Jobs

Open embedded Linux and product security roles at Embetrix.

Embedded Linux / Security Specialist

Remote · Full-time or contract · EU work permit and residency required

You design and harden the software stack of embedded Linux devices: from the boot ROM to the update client. Most of our projects involve secure boot, encrypted storage and keeping devices patchable in the field.

What you will work on

  • Secure boot chains: U-Boot, signed FIT images, dm-verity, measured boot
  • Yocto and Buildroot integration for customer hardware
  • Key storage and crypto hardware: TPM 2.0, HSMs, OP-TEE, PKCS#11
  • OTA updates with SWUpdate, RAUC and Eclipse hawkBit
  • System hardening and security reviews of existing devices

What we look for

  • Solid C/C++/Rust and shell, comfortable reading kernel and bootloader code
  • Hands-on Yocto experience: writing layers, recipes and classes
  • Working knowledge of applied cryptography: signatures, certificates, key handling
  • Clear written English; we work asynchronously with remote customers

Nice to have

  • Upstream contributions (kernel, U-Boot, Yocto layers)
  • Experience with EU Cyber Resilience Act or IEC 62443 requirements
Apply for this role

SecDevOps Engineer

Remote · Full-time or contract · EU work permit and residency required

You build and run the pipelines that turn source code into signed, traceable device images. Your job is to make secure releases boring: reproducible, automated and auditable.

What you will work on

  • CI/CD pipelines for Yocto builds on GitLab and GitHub Actions
  • SBOM generation, CVE scanning and vulnerability triage for device firmware
  • Release signing infrastructure and key management (PKI, HSM-backed signing)
  • Automated on-target testing with real hardware in the loop
  • Build caching, shared state and infrastructure as code

What we look for

  • Strong Python and shell scripting
  • Experience running CI/CD for large builds: containers, runners, caching
  • Familiarity with vulnerability management: CVE feeds, SBOM formats, patch tracking
  • Clear written English; we work asynchronously with remote customers

Nice to have

  • Yocto knowledge (cve-check, SPDX manifests)
  • Ansible or Terraform, self-hosted runner fleets
Apply for this role

No matching role?

If you work in embedded Linux or device security and think you would fit, send an open application with a short note on what you have built.