freehire launches on Product Hunt on 26 August.

Follow →

Senior Software Security Engineer

Summary

Design and implement secure boot, disk encryption, TPM-backed key management, and Linux hardening for appliance products, while contributing to a media streaming stack.

The Role

You will own the security architecture and secure-platform engineering of our appliance products: the trusted boot chain, disk and payload encryption, hardware-backed key management, attestation, OS hardening, and the build and provisioning systems that produce tamper-resistant units. The role also involves work on our media streaming stack and its integration with third-party platforms, but the center of gravity is software security — designing, implementing, and defending the mechanisms that keep our devices and our intellectual property protected in hostile environments.

What You Will Do

● Design and maintain the appliance trust architecture: UEFI Secure Boot key hierarchy and signing workflows, measured boot, and TPM-anchored secrets

● Work with TPM 2.0 in production: key creation and attributes, PCR measurement and policy, sealed storage, remote attestation(quotes, verification chains), and LUKS/Clevis disk-encryption binding

● Harden the Linux platform end to end: kernel configuration and lockdown, IMA appraisal policy, AppArmor confinement, sysctl and module-blacklist hardening, auditd, and systemd sandboxing

● Own the secure build pipeline: hardened kernel builds, signed OS image assembly, reproducibility practices, and cryptographic verification at every stage

● Implement applied-cryptography work flows correctly: signature schemes (RSA-PSS, OAEP), authenticated encryption(AES-GCM), canonical serialization for signed documents, key ceremonies, and key-compromise response

● Build verification in frastructure: QEMU/OVMF/swTPM-based boot testing, self-tests with negative controls, andfail-closed validation gates

● Contribute to threat modeling: define adversaries and trust boundaries, document what is in and out of scope, and defend architectural invariants through written decision records

● Develop and debug within our media streaming stack (RTSP, ONVIF, media pipelines) as product work requires

● Write operator-grade tooling (bash, Python, C)and the runbooks that go with it

Required Experience

Software and platform security (core of the role):

● 5+ years in security-focused systems engineering on Linux

● UEFI Secure Boot: key hierarchy (PK/KEK/db),image signing, enrollment workflows

● TPM 2.0 hands-on experience: key attributes, PCR policies, sealing, attestation concepts (EK, AK, quotes)

● Disk encryption in production: LUKS2,cryptsetup, TPM binding (Clevis or equivalent)

● Linux hardening: mandatory access control(AppArmor or SELinux), kernel lockdown, IMA/EVM or comparable integrity mechanisms, audit frameworks

● Applied cryptography: correct use of asymmetric signatures, authenticated encryption, and verification chains — able to implement, review, and spot misuse; not expected to design primitives

● Threat modeling and secure design review experience

Linux systems engineering:

● Deep Linux internals: boot process (UEFI →bootloader → kernel → init), systemd, udev, initramfs

● Building custom Linux images or distributions; kernel build and configuration

● Expert-level bash and strong Python; Cproficiency for systems work

● A quality bar of idempotent, fail-loud, self-tested tooling

Streaming and integration (working knowledge):

● Familiarity with video streaming protocols(RTSP/RTP) and device-integration standards such as ONVIF

● Exposure to media frameworks (GStreamer, FFmpeg, or equivalent) and debugging protocol-level issues with packet captures

● Codec-agnostic: we care about sound engineering, not any specific video format

Nice to Have

● Anti-tamper and reverse-engineering-resistance techniques: encrypted payloads, secure loaders, self-integrity checks

● Experience with air-gapped orno-update-channel deployment models and the operational discipline they require

● Secure provisioning at scale or in manufacturing contexts; per-unit key management

● Reproducible builds; supply-chain security awareness

● VMS/NVR platform integration experience

● Performance engineering: profiling, optimization of systems or media code

● Singapore work eligibility

How We Work

● Small team, high trust, high ownership

● Architecture decisions are written down; invariants are documented and changes go through review

● Quality and paper trail matter: our units ship to security-critical deployments where compromise response is measured in recalled hardware, not hotfixes

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available