Embedded Security Engineer
Indexed description
Eagle Wireless is a connectivity company delivering secure, reliable, and scalable cellular modules and solutions for automotive and IoT applications. With a strong presence in the United States and global R&D teams across North America, Europe, and APAC, Eagle Wireless supports customers worldwide with long-life, compliant, and cyber-secure connectivity products. Focused on trust, supply chain resilience, and regulatory compliance, Eagle Wireless helps OEMs, Tier 1 suppliers, and IoT innovators deploy connected technologies with confidence in an increasingly complex global environment.
We are looking for: Embedded Security Engineer
Job Summary:
We are seeking a skilled Security Engineer to join our R&D Automotive team, focused on the vulnerability-management lifecycle for our cellular module firmware. The ideal candidate has a strong background in embedded Linux and security analysis, and is comfortable taking a raw CVE or vendor bulletin and determining, with evidence, whether it's a real risk for our product, then driving the fix across the full stack, from Linux userspace down to baseband code.
Key Responsibilities:
- Perform scanning and analyze of CVE/OSS for firmware releases
- Maintain an accurate SBOM (software bill of materials) per product/release, covering open-source and proprietary vendor components.
- Analyze whether a CVE is actually reachable and exploitable in our configuration
- Write risk assessments and dispositions (affected / not affected / mitigated / fix planned) per product line and release for customers.
- Prioritize fixes based on severity, exploitability, and exposure; escalate critical remotely-exploitable issues immediately.
- Backport upstream fixes into our Yocto build
- Integrate Qualcomm security patches, TrustZone/QTEE, and bootloader trees; adapt patches that conflict with local modifications.
- Verify fixes end-to-end: rebuild affected images, run regression tests, and re-test proof-of-concept exploits where available.
- Maintain patch and disposition history per firmware release; feed fixes into release planning and release notes.
- Support customer security questionnaires, audits, and regulatory/certification needs (UNECE R155/CSMS, ISO/SAE 21434, carrier and RED/CRA requirements).
- Improve pipeline automation: CVE scanning in CI, SBOM generation, and alerting on new advisories affecting shipped versions.
Qualifications:
- Degree in Computer Science, Electrical Engineering, or a related field.
- 3+ years embedded Linux development, with strong C (and working C++) skills.
- Hands-on Yocto/OpenEmbedded experience: BitBake recipes, layers, .bbappend/patch workflow, devtool.
- Linux kernel patching experience: backporting fixes from mainline/LTS to a vendor kernel.
- Solid security fundamentals: vulnerability classes, CVSS scoring, threat modeling of embedded attack surfaces.
- Good troubleshooting instincts: comfortable with incomplete information, diagnosing on-target with serial console, gdb, and logs.
- Proficient with git/gerrit on large multi-repo codebases, cross-compilation, and debugging on embedded targets.
- Excellent written communication skills: able to produce clear, precise technical risk assessments for customers and auditors.
Strongly Preferred:
- Qualcomm platform experience: modem/baseband codebase structure (AMSS, Hexagon DSP), TrustZone/QTEE, secure boot chain, EFS/NV configuration.
- Cellular protocol knowledge (LTE/5G NAS/RRC, IMS/VoLTE, SIM/UICC).
- Experience with Qualcomm tooling (QXDM/QCAT log analysis, QFIL).
- SELinux policy, secure coding review, fuzzing, or penetration-testing experience.
- Familiarity with automotive/regulatory security frameworks: UNECE R155, Cyber Resilience Act, carrier security requirements.
Benefits:
- Competitive salary and performance-based bonuses.
- Opportunities for professional growth and development.
- Flexible working hours and remote work options.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search