HungryJob 🇵🇭
TI

Senior Software Security Engineer (Linux Appliances)

Total Integrated Resources Pte Ltd

Bonifacio Global City, Metro ManilaPosted 8 days agoJobStreet

Setup
Remote
Type
Full-time
Level
Senior
Salary
PHP 80k–120k/mo
Closes
Open

Skills mentioned

PythonLinuxFinanceManufacturing
Sign up free to tailor my resume for this job Apply on JobStreet

Members see a match score against their own skills and get a resume + cover letter written for this posting.

About the role

You will own the security architecture and secure-platform engineering of appliance products: the trusted boot chain, disk and payload encryption, hardware-backed key management, attestation, OS hardening, and the build and provisioning systems that produce tamper-resistant units. The role also involves work on media streaming stack and its integration with third-party platforms, but the center of gravity is software security — designing, implementing, and defending the mechanisms that keep devices and intellectual property protected in hostile environments.

Key responsibilities

Design and maintain the appliance trust architecture: UEFI Secure Boot key hierarchy and signing workflows, measured boot, and TPM-anchored secrets

Work with TPM 2.0 in production: key creation and attributes, PCR measurement and policy, sealed storage, remote attestation (quotes, verification chains), and LUKS/Clevis disk-encryption binding

  • Harden the Linux platform end to end: kernel configuration and lockdown, IMA appraisal policy, App
  • Armor confinement, sysctl and module-blacklist hardening, auditd, and systemd sandboxing
  • Own the secure build pipeline: hardened kernel builds, signed OS image assembly, reproducibility practices, and cryptographic verification at every stage

Implement applied-cryptography workflows correctly: signature schemes (RSA-PSS, OAEP), authenticated encryption (AES-GCM), canonical serialization for signed documents, key ceremonies, and key-compromise response

Build verification infrastructure: QEMU/OVMF/swTPM-based boot testing, self-tests with negative controls, and fail-closed validation gates

Contribute to threat modeling: define adversaries and trust boundaries, document what is in and out of scope, and defend architectural invariants through written decision records

  • Develop and debug within media streaming stack (RTSP, ONVIF, media pipelines) as product work requires
  • Write operator-grade tooling (bash, Python, C) and the runbooks that go with it

Required Experience

Software and Platform Security (Core of the Role):5+ years in security-focused systems engineering on Linux;UEFI Secure Boot: key hierarchy (PK/KEK/db), image signing, enrollment workflows;TPM 2.0 hands-on experience: key attributes, PCR policies, sealing, attestation concepts (EK, AK, quotes); Disk encryption in production: LUKS2, cryptsetup, TPM binding (Clevis or equivalent); Linux hardening: mandatory access control (App

Armor or SELinux), kernel lockdown, IMA/EVM or comparable integrity mechanisms, audit frameworks; Applied cryptography: correct use of asymmetric signatures, authenticated encryption, and verification chains (able to implement, review, and spot misuse); not expected to designprimitives; Threat modeling and secure design review experience. Linux Systems Engineering

Deep Linux internals: boot process (UEFI → bootloader → kernel → init), systemd, udev, initramfs; Building custom Linux images or distributions; kernel build and configuration; Expert-level bash and strong Python; C proficiency for systems work;A quality bar of idempotent, fail-loud, self-tested tooling. Streaming and Integration (Working Knowledge): Familiarity with video streaming protocols (RTSP/RTP) and device-integration standards such as ONVIF;Exposure to media frameworks (GStreamer, FFmpeg, or equivalent) and debugging protocol-level issues with packet captures; Codec-agnostic: we care about sound engineering, not any specific video format. Nice to Have

Anti-tamper and reverse-engineering-resistance techniques: encrypted payloads, secure loaders, self-integrity checks; Experience with air-gapped or no-update-channel deployment models and the operational discipline they require; Secure provisioning at scale or in manufacturing contexts; per-unit key management; Reproducible builds; supply-chain security awareness;VMS/NVR platform integration experience; Performance engineering: profiling, optimization of systems or media code; Singapore work eligibility. How We Work

Small team, high trust, high ownership; Architecture decisions are written down; invariants are documented and changes go through review; Quality and paper trail matter: our units ship to security-critical deployments where compromise response is measured in recalled hardware, not hotfixes.

Sourced from JobStreet · posted 8 days ago · you apply on the original site