Trust concepts.
- Hands-on experience with bootloaders or early-boot security architecture.
- Hands-on experience with a Trusted Execution Environment (TEE) or hardware-isolated secure execution environment.
- Experience implementing Linux or Android platform security controls, including SELinux, AppArmor, or comparable mandatory access-control technologies.
- Understanding of Linux isolation and containment concepts including cgroups, namespaces, seccomp, or comparable mechanisms.
- Strong understanding of ARM-based embedded systems and secure system architecture.
- Experience debugging and integrating security features across multiple layers of an embedded platform.
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
Preferred Qualifications
\n
- \n
- OP-TEE development, including Trusted Applications.
- ARM TrustZone and Secure World architecture.
- QSEE/QTEE, Trusty, GlobalPlatform, KeyMint/Keymaster, or similar trusted execution technologies.
- U-Boot Verified Boot, Barebox, UEFI, Android Verified Boot (AVB/AVB2), Trusted Firmware-A (TF-A), PBL/SBL, BootROM, or comparable early-boot technologies.
- Strong hands-on experience developing or modifying SELinux or AppArmor policies.
- Experience with cgroups, namespaces, and seccomp in production embedded systems.
- dm-verity and dm-crypt.
- Yocto Project or Buildroot.
- PKI, certificate management, cryptographic signing, and key lifecycle management.
- Physical HSMs, secure elements, TPMs, or hardware-backed key storage.
- Manufacturing key injection, secure device provisioning, eFuse/OTP programming, or end-of-line security testing.
- Secure OTA, A/B boot, recovery mechanisms, and hardware-backed anti-rollback.
- Experience in automotive, autonomous systems, robotics, mobile, semiconductor, aerospace/defense, IoT, or other security-critical embedded environments.
- Python and/or Bash for tooling and automation.
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
Why This Role
\n
This is an opportunity to work on security at the platform and device level, rather than application security alone.
\n
\n
You will help shape how an advanced embedded platform establishes trust at power-on, protects execution at runtime, securely delivers software updates, protects cryptographic material, and maintains integrity throughout manufacturing and production deployment.
\n
\n
The role offers significant technical ownership across hardware security, firmware, Embedded Linux, cryptography, secure boot, trusted execution, and device lifecycle security.
\n
\n
This position requires working onsite in Foster City four days per week.
\n
\n
Candidates currently living elsewhere in the United States may be considered if they are willing and able to relocate to the San Francisco Bay Area at their own expense. Relocation assistance is not available.
