Senior Embedded Platform Security Engineer (India)

Senior Embedded Platform Security Engineer (India)

28 Aug
|
L4B Software
|
India

28 Aug

L4B Software

India

About L4B Software

L4B Software develops secure, reliable operating-system platforms for embedded, regulated and mission-critical products. Our engineers work close to the operating system and hardware, where security, reliability and long-term maintainability matter.

About the role

We are looking for a senior, hands-on Embedded Platform Security Engineer with robust experience securing Linux and Android platforms at system level. This is an engineering and integration role, not primarily a governance, compliance or application-security position.

You will work across the platform security chain, including bootloaders, secure and verified boot, kernel security, trusted execution environments, encrypted storage, filesystem integrity, hardware-backed key management, secure storage and Android platform security. You should be comfortable investigating problems across BSP, bootloader, kernel, Device Tree, TEE, native services and userspace boundaries.

This role is for an engineer who can turn platform-security architecture into a working embedded implementation, and debug it when the layers do not behave as expected.

What you will do

- Design, implement and review security architecture for Embedded Linux and Android/AOSP platforms.
- Integrate and troubleshoot secure boot and chain-of-trust mechanisms from early boot through bootloader, kernel and operating system.
- Implement and maintain storage and filesystem-security mechanisms such as dm-crypt, dm-verity, fs-verity, LUKS, encrypted partitions and authenticated system images.
- Integrate Trusted Execution Environments and hardware-backed security mechanisms, including ARM TrustZone, OP-TEE or equivalent vendor technologies.
- Work with secure key provisioning, hardware-backed key storage, secure storage, RPMB, cryptographic accelerators and root-of-trust mechanisms.
- Implement and troubleshoot Android platform-security mechanisms such as Android Verified Boot, file-based encryption, KeyMint/Keymaster, hardware-backed keystores, SELinux, rollback protection and device-integrity mechanisms.
- Analyze interactions between bootloader, Linux kernel, Device Tree, BSP components, security firmware, TEE and operating-system security services.
- Debug low-level security integration issues using boot logs, kernel traces,



source-code analysis and SoC/platform documentation.
- Review Linux kernel and userspace configurations for security weaknesses, hardening opportunities and unnecessary attack surface.
- Apply Linux security mechanisms such as capabilities, namespaces, seccomp, SELinux, AppArmor and other Linux Security Modules where appropriate.
- Support vulnerability investigation, CVE triage and remediation at kernel, BSP, system-library and platform level.
- Support SBOM, SCA, static analysis, fuzzing and security-verification activities.
- Perform threat modeling and translate identified threats into concrete technical controls and verification criteria.
- Work closely with platform, software, validation and quality teams to turn security requirements into implementation, tests and evidence.

What you bring

Must have

- Strong professional experience developing, integrating or securing Embedded Linux products or platforms.
- Strong hands-on Linux security experience at kernel, BSP and system level.
- Hands-on Android/AOSP platform-security experience, not only Android application security.
- Strong understanding of embedded boot flows from hardware root of trust and bootloader through kernel and userspace.
- Practical experience implementing or debugging secure boot, verified boot or comparable chain-of-trust mechanisms.
- Hands-on experience with dm-crypt, dm-verity or equivalent Linux storage and integrity technologies.
- Experience with ARM TrustZone, OP-TEE or another Trusted Execution Environment.
- Understanding of hardware-backed key management, secure storage and cryptographic services.
- Experience working with ARM-based embedded SoCs and vendor-specific platform-security mechanisms.
- Strong Embedded Linux build-system knowledge, ideally Yocto Project, OpenEmbedded and BitBake.
- Strong C/C++ understanding and the ability to investigate platform-security issues at source-code level.
- Ability to work across bootloader, kernel, BSP,



Device Tree, TEE and userspace boundaries.
- Experience with vulnerability analysis and remediation of low-level platform components.
- Ability to read SoC, security and platform documentation and translate it into working implementations.
- Strong debugging and root-cause-analysis skills.

Product-security engineering

You should understand how low-level platform implementation connects to broader product-security activities. Experience with threat modeling, attack-surface analysis, vulnerability management, CVE remediation, SBOM/SCA, security requirements, security verification and secure-development lifecycle activities is important.

Experience applying IEC 62443, IEC 81001-5-1 or a comparable product-cybersecurity standard is valuable, particularly when engineering controls must be translated into requirements, tests and evidence.

Nice to have

- Experience securing multiple ARM-based SoC families or vendor BSPs.
- Deep Android BSP or AOSP platform-development experience.
- BSP bring-up and Device Tree experience.
- Linux kernel configuration, hardening or debugging experience.
- U-Boot or UEFI development experience.
- TPM 2.0, secure elements or device-identity provisioning.
- OTA and secure firmware-update architecture.
- PKI, certificates and manufacturing/device provisioning flows.
- Static analysis, fuzzing or penetration-testing experience.
- IEC 62443, IEC 81001-5-1, IEC 62304 or comparable standards experience.
- Experience with regulated, safety-critical, mission-critical or long-lifecycle products.

What this role is not

- Not primarily an Android application-development role focused on Kotlin, Java or application-layer features.
- Not primarily a GRC, audit or cybersecurity-compliance position.
- Not a pure vulnerability-management or SOC role.
- You do not need to spend your time writing device drivers, but you must be technically comfortable going deep enough into the BSP, kernel, bootloader and hardware-security architecture to resolve platform-security integration problems.

The successful candidate can move confidently between Linux, Android, bootloader, kernel, TEE and SoC security mechanisms and turn security architecture into a secure, testable and maintainable embedded platform.

📌 Senior Embedded Platform Security Engineer (India)
🏢 L4B Software
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior embedded platform security engineer (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: senior embedded platform security engineer (india) / india