Job Description
Senior Embedded Platform Security Engineer
Pune, India | Hybrid | Full-Time Employment
L4B Software | Headquartered in Munich, Germany
Secure the platform from the first stage of boot to the services running on top of it.
Before You Apply
This is a hands-on embedded platform security engineering role.
We are looking for engineers who have worked deep within Embedded Linux and/or Android/AOSP platforms, where security involves the boot chain, kernel, BSP, trusted execution, storage, key management, hardware security, and system-level integration.
This is not primarily an application-security, SOC, GRC, audit, or cybersecurity-compliance role.
Work Model: Hybrid – Pune
This is not a fully remote position.
Candidates who can join immediately or within a shorter notice period will be preferred.
About L4B Software
L4B Software is an embedded software and platform-engineering company headquartered in Munich, Germany, with an engineering presence in Pune, India.
We design, customize, integrate, secure, and maintain operating-system platforms based on technologies such as Embedded Linux and Android/AOSP, tailored to the hardware, security requirements, product architecture, and lifecycle needs of our customers.
Our engineering capabilities span:
Customized Embedded Linux | Android/AOSP | BSP & Platform Integration | Platform Cybersecurity | DevOps | System Validation
We support demanding and long-lifecycle products across medical technology, automotive, industrial systems, and other embedded environments where security, reliability, and maintainability are fundamental engineering requirements.
Our engineers work deep within the platform—from bootloader and BSP integration through OS customization, cybersecurity, system services, deployment infrastructure, and validation.
About the Role
We are looking for a Senior Embedded Platform Security Engineer who can turn platform-security architecture into a working, secure, testable embedded implementation.
You will work across the security chain:
Hardware Root of Trust Bootloader Secure/Verified Boot Kernel TEE Secure Storage Android/Linux Platform System Services
This means understanding not only how individual security mechanisms work, but how they interact across the complete embedded platform.
When those layers don't behave as expected, you should be comfortable going deep enough into the BSP, bootloader, kernel, Device Tree, TEE, security firmware, and userspace to understand why.
What You'll Do
- Design, implement, and review security architecture for customized Embedded Linux and Android/AOSP platforms.
- Integrate and troubleshoot Secure Boot, Verified Boot, and chain-of-trust mechanisms from early boot through bootloader, kernel, and operating system.
- Implement storage and filesystem-security mechanisms including dm-crypt, dm-verity, fs-verity, LUKS, encrypted partitions, and authenticated system images.
- Integrate Trusted Execution Environments and hardware-backed security mechanisms using technologies such as ARM TrustZone and OP-TEE.
- Work with secure key provisioning, hardware-backed key storage, secure storage, RPMB, cryptographic accelerators, and hardware root-of-trust mechanisms.
- Implement and troubleshoot Android platform-security mechanisms including Android Verified Boot (AVB), File-Based Encryption, KeyMint/Keymaster, hardware-backed Keystore, SELinux, and rollback protection.
- Analyze interactions between the bootloader, Linux kernel, Device Tree, BSP, security firmware, TEE, and OS security services.
- Debug low-level security-integration issues using boot logs, kernel traces, source-code analysis, and SoC/platform documentation.
- Review Linux kernel and userspace configurations for hardening opportunities and unnecessary attack surface.
- Apply Linux security mechanisms including capabilities, namespaces, seccomp, SELinux, AppArmor, and other Linux Security Modules, where appropriate.
- Investigate vulnerabilities and support CVE triage and remediation across kernel, BSP, system libraries, and platform components.
- Support SBOM, SCA, static analysis, fuzzing, and security-verification activities.
- Perform threat modelling and translate identified threats into concrete technical controls and verification criteria.
- Work with platform, validation, cybersecurity, and quality teams to translate security requirements into implementation, tests, and engineering evidence.
What You Bring
We're looking for someone with strong hands-on experience at the embedded platform level.
Core Experience
- Strong professional experience developing, integrating, or securing Embedded Linux products or platforms.
- Hands-on Linux security experience at kernel, BSP, and system level.
- Android/AOSP platform-security experience, beyond Android application security.
- Strong understanding of embedded boot flows—from hardware root of trust and bootloader through kernel and userspace.
- Practical experience implementing or debugging Secure Boot, Verified Boot, or comparable chain-of-trust mechanisms.
- Hands-on experience with dm-crypt, dm-verity, or comparable Linux storage/integrity technologies.
- Experience with ARM TrustZone, OP-TEE, or another Trusted Execution Environment.
- Understanding of hardware-backed key management, secure storage, and cryptographic services.
- Experience working with ARM-based embedded SoCs and vendor-specific platform-security mechanisms.
- Strong Embedded Linux build-system knowledge, ideally Yocto Project, OpenEmbedded, and BitBake.
- Strong C/C++ understanding with the ability to investigate security problems at source-code level.
- Ability to work across bootloader, kernel, BSP, Device Tree, TEE, and userspace boundaries.
- Experience investigating and remediating vulnerabilities in low-level platform components.
- Ability to interpret SoC, security, and platform documentation and turn it into working implementations.
- Strong debugging and root-cause-analysis capability.
Product Security Engineering
Strong platform security also requires understanding why a technical control exists and what risk it addresses.
You should be comfortable connecting low-level engineering with broader product-security activities such as:
Threat Modelling | Attack-Surface Analysis | Vulnerability Management | CVE Remediation | SBOM/SCA | Security Requirements | Security Verification | Secure Development Lifecycle
Experience applying IEC 62443, IEC 81001-5-1, or comparable product-cybersecurity frameworks is valuable, particularly where cybersecurity requirements need to become concrete engineering controls, tests, and evidence.
Experience We'd Especially Value
You don't need to tick every box. Relevant depth in several of these areas would make your profile particularly interesting:
- Multiple ARM-based SoC families or vendor BSPs
- Deep Android BSP / AOSP platform development
- BSP bring-up and Device Tree
- Linux kernel configuration, hardening, and debugging
- U-Boot or UEFI
- TPM 2.0
- Secure elements
- Device-identity provisioning
- Secure OTA and firmware-update architecture
- PKI and certificate management
- Manufacturing/device provisioning flows
- Static analysis and fuzzing
- Security testing / penetration testing of embedded platforms
- IEC 62443
- IEC 81001-5-1
- IEC 62304 or comparable regulated-development environments
- Automotive or medical-device cybersecurity
- Safety-critical, mission-critical, or long-lifecycle products
You Might Be a Great Fit If...
You don't stop at:
Secure Boot is enabled.
You want to understand the complete chain of trust, how keys are provisioned, what is verified, where trust originates, what happens during an update, how rollback is prevented, and what happens when verification fails.
If Android reports a security problem, you're comfortable investigating whether the cause actually sits in AVB, SELinux, KeyMint, the TEE, BSP, kernel, bootloader, or SoC configuration.
You can read platform documentation, inspect source code and logs, talk to BSP and AOSP engineers, and turn a security architecture diagram into something that actually works on target hardware.
What This Role Is Not
This is not primarily:
- Android application development using Kotlin/Java
- Web or mobile application security
- SOC/SIEM operations
- GRC or cybersecurity compliance
- Security auditing
- Pure vulnerability management
- Policy-only cybersecurity
You also don't need to spend your entire role writing device drivers.
But you must be technically comfortable going deep enough into the bootloader, BSP, kernel, Device Tree, TEE, and hardware-security architecture to solve platform-security integration problems.
What Success Looks Like
You can take a platform-security requirement and carry it through:
Architecture Implementation Integration Debugging Verification
Security mechanisms don't merely exist in documentation—they are correctly implemented, integrated with the target hardware, testable, maintainable, and supported by engineering evidence.
You become someone the engineering team can rely on when a security problem crosses the boundaries between hardware, bootloader, BSP, kernel, TEE, Android/Linux, and system services.
Why Join L4B?
This role gives you the opportunity to work on cybersecurity where it becomes part of the platform itself.
You'll work alongside engineers building customized Embedded Linux and Android/AOSP platforms, rather than operating only at the application or policy layer.
You'll solve problems involving real hardware, SoCs, boot chains, kernels, trusted execution, cryptography, platform integration, and long-term product security.
For an engineer who enjoys understanding systems deeply and turning security architecture into working embedded technology, this is the kind of role where that depth matters.
Our Hiring Approach
We hire for technical depth, relevant hands-on experience, problem-solving ability, and demonstrated engineering ownership.
You don't need to match every technology listed above. If you have strong low-level Embedded Linux/platform-security experience and can demonstrate the ability to solve security problems across system boundaries, we'd like to hear from you.
Equivalent practical experience is welcome where a formal degree isn't essential to the work.
Pune | Hybrid | Full-Time Employment
Fast joiners will be preferred.