1

Embedded Systems Security Researcher Jobs (NOW HIRING)

Be Seen First

Both Contract and Fulltime available We are looking for an Embedded Systems Security Engineer to implement security solution to harden our next-generation embedded Linux platform. In this role, you ...

Be Seen First

Both Contract and Fulltime available We are looking for an Embedded Systems Security Engineer to implement security solution to harden our next-generation embedded Linux platform. In this role, you ...

Participation in security research, CTFs, or hardware/firmware projects * Internship or academic project experience related to embedded systems or firmware development Some Of The Extras That Make ...

next page

Showing results 1-20

Embedded Systems Security Researcher information

See salary details

$62.5K

$137.3K

$192K

How much do embedded systems security researcher jobs pay per year?

As of Sep 9, 2026, the average yearly pay for embedded systems security researcher in the United States is $137,274.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,500.00 and $163,500.00 per year, depending on experience, location, and employer.

What does an embedded systems security researcher do?

An Embedded Systems Security Researcher focuses on identifying, analyzing, and mitigating security vulnerabilities within embedded devices such as IoT gadgets, medical devices, automotive systems, and industrial controllers. They perform tasks like reverse engineering firmware, penetration testing, and developing security patches to protect these systems from cyber threats. Their work is essential in ensuring that embedded devices, which often have limited resources and connectivity to critical infrastructure, remain secure against evolving attacks.

What are the key skills and qualifications needed to thrive as an embedded systems security researcher?

To thrive as an Embedded Systems Security Researcher, you need a strong background in computer science, cybersecurity, and embedded systems engineering, often supported by a relevant degree or certifications like CISSP or CEH. Familiarity with tools such as IDA Pro, Ghidra, JTAG debuggers, and various embedded operating systems is crucial for analyzing and securing devices. Analytical thinking, attention to detail, and effective communication stand out as vital soft skills for presenting findings and collaborating with teams. These skills are essential to identify vulnerabilities, propose robust solutions, and ensure the security of embedded devices in increasingly interconnected environments.

What are some common challenges faced by embedded systems security researchers when analyzing device vulnerabilities?

Embedded Systems Security Researchers often encounter challenges such as limited device documentation, proprietary firmware, and restricted debugging interfaces, which can make reverse engineering and vulnerability analysis more complex. Additionally, embedded devices frequently use custom hardware and software combinations, requiring adaptability and deep technical knowledge. Collaboration with hardware engineers and software developers is common, as understanding the full system context is essential for effective security assessment and mitigation.

What are popular job titles related to Embedded Systems Security Researcher jobs?

For Embedded Systems Security Researcher jobs, the most frequently searched job titles are:

Infographic showing various Embedded Systems Security Researcher job openings in the United States as of September 2026, with employment types broken down into 83% Full Time, and 17% Contract. Highlights an 83% In-person, and 17% Remote job distribution, with an average salary of $137,274 per year, or $66 per hour.

Embedded Systems Security Engineer

Foster City, CA โ€ข On-site

Full-time

Posted 16 days ago


Job description

Embedded Systems Security Engineer

Onsite in Foster City, CA | 5 days in office
 
We are looking for an Embedded Systems Security Engineer to implement security solution to harden our next-generation embedded Linux platform. In this role, you will bridge the gap between low-level hardware security, kernel hardening, and secure user-space application containment. You will not only design cryptographic defense mechanisms but will also automate security pipelines in CI/CD and partner directly with manufacturing teams to ensure devices are provisioned securely and reliably at scale without production risks.
Roles & Responsibilities:
  • Platform Hardening & Architecture: Design and implement the Hardware Root of Trust and Secure Boot architecture from the first-stage bootloader through the Linux kernel.
  • Storage & Integrity Management: Implement dm-verity for cryptographically verified read-only root filesystems and secure data encryption at rest.
  • Trusted Execution Environments: Develop, integrate, and maintain a TEE (e.g., OP-TEE) and author Secure/Trusted Applications (TAs).
  • Application Sandboxing: Enforce strict user-space isolation and sandboxing strategies using SELinux, AppArmor, cgroups, namespaces, and seccomp filters to protect core systems from untrusted applications.
  • DevSecOps Automation: Build automated cryptographic signing pipelines within CI/CD infrastructure (e.g., GitLab CI, GitHub Actions) to securely sign bootloaders, kernels, and OTA payloads using HSMs or secure key vaults.
  • Production Provisioning Support: Collaborate with manufacturing teams to write robust scripts and tools for burning permanent hardware configuration fuses (eFuses / OTP memory) securely, designing end-of-line (EOL) test software to validate security features before shipping.
  • System Resilience: Architect multi-slot boot recovery layouts (e.g., A/B partitioning) to guarantee fail-safe resilience against failed OTA updates or corrupted boots.

Qualifications:
  • Education: Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical discipline (or equivalent practical experience).
  • Core Experience: 6+ years of professional experience in Embedded Linux development, board bring-up, and Board Support Package (BSP) customization.
  • Security Focus: 3+ years of dedicated, hands-on experience deploying device-level security features into physical production hardware.
  • Low-Level Systems: Expert knowledge of bootloader configurations (e.g., U-Boot Verified Boot, Barebox) and customizing the Linux kernel storage/security subsystem (dm-crypt, dm-verity).
  • Hardware Security Architecture: Deep understanding of modern processor security architectures, specifically ARM TrustZone (ARMv7-A / ARMv8-A, Exception Levels EL1–EL3).
  • Sandboxing & Access Controls: Proven track record implementing SELinux/AppArmor policies and utilizing standard Linux containment tools (cgroups, namespaces).
  • Build Automation: Proficiency with embedded Linux build automated frameworks like the Yocto Project (BitBake recipe design) or Buildroot.
  • Programming: Advanced proficiency in C and strong scripting skills in Python or Bash.

Preferred Qualifications:
  • Cryptography Expertise: Strong foundational knowledge of symmetric/asymmetric cryptography, hashing algorithms (SHA-256/384), public key infrastructure (PKI), and handling physical Hardware Security Modules (HSMs).
  • Manufacturing Scale: Prior experience working with Contract Manufacturers (CMs) or internal factory lines to deploy secure key-injection and fuse-burning protocols.
  • Advanced Sandboxing: Experience with embedded container runtimes (e.g., LXC, crun) or lightweight sandboxing frameworks tailored for resource-constrained architectures.
  • Anti-Rollback Protection: Experience designing secure versioning and hardware-enforced anti-rollback strategies for OTA updates.