Sr Software Engineer, Device Security

Insight Global
Palo Alto, CA, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Android Software Development C++ (Programming Language) Cyber Security Computer Programming Firmware Key Management Network Security Linux Security Modules Public Key Infrastructure Cloud Services Data Streaming
+5 more
EndPointSecurity Data Processing Selinux Coreos U-Boot

Job description

  • Lead the design and implementation of embedded device security architecture from the ground up. This includes using the best industry standard cryptography practices for things like secure key management systems, hardware secure boot, PKI, efficient encryption of data, and more.

  • Collaborate cross-functionally with the CoreOS, Firmware, Design, and Cloud Services teams to create robust security features.

  • Develop custom TrustZone or native kernel applications to enhance hardware-backed identity solutions and data protection.

  • Work on high-profile projects, such as secure channels between devices, protecting personal data, and automatic theft detection; which all require secure and efficient data handling.

  • Interface with biometric sensors to create secure channels for data flow inside and outside device boundaries.

Requirements

  • 6+ years of experience in secure programming in embedded system, AOSP, or Windows environments, primarily in C, C++, or Java.

  • Strong understanding of general embedded systems security concepts, including establishing roots of trust, secure boot, cryptography, PKI, or application sandboxing.

  • Experience in firmware security, OS-level security, or network security.

  • Demonstrated ability to architect and lead multi-disciplinary projects from concept to deployment.

  • Experience in designing secure interfaces with biometric sensors, custom PKI handling, or factory flow processes.

  • Ability to work closely with cross-functional teams to assess attack surface and threat models across many different features.

  • Deep understanding (OR deep desire to learn) of cryptography, security, and privacy theory and practices. * Background in embedded systems like consumer electronics, IoT, medical, or payment devices or systems.

  • Experience with AOSP and Linux security, including TrustZone, TEE, AVB, Keystore, and SELinux.

  • Experience with privacy compliance standards like GDPR, CCPA, HIPAA, or ISO.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

5:44 min

Tightening the security perimeter using SELinux

Dimitrij Klesev +1 · LIVE

2:44 min

Evaluating etcd deployment operators and helm charts

Mario Valderrama Mario Valderrama +1 · WWC 2024

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

9:38 min

Troubleshooting SELinux container permission denials live

Dimitrij Klesev +1 · LIVE

1:57 min

Following security research and continuous developer education

Martin Schmiedecker · LIVE

Videos

See all

Related articles

See all