Senior Software Security Engineer
Summary
Design and implement secure boot, disk encryption, TPM-backed key management, and Linux hardening for appliance products, while contributing to a media streaming stack.
The Role
You will own the security architecture and secure-platform engineering of our appliance products: the trusted boot chain, disk and payload encryption, hardware-backed key management, attestation, OS hardening, and the build and provisioning systems that produce tamper-resistant units. The role also involves work on our media streaming stack and its integration with third-party platforms, but the center of gravity is software security — designing, implementing, and defending the mechanisms that keep our devices and our intellectual property protected in hostile environments.
What You Will Do
● Design and maintain the appliance trust architecture: UEFI Secure Boot key hierarchy and signing workflows, measured boot, and TPM-anchored secrets
● Work with TPM 2.0 in production: key creation and attributes, PCR measurement and policy, sealed storage, remote attestation(quotes, verification chains), and LUKS/Clevis disk-encryption binding
● Harden the Linux platform end to end: kernel configuration and lockdown, IMA appraisal policy, AppArmor confinement, sysctl and module-blacklist hardening, auditd, and systemd sandboxing
● Own the secure build pipeline: hardened kernel builds, signed OS image assembly, reproducibility practices, and cryptographic verification at every stage
● Implement applied-cryptography work flows correctly: signature schemes (RSA-PSS, OAEP), authenticated encryption(AES-GCM), canonical serialization for signed documents, key ceremonies, and key-compromise response
● Build verification in frastructure: QEMU/OVMF/swTPM-based boot testing, self-tests with negative controls, andfail-closed validation gates
● Contribute to threat modeling: define adversaries and trust boundaries, document what is in and out of scope, and defend architectural invariants through written decision records
● Develop and debug within our media streaming stack (RTSP, ONVIF, media pipelines) as product work requires
● Write operator-grade tooling (bash, Python, C)and the runbooks that go with it
Required Experience
Software and platform security (core of the role):
● 5+ years in security-focused systems engineering on Linux
● UEFI Secure Boot: key hierarchy (PK/KEK/db),image signing, enrollment workflows
● TPM 2.0 hands-on experience: key attributes, PCR policies, sealing, attestation concepts (EK, AK, quotes)
● Disk encryption in production: LUKS2,cryptsetup, TPM binding (Clevis or equivalent)
● Linux hardening: mandatory access control(AppArmor or SELinux), kernel lockdown, IMA/EVM or comparable integrity mechanisms, audit frameworks
● Applied cryptography: correct use of asymmetric signatures, authenticated encryption, and verification chains — able to implement, review, and spot misuse; not expected to design primitives
● Threat modeling and secure design review experience
Linux systems engineering:
● Deep Linux internals: boot process (UEFI →bootloader → kernel → init), systemd, udev, initramfs
● Building custom Linux images or distributions; kernel build and configuration
● Expert-level bash and strong Python; Cproficiency for systems work
● A quality bar of idempotent, fail-loud, self-tested tooling
Streaming and integration (working knowledge):
● Familiarity with video streaming protocols(RTSP/RTP) and device-integration standards such as ONVIF
● Exposure to media frameworks (GStreamer, FFmpeg, or equivalent) and debugging protocol-level issues with packet captures
● Codec-agnostic: we care about sound engineering, not any specific video format
Nice to Have
● Anti-tamper and reverse-engineering-resistance techniques: encrypted payloads, secure loaders, self-integrity checks
● Experience with air-gapped orno-update-channel deployment models and the operational discipline they require
● Secure provisioning at scale or in manufacturing contexts; per-unit key management
● Reproducible builds; supply-chain security awareness
● VMS/NVR platform integration experience
● Performance engineering: profiling, optimization of systems or media code
● Singapore work eligibility
How We Work
● Small team, high trust, high ownership
● Architecture decisions are written down; invariants are documented and changes go through review
● Quality and paper trail matter: our units ship to security-critical deployments where compromise response is measured in recalled hardware, not hotfixes