About this opportunity
Horizontal Talent lists this Embedded Systems Security Engineer opportunity in foster city, California. Review the employer’s description below for duties, qualifications and application requirements.
Job description
Join a hands-on embedded security team working to harden a next-generation Linux platform with a strong focus on secure boot, device integrity, and production-ready system protection. This role is ideal for an experienced systems engineer who enjoys bridging hardware security, kernel hardening, trusted execution environments, and secure manufacturing workflows.
Responsibilities
Design and implement hardware root of trust and secure boot solutions from early boot through the Linux kernel
Build and maintain storage integrity protections such as verified read-only root file systems and encryption at rest
Develop, integrate, and support trusted execution environment components and secure applications within the TEE
Apply strong user-space isolation controls using tools such as SELinux, AppArmor, cgroups, namespaces, and seccomp
Automate cryptographic signing workflows for bootloaders, kernels, and OTA artifacts within CI/CD pipelines
Partner with manufacturing teams to create secure provisioning processes, including fuse programming and end-of-line security validation
Design resilient multi-slot boot and recovery strategies to help devices recover safely from failed updates or boot issues
Collaborate across engineering, build, and production teams to ensure security is implemented reliably at scale
Skills
6+ years of experience in embedded Linux development, board bring-up, or BSP customization
3+ years of practical experience deploying security controls on physical hardware
Strong understanding of bootloader security and verified boot concepts
Experience with Linux storage and security technologies such as dm-crypt and dm-verity
Solid knowledge of ARM TrustZone and modern embedded processor security architecture
Proficiency with C and scripting in Python or Bash
Experience with embedded Linux build systems such as Yocto or Buildroot
Ability to work effectively across hardware, software, and manufacturing functions
Preferred Skills
Background in cryptography, including hashing, public key infrastructure, and symmetric/asymmetric methods
Experience working with HSMs or secure key vaults
Prior collaboration with contract manufacturers or factory operations on secure provisioning
Experience with lightweight container or sandboxing tools for embedded systems
Knowledge of anti-rollback strategies for firmware and OTA updates
Experience authoring secure/trusted applications for a TEE such as OP-TEE
Horizontal is committed to fostering an inclusive, respectful, and welcoming environment where people with diverse backgrounds, perspectives, and experiences can do their best work. We value equity, belonging, and collaboration, and we encourage qualified candidates to apply even if they do not meet every preferred qualification.
By applying for this position, you acknowledge and agree that Horizontal Talent may contact you regarding your application using automated technology, including phone calls, SMS/text messages, or email, which may be delivered by our virtual AI recruiter, Alex.
Please apply through this online posting or by visiting our Job Board at Applications will be accepted for 4 weeks. For those that join the team, we offer competitive compensation and benefits including medical, dental, vision, and retirement. Check out all we have to offer and how you can become part of the Horizontal Talent Team. The pay range for this role is $61 - $97 per hour based on qualifications and experience.
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.