Secure Embedded Software Engineer
1
Which company are you aiming at?
To generate precise rejection-prevention feedback and application strategy, tell us where you're targeting.
2
Send your application
You need an account so we know where to send the feedback.
The job description
Tech stack. C, secure boot, ARM TrustZone, hardware crypto accelerators, mbedTLS, key provisioning, TPM/secure elements, side-channel awareness
About the role
You will join a payment terminal company where every device handles cardholder data and must pass rigorous security certification. The secure embedded team owns the device's trust foundation: secure boot, key management, and the hardened firmware that protects secrets from physical and remote attackers. This role matters because a single compromised key or bypassed boot check can invalidate the security of an entire deployed fleet, and attackers only need to win once.
What you will achieve
- Ship a secure boot chain with measured boot from ROM through application, verified on two hardware platforms with zero bypass findings in independent penetration testing, with test reports retained as certification evidence
- Drive key provisioning infrastructure that injects unique device keys at manufacturing with a measured defect rate below 100 PPM across the first production ramp, monitored by automated yield dashboards
- Reduce the attack surface by implementing TrustZone-based isolation, moving all key material and crypto operations into the secure world with a minimized trusted codebase
- Build a tamper-response firmware layer that detects physical intrusion attempts and zeroizes secrets within 100 milliseconds, validated by lab attack testing, with attack test results reviewed by the security architect
- Own the security validation test suite, covering 200+ attack scenarios from glitching to firmware rollback attempts, run as a gate on every release, with new scenarios added after every penetration test
What you will bring
Must-haves
- 2-5 years in embedded security: secure boot, cryptography integration, or hardened firmware development for certified products
- Strong C with security-conscious coding: constant-time operations, memory hygiene, and input validation at trust boundaries
- Hands-on experience with ARM TrustZone or equivalent trusted execution environments in production
- Working knowledge of cryptographic primitives and their correct embedded use: AES, ECDSA/ECDH, SHA, and HMAC
- Experience with secure key provisioning and lifecycle management integrated into manufacturing flows
- Familiarity with secure elements or TPMs and their integration into boot and attestation flows
- Threat-modeling instincts: habitually thinking like an attacker about your own firmware
Nice-to-haves
- Experience with payment security standards such as PCI PTS or Common Criteria evaluations
- Knowledge of side-channel attack mitigations including DPA/EMA countermeasures
- Familiarity with post-quantum cryptography migration planning for embedded fleets
Apple
NVIDIA
Tesla
Qualcomm
Bosch
Garmin