Senior Software Security Engineer (Linux Appliances)
Bonifacio Global City, Metro ManilaPosted 8 days agoJobStreet
Skills mentioned
Members see a match score against their own skills and get a resume + cover letter written for this posting.
About the role
You will own the security architecture and secure-platform engineering of appliance products: the trusted boot chain, disk and payload encryption, hardware-backed key management, attestation, OS hardening, and the build and provisioning systems that produce tamper-resistant units. The role also involves work on media streaming stack and its integration with third-party platforms, but the center of gravity is software security — designing, implementing, and defending the mechanisms that keep devices and intellectual property protected in hostile environments.
Key responsibilities
Design and maintain the appliance trust architecture: UEFI Secure Boot key hierarchy and signing workflows, measured boot, and TPM-anchored secrets
Work with TPM 2.0 in production: key creation and attributes, PCR measurement and policy, sealed storage, remote attestation (quotes, verification chains), and LUKS/Clevis disk-encryption binding
- Harden the Linux platform end to end: kernel configuration and lockdown, IMA appraisal policy, App
- Armor confinement, sysctl and module-blacklist hardening, auditd, and systemd sandboxing
- Own the secure build pipeline: hardened kernel builds, signed OS image assembly, reproducibility practices, and cryptographic verification at every stage
Implement applied-cryptography workflows correctly: signature schemes (RSA-PSS, OAEP), authenticated encryption (AES-GCM), canonical serialization for signed documents, key ceremonies, and key-compromise response
Build verification infrastructure: QEMU/OVMF/swTPM-based boot testing, self-tests with negative controls, and fail-closed validation gates
Contribute to threat modeling: define adversaries and trust boundaries, document what is in and out of scope, and defend architectural invariants through written decision records
- Develop and debug within media streaming stack (RTSP, ONVIF, media pipelines) as product work requires
- Write operator-grade tooling (bash, Python, C) and the runbooks that go with it
Required Experience
Software and Platform Security (Core of the Role):5+ years in security-focused systems engineering on Linux;UEFI Secure Boot: key hierarchy (PK/KEK/db), image signing, enrollment workflows;TPM 2.0 hands-on experience: key attributes, PCR policies, sealing, attestation concepts (EK, AK, quotes); Disk encryption in production: LUKS2, cryptsetup, TPM binding (Clevis or equivalent); Linux hardening: mandatory access control (App
Armor or SELinux), kernel lockdown, IMA/EVM or comparable integrity mechanisms, audit frameworks; Applied cryptography: correct use of asymmetric signatures, authenticated encryption, and verification chains (able to implement, review, and spot misuse); not expected to designprimitives; Threat modeling and secure design review experience. Linux Systems Engineering
Deep Linux internals: boot process (UEFI → bootloader → kernel → init), systemd, udev, initramfs; Building custom Linux images or distributions; kernel build and configuration; Expert-level bash and strong Python; C proficiency for systems work;A quality bar of idempotent, fail-loud, self-tested tooling. Streaming and Integration (Working Knowledge): Familiarity with video streaming protocols (RTSP/RTP) and device-integration standards such as ONVIF;Exposure to media frameworks (GStreamer, FFmpeg, or equivalent) and debugging protocol-level issues with packet captures; Codec-agnostic: we care about sound engineering, not any specific video format. Nice to Have
Anti-tamper and reverse-engineering-resistance techniques: encrypted payloads, secure loaders, self-integrity checks; Experience with air-gapped or no-update-channel deployment models and the operational discipline they require; Secure provisioning at scale or in manufacturing contexts; per-unit key management; Reproducible builds; supply-chain security awareness;VMS/NVR platform integration experience; Performance engineering: profiling, optimization of systems or media code; Singapore work eligibility. How We Work
Small team, high trust, high ownership; Architecture decisions are written down; invariants are documented and changes go through review; Quality and paper trail matter: our units ship to security-critical deployments where compromise response is measured in recalled hardware, not hotfixes.
Sourced from JobStreet · posted 8 days ago · you apply on the original site