Job Summary
Own the hardware root-of-trust to application-layer security chain on ARM-based heterogeneous SoC platforms used in industrial, robotics and connected edge products. The role covers secure/measured boot bring-up, TrustZone and Trusted Execution Environment enablement, key and certificate management, and secure device provisioning in high-volume manufacturing.
Key Responsibilities
- Bring up and harden secure boot and measured boot chains across bootloaders, firmware and kernel on ARMv8-A/ARMv9 class SoCs.
- Design, port and maintain TEE solutions (OP-TEE or equivalent) including Trusted Applications, secure storage and secure world–normal world communication.
- Implement TrustZone-based isolation, secure memory partitioning and access control policies across CPU, DSP and accelerator subsystems.
- Define and implement device identity, key provisioning, fusing and certificate flows for factory and field provisioning at scale.
- Implement anti-rollback, debug lockdown, secure JTAG and lifecycle state management policies.
- Support cryptographic acceleration enablement (crypto engines, RNG/TRNG, PKCS#11 / Keystore backends).
- Contribute to threat modelling, security architecture reviews and vulnerability triage; support external security assessments and certification evidence.
- Work with silicon vendor security documentation and escalate platform-level security defects; mentor engineers on secure coding practices.
Skill Requirements
- 8–10 years of embedded systems engineering with at least 4 years focused on platform security.
- Strong C, with working ARM assembly and secure firmware debugging skills.
- Hands-on secure boot / measured boot bring-up on ARM SoCs — chain of trust, image signing, verified boot.
- Practical TrustZone and TEE experience: OP-TEE, GlobalPlatform TEE APIs, Trusted Application development.
- Applied cryptography fundamentals — AES, RSA/ECC, SHA, HMAC, key derivation, PKI and certificate chains.
- Bootloader internals (U-Boot / ABL / TF-A class), device tree and early-boot debug using JTAG and serial consoles.
- Understanding of secure provisioning in manufacturing — eFuse/OTP programming, HSM-backed signing infrastructure.
Other Requirements
- Exposure to Android Verified Boot, Keymaster/KeyMint, StrongBox or Windows-based secure boot flows.
- Familiarity with security standards and certification regimes such as IEC 62443, FIPS 140-3, SESIP or PSA Certified.
- Experience with hypervisor-assisted isolation and secure virtualization.
- Fuzzing, static analysis and secure SDLC tooling.