Overview
In this role you will strengthen security across platform firmware and embedded Linux systems, spanning BIOS, BMC, and device firmware. You’ll work with firmware and platform teams to design and implement security controls, while collaborating with security evaluation groups to improve validation and CI-integrated checks. The position combines hands-on work on low-level firmware, embedded Linux, and system hardening to protect boot chains, firmware updates, and management environments. You will influence both design and implementation, contributing to secure, scalable platform security across data-center and embedded contexts.
Pay / Benefits
- relocation package with visa sponsorship
- accommodations during recruitment process
- hybrid working options
- equal opportunities employer
Responsibilities
- Evaluate and integrate security mechanisms across BIOS, BMC, and device firmware (secure boot, firmware verification, update flows, rollback protection, debug controls)
- Improve security of Linux-based management environments through system hardening, service isolation, access control, and secure configuration
- Identify attack surfaces and gaps, apply and validate hardening measures and secure defaults
- Collaborate with security evaluation and engineering teams to support testing, develop validation tools/scripts, and integrate security checks into CI workflows
- Support threat modeling and analysis of firmware and management plane components to identify attack paths and improvement areas
Key requirements
- Hands-on experience with embedded Linux systems, including building/customizing Yocto/OpenEmbedded platforms
- Experience implementing and validating Linux hardening controls (service/interface hardening, privilege management, reducing attack surface)
- Experience contributing to security control implementation/integration in firmware or embedded environments
- Strong understanding of low-level firmware and boot flows (BIOS/UEFI, bootloaders, platform firmware)
- Experience with secure boot chains and firmware trust models (firmware verification, UEFI)
- Experience with firmware update mechanisms (signing, verification, rollback protection)
- Familiarity with ARM architecture and boot processes (early boot stages, firmware–hardware interaction)
- Familiarity with platform interconnects like PCIe and related security considerations
- Experience developing automation/validation tools or scripts; CI workflow integration
- Proficiency in C/C++ for systems/embedded development
- Understanding of Linux security fundamentals (authentication, authorization, system protections)
- Familiarity with file system/data protection mechanisms (encryption like eCryptfs)
- Ability to analyze firmware and system-level attack surfaces
- collaboration with cross-functional teams
- focus on security-driven problem solving
- analytical mindset for threat analysis
- Yocto/OpenEmbedded
- Linux hardening and platform security
- secure boot and firmware verification
…
