вчера

security engineer for embedded platforms

ориентир по рынку
вакансия зп не указана
в среднем 328 556 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

L4B Software develops secure, reliable operating-system platforms for embedded, regulated, and mission-critical products. Its engineers work close to the operating system and hardware, with a focus on security, reliability, and long-term maintainability.

задачи

  • Design, implement, and review security architecture for Embedded Linux and Android/AOSP platforms;
  • Integrate and troubleshoot secure boot and chain-of-trust mechanisms across bootloader, kernel, and OS;
  • Implement and maintain storage and filesystem security mechanisms;
  • Integrate TEEs and hardware-backed security mechanisms;
  • Work with secure key provisioning, hardware-backed key storage, RPMB, cryptographic accelerators, and root-of-trust mechanisms;
  • Implement and troubleshoot Android platform-security mechanisms;
  • Analyze interactions across bootloader, kernel, Device Tree, BSP, security firmware, TEE, and OS security services;
  • Debug low-level security integration issues using boot logs, kernel traces, source-code analysis, and SoC/platform documentation;
  • Review Linux kernel and userspace configurations for security weaknesses and hardening opportunities;
  • Apply Linux security mechanisms, including capabilities, namespaces, seccomp, SELinux, AppArmor, and other LSMs;
  • Support vulnerability investigation, CVE triage, and remediation at kernel, BSP, system-library, and platform level;
  • Support SBOM, SCA, static analysis, fuzzing, and security-verification activities;
  • Perform threat modeling and translate threats into technical controls and verification criteria;
  • Work with platform, software, validation, and quality teams to turn security requirements into implementation, tests, and evidence.

требования

  • At least 5 years of professional experience;
  • Strong experience developing, integrating, or securing Embedded Linux products and platforms;
  • Strong hands-on Linux security experience at kernel, BSP, and system level;
  • Hands-on Android/AOSP platform-security experience beyond Android application security;
  • Strong understanding of embedded boot flows from hardware root of trust and bootloader through kernel and userspace;
  • Practical experience implementing or debugging secure boot, verified boot, or comparable chain-of-trust mechanisms;
  • Hands-on experience with dm-crypt, dm-verity, or equivalent Linux storage and integrity technologies;
  • Experience with ARM TrustZone, OP-TEE, or another TEE;
  • Understanding of hardware-backed key management, secure storage, and cryptographic services;
  • Experience with ARM-based embedded SoCs and vendor-specific platform-security mechanisms;
  • Strong Embedded Linux build-system knowledge, ideally Yocto Project, OpenEmbedded, and BitBake;
  • Strong C/C++ understanding with the ability to investigate platform-security issues at source-code level;
  • Ability to work across bootloader, kernel, BSP, Device Tree, TEE, and userspace boundaries;
  • Experience with vulnerability analysis and remediation of low-level platform components;
  • Strong debugging and root-cause-analysis skills;
  • Experience with threat modeling, attack-surface analysis, vulnerability management, CVE remediation, SBOM/SCA, and secure-development lifecycle activities;
  • Nice to have: experience securing multiple ARM-based SoC families or vendor BSPs, deep Android BSP or AOSP platform-development experience, BSP bring-up and Device Tree experience, U-Boot or UEFI/EDK2 development experience, TPM 2.0, secure elements or device-identity provisioning, OTA and secure firmware-update architecture, PKI and manufacturing/device provisioning flows, static analysis, fuzzing or penetration-testing experience, IEC 62443, IEC 81001-5-1, IEC 62304 or comparable standards experience, experience with regulated, safety-critical or long-lifecycle products.

условия

  • Full-time employment only; no B2B or contract engagements;
  • Short-notice or immediate joiners are preferred.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.