Skip to content

Open nowPosted 55 days ago

Senior Embedded Linux Platform Engineer

Workable (global search)109,826 open roles

Where
Bulverde, TX, United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Embedded Linux Platform EngineerWorkable (global search) · Bulverde, TX, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 2 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 55 days ago

Workable (global search) median: 2 days open

The posting

Secure platform ownership for next-generation Hardware Security Modules

Position Summary

We are seeking a Senior Embedded Linux Platform Engineer to lead the development and maintenance of the embedded software platform powering our next-generation Hardware Security Modules (HSMs). This role bridges hardware and application software by owning the Linux platform, Board Support Package (BSP), security architecture, and hardware interfaces that enable our cryptographic applications.

The ideal candidate has deep experience with embedded Linux, Buildroot, kernel and device-tree configuration, low-level hardware interfaces, secure boot, PCIe, and high-speed networking. The engineer will collaborate closely with hardware, FPGA, security, manufacturing, and application teams to deliver a secure, reliable, production-ready appliance.

Responsibilities

Embedded Linux Platform

  • Develop, maintain, and reproducibly build a Buildroot-based Linux distribution.
  • Customize and maintain Linux kernels for selected System-on-Modules (SoMs).
  • Configure and maintain device trees and board-specific platform definitions.
  • Build and maintain BSPs for custom HSM hardware and successive board revisions.
  • Integrate kernel drivers, platform services, bootloaders, and root filesystems.
  • Optimize boot performance, system footprint, reliability, and maintainability.
  • Support production images, manufacturing configuration, and secure update mechanisms.

Hardware Integration

  • Bring platform hardware into Linux and expose clean, documented interfaces to application software.
  • Integrate and validate I²C, SPI, GPIO, UART, USB, PCIe, EEPROM/flash, and other board-level interfaces.
  • Enable sensors, fan controllers, LEDs, buttons, watchdogs, voltage monitors, reset controls, TPMs, and secure elements.
  • Develop or adapt kernel drivers and user-space services where existing interfaces are insufficient.
  • Use schematics, datasheets, oscilloscopes, logic analyzers, and other tools to diagnose board-level issues.

Security

  • Design, implement, maintain, and validate secure boot and the complete chain of trust.
  • Configure and integrate hardware roots of trust, TPMs, secure elements, and measured-boot capabilities where appropriate.
  • Recommend secure component choices and platform architectures based on threat, lifecycle, and supply-chain considerations.
  • Review hardware and low-level software designs for security weaknesses and attack surface.
  • Support tamper detection, encrypted storage, key protection, secure manufacturing, and device provisioning.
  • Define and support secure firmware and software update strategies, including rollback protection and recovery.

Networking

  • Integrate and support 10 GbE connectivity through PCIe-connected network devices and external Ethernet interfaces.
  • Configure Ethernet controllers, PHYs, drivers, link behavior, and relevant hardware offload features.
  • Tune the Linux networking stack for throughput, latency, reliability, and predictable appliance behavior.
  • Diagnose performance bottlenecks across PCIe, DMA, interrupts, drivers, and the network stack.

Platform Enablement

  • Lead bring-up of new SoMs, custom boards, and hardware revisions from first power-on through application readiness.
  • Create platform diagnostics, hardware validation utilities, and manufacturing test support.
  • Establish automated, repeatable build and integration workflows for embedded platform releases.
  • Support production, quality, field engineering, and sustaining activities throughout the product lifecycle.
  • Document platform architecture, interfaces, security assumptions, build procedures, and operational constraints.

Requirements

Required Qualifications

  • Bachelor’s or Master’s degree in Computer Engineering, Electrical Engineering, Computer Science, or a related field, or equivalent practical experience.
  • Five or more years of professional experience developing embedded Linux systems.
  • Strong C programming and debugging skills in resource-constrained or hardware-adjacent environments.
  • Hands-on experience with Buildroot or Yocto, Linux kernel configuration, device trees, and cross-compilation toolchains.
  • Practical knowledge of the Linux boot process, bootloaders such as U-Boot, root filesystems, kernel modules, and driver integration.
  • Experience collaborating across hardware, systems, security, and application engineering disciplines.
  • Proficiency with Git and disciplined software configuration-management practices.

Required Technical Experience

Embedded Linux

  • Buildroot or Yocto; Linux kernel configuration and customization; device trees; bootloaders; init systems; root filesystems; kernel modules; BSP and driver integration.

Hardware Interfaces

  • Hands-on experience with several of the following: I²C, SPI, UART, GPIO, PCIe, USB, MDIO, Ethernet PHYs, DMA, and interrupts.

Networking

  • Linux networking stack, Ethernet drivers, 10 GbE, PCIe-connected networking, and network performance analysis or tuning.

Platform Security

  • Experience with one or more of the following: secure boot, measured boot, TPMs, secure elements, trusted execution, hardware roots of trust, secure updates, or applied cryptography fundamentals.

Preferred Qualifications

  • Experience developing security appliances, HSMs, cryptographic products, or other high-assurance embedded systems.
  • Familiarity with FIPS 140-3, Common Criteria, or comparable product-security certification environments.
  • ARM64 platform experience and familiarity with SoMs from NXP, AMD, Intel, TI, or similar vendors.
  • Linux kernel or PCIe driver development experience.
  • Experience reviewing schematics and conducting hands-on hardware debugging.
  • Experience with manufacturing diagnostics, secure provisioning, lifecycle controls, and field-update strategies.

Nice to Have

  • OpenSSL, PKCS #11, secure key storage, or related cryptographic interfaces.
  • Trusted Firmware-A, OP-TEE, trusted execution environments, or hardware-backed attestation.
  • Rust for systems programming.
  • CI/CD practices for embedded systems and reproducible, containerized build environments.
  • Experience with performance profiling, reliability testing, or fault-injection techniques.

What Success Looks Like

  • New hardware platforms boot reliably and can be brought to application readiness through a repeatable, documented process.
  • All required peripherals and control signals are exposed through stable, well-documented Linux interfaces.
  • Secure boot and the platform root of trust are implemented, validated, maintainable, and aligned with product-security goals.
  • 10 GbE and external Ethernet interfaces achieve expected throughput, latency, and reliability.
  • Builds are reproducible, version-controlled, automated, and suitable for manufacturing and field release.
  • Platform risks are identified early, communicated clearly, and addressed in partnership with hardware and security teams.
  • The embedded platform provides a stable, secure foundation that allows HSM application teams to deliver confidently.

Benefits

  • Health, dental, vision, life, and short/long-term disability insurance
  • Paid vacation, holidays, and sick leave
  • Competitive compensation and opportunities for advancement
  • Retirement plan with employer contribution match
  • Welcoming, family-style corporate culture uniquely suited to fast-paced, entrepreneurial, and motivated individuals
  • One of San Antonio’s “Best Places to Work” for nine consecutive years
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.