Embedded Security Engineer
The job description
Tech stack. C and C++, ARM TrustZone and TPM, secure boot chains, firmware signing and verification, JTAG and SWD debugging, side-channel analysis basics, Yocto or embedded Linux, hardware security modules
About the role
You will secure the firmware and hardware roots of trust for an IoT device company shipping millions of connected units into homes and enterprises worldwide. The team owns secure boot, key provisioning, and update integrity from silicon selection through cloud integration, working shoulder to shoulder with hardware and firmware engineers. You will review designs, test real hardware, and build the processes that keep fleets secure for a decade of field life. This role matters because a compromised device fleet cannot be fixed with a password reset; the security has to be baked into the hardware and firmware from day one, and you are the engineer who makes sure it is.
What you will achieve
- Ship a secure boot chain with cryptographic firmware verification on every new product, validated through hardware-in-the-loop testing before mass production begins.
- Build the factory key provisioning process so each device leaves manufacturing with unique, hardware-protected credentials and zero shared secrets.
- Deliver encrypted, rollback-protected OTA updates achieving a 99 percent fleet update success rate across diverse real-world network conditions.
- Find and fix firmware vulnerabilities through systematic code review and coverage-guided fuzzing before each major release.
- Document the device threat model so hardware, firmware, and cloud teams operate from one consistent, agreed security picture.
What you will bring
Must-haves
- 2 to 5 years in embedded software, firmware engineering, or hardware security roles with shipped products.
- Strong C and C++ skills, including memory safety pitfalls and how attackers exploit them in practice.
- Understanding of secure boot architecture, code signing infrastructure, and chain-of-trust design principles.
- Familiarity with hardware security primitives: TPMs, secure elements, TrustZone, or eFuse-based protections.
- Experience debugging real hardware with JTAG, SWD, or logic analyzers on development boards.
- Knowledge of cryptographic fundamentals: symmetric and asymmetric algorithms, hashing, and sound key management.
- Ability to read schematics and datasheets well enough to assess hardware attack surface.
Nice-to-haves
- Experience with side-channel or fault-injection analysis techniques in a lab setting.
- Familiarity with PSA Certified, SESIP, or similar IoT security evaluation frameworks.
- Contributions to embedded security tooling or published vulnerability research.
- Knowledge of secure manufacturing and supply chain integrity practices.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta