1

Linux Kernel Security Engineer Jobs (NOW HIRING)

Your work will help shape kernel reliability, security, performance, and support for a platform ... Proven experience as a Senior Software Engineer, Tech Lead, Team Lead, or similar technical ...

Showing results 41-60

Linux Kernel Security Engineer information

See salary details

$11K

$114.5K

$129.5K

How much do linux kernel security engineer jobs pay per year?

As of Sep 10, 2026, the average yearly pay for linux kernel security engineer in the United States is $114,500.00, according to ZipRecruiter salary data. Most workers in this role earn between $104,000.00 and $125,000.00 per year, depending on experience, location, and employer.

What does a Linux Kernel Security Engineer do?

A Linux Kernel Security Engineer is responsible for identifying, analyzing, and mitigating security vulnerabilities within the Linux kernel. They develop and implement security features, patch vulnerabilities, and work closely with developers to ensure the kernel remains secure against evolving threats. Additionally, they may review code, participate in security audits, and contribute to open source security initiatives. Their work is critical for maintaining the integrity and safety of systems that rely on the Linux operating system.

What are the key skills and qualifications needed to thrive as a Linux Kernel Security Engineer?

To thrive as a Linux Kernel Security Engineer, you need deep expertise in C programming, Linux kernel internals, security architecture, and typically a degree in computer science or a related field. Familiarity with tools like static analysis software, kernel debugging utilities (such as GDB or ftrace), and certifications like OSCP or CEH is highly valued. Strong analytical thinking, problem-solving abilities, and effective communication are essential soft skills that enable collaboration and clear documentation of vulnerabilities. These skills are crucial for identifying, addressing, and preventing security threats within complex kernel environments, ensuring robust system protection.

What are some common challenges faced by Linux Kernel Security Engineers when working with open-source communities?

Linux Kernel Security Engineers often collaborate with open-source communities to propose and implement security patches. A common challenge is ensuring code changes meet rigorous review standards and are accepted by upstream maintainers, which requires clear communication and thorough documentation. Additionally, balancing the need for robust security with system performance and compatibility is crucial. Engineers must also stay updated on evolving security threats and coordinate with global contributors to address vulnerabilities promptly.

What are popular job titles related to Linux Kernel Security Engineer jobs?

For Linux Kernel Security Engineer jobs, the most frequently searched job titles are:

Infographic showing various Linux Kernel Security Engineer job openings in the United States as of August 2026, with employment types broken down into 88% Full Time, 10% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $114,500 per year, or $55 per hour.

Embedded Linux Security Engineer

Foster City, CA โ€ข On-site

ALTEN Technology USA
Engineering Professional Servicesย โ€ขย 10K+ employees

$120K - $150K/yr

Full-time

Posted 28 days ago


Job description

Workplace: On-Site, 5 daysย 
Location: Foster City, CA

We are looking for an Embedded Linux Security Engineer to implement security solution to harden our next-generation embedded Linux platform. In this role, you will bridge the gap between low-level hardware security, kernel hardening, and secure user-space application containment. You will not only design cryptographic defense mechanisms but will also automate security pipelines in CI/CD and partner directly with manufacturing teams to ensure devices are provisioned securely and reliably at scale without production risks.

Responsibilitiesย 
ย  ย  Platform Hardening & Architecture: Design and implement the Hardware Root of Trust and Secure Boot architecture from the first-stage bootloader through the Linux kernel.
ย  ย  Storage & Integrity Management: Implement dm-verity for cryptographically verified read-only root filesystems and secure data encryption at rest.
ย  ย  Trusted Execution Environments: Develop, integrate, and maintain a TEE (e.g., OP-TEE) and author Secure/Trusted Applications (TAs).
ย  ย  Application Sandboxing: Enforce strict user-space isolation and sandboxing strategies using SELinux, AppArmor, cgroups, namespaces, and seccomp filters to protect core systems from untrusted applications.
ย  ย  DevSecOps Automation: Build automated cryptographic signing pipelines within CI/CD infrastructure (e.g., GitLab CI, GitHub Actions) to securely sign bootloaders, kernels, and OTA payloads using HSMs or secure key vaults.
ย  ย  Production Provisioning Support: Collaborate with manufacturing teams to write robust scripts and tools for burning permanent hardware configuration fuses (eFuses / OTP memory) securely, designing end-of-line (EOL) test software to validate security features before shipping.
ย  ย  System Resilience: Architect multi-slot boot recovery layouts (e.g., A/B partitioning) to guarantee fail-safe resilience against failed OTA updates or corrupted boots.

Required Qualificationsย 
ย  ย  Education: Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, or a related technical discipline (or equivalent practical experience).
ย  ย  Core Experience: 6+ years of professional experience in Embedded Linux development, board bring-up, and Board Support Package (BSP) customization.
ย  ย  Security Focus: 3+ years of dedicated, hands-on experience deploying device-level security features into physical production hardware.
ย  ย  Low-Level Systems: Expert knowledge of bootloader configurations (e.g., U-Boot Verified Boot, Barebox) and customizing the Linux kernel storage/security subsystem (dm-crypt, dm-verity).
ย  ย  Hardware Security Architecture: Deep understanding of modern processor security architectures, specifically ARM TrustZone (ARMv7-A / ARMv8-A, Exception Levels EL1-EL3).
ย  ย  Sandboxing & Access Controls: Proven track record implementing SELinux/AppArmor policies and utilizing standard Linux containment tools (cgroups, namespaces).
ย  ย  Build Automation: Proficiency with embedded Linux build automated frameworks like the Yocto Project (BitBake recipe design) or Buildroot.
ย  ย  Programming: Advanced proficiency in C and strong scripting skills in Python or Bash.

Preferred Qualificationsย 
ย  ย  Cryptography Expertise: Strong foundational knowledge of symmetric/asymmetric cryptography, hashing algorithms (SHA-256/384), public key infrastructure (PKI), and handling physical Hardware Security Modules (HSMs).
ย  ย  Manufacturing Scale: Prior experience working with Contract Manufacturers (CMs) or internal factory lines to deploy secure key-injection and fuse-burning protocols.
ย  ย  Advanced Sandboxing: Experience with embedded container runtimes (e.g., LXC, crun) or lightweight sandboxing frameworks tailored for resource-constrained architectures.
ย  ย  Anti-Rollback Protection: Experience designing secure versioning and hardware-enforced anti-rollback strategies for OTA updates.

Salary Range
ย  ย  $120,000 - 150,000
ย  ย  The actual salary offered is dependent on various factors including, but not limited to, location, the candidate's combination of job-related knowledge, qualifications, skills, education, training, and experienceย