> Markdown version of [/jobs/ext/1788688-embedded-systems-security-engineer](https://www.wearedevelopers.com/jobs/ext/1788688-embedded-systems-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Embedded Systems Security Engineer - **Company:** Snap Inc. - **Location:** San Diego, CA, United States - **Experience:** Experienced - **Salary:** $157,000.0 - $235,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, C++ (Programming Language), Static Program Analysis, Computer Engineering, Software Debugging, Linux, Dynamic Program Analysis, Embedded Operating Systems, Firmware, Fuzz Testing, Key Management, Linux System Administration, Parsing, Secure Coding, Security Software, Data Streaming, Privacy Controls, Data Processing, Information Technology, Vulnerability Analysis, Programming Languages - **Published:** July 8, 2026 - **Apply:** https://dejobs.org/x/x/E43440177B6143498C92946E02FEB7C5/job/ ## About the Role * Knowledge of Linux-based system security, embedded operating systems, trusted execution boundaries, secure software architecture, applied cryptography, authentication, authorization, attestation, key management, and platform hardening techniques. * Knowledge of permission systems, access control, least-privilege design, sandboxing, secure IPC, service isolation, and privacy-preserving access to sensors, user data, and system capabilities. * Develop security and privacy controls for on-device AI features, including model integrity, sensitive data handling, inference-time privacy protections, and local policy enforcement. * Ability to perform security analysis, threat modeling, vulnerability assessment, secure code review, fuzzing, static analysis, dynamic analysis, and automated security validation across OS, firmware and AI/ML system boundaries., * Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, a related technical field, or equivalent practical experience. * 5+ years of experience developing production software in one or more programming languages such as C, C++, Rust. * 3+ years of experience building security, privacy, or platform protection features for Linux-based, embedded, mobile, wearable, or connected device systems. * Experience with applied cryptography, authentication, authorization, secure communications, key management, threat modeling, vulnerability assessment, or system security for embedded or Linux-based systems., * Master's degree or PhD in Computer Science, Computer Engineering, Electrical Engineering, or a related technical discipline. * Experience designing or building on-device permission systems, access control frameworks, sandboxing, secure IPC, service isolation, least-privilege architectures, or privacy-preserving controls for sensor-rich devices. * Experience securing on-device AI, ML, or assistant-like systems, including model integrity, sensitive data handling, inference-time privacy, AI feature permissions, local policy enforcement, and protection of model inputs and outputs. * Experience with trusted execution technologies, secure manufacturing, device provisioning, attestation, anti-rollback, secure debug, lifecycle state management, fuzzing, automated security validation, or platform-level vulnerability hardening for Linux-based systems. ## Description * Design, build, and harden on-device security systems for Specs, including permissions, access control, secure IPC, sandboxing, and trusted execution boundaries. * Develop security and privacy controls for on-device AI features, including model integrity, sensitive data handling, inference-time privacy protections, local policy enforcement, and secure access to sensors, user data, and system capabilities. * Research, design, and implement security features that improve the security posture of Specs across Snap OS, firmware, applications, system services, and cloud-connected device surfaces. * Improve fuzzing infrastructure, automated security testing, and continuous validation pipelines for OS components, IPC mechanisms, parsers, services, drivers, firmware interfaces, and AI-related data flows. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Building a Compiler with C#](https://www.wearedevelopers.com/videos/116-building-a-compiler-with-c) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 166: Sycophancy, Zip bombs and AI Native Development](https://www.wearedevelopers.com/magazine/585-dev-digest-166-sycophancy-zip-bombs-and-ai-native-development) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data)