Jobs · Information Technology · Georgia

Embedded Linux Security Engineer (Kernel/Bootloader / Ramdisk)

Accord Technologies Inc · Atlanta, GA · 6 mo ago
On-siteInformation TechnologyFull-time

Vulnerability Assessment & CVE Remediation

Identify, analyze, and triage CVEs impacting the Xilinx Linux kernel, ramdisk packages, U-Boot, and embedded software stack using NVD, AMD/Xilinx Security Bulletins, and OSS tooling. Apply kernel patches, backport security fixes from upstream LTS kernels (e.g., 5.x LTS, Xilinx downstream), or implement mitigation workarounds. Patch vulnerabilities in U-Boot, kernel modules, device drivers, and user-space packages (BusyBox, OpenSSL, etc.) — primarily focused on version upgrades and CVE-specific patches. Maintain detailed documentation of vulnerabilities, root cause analysis, mitigation steps, patch sources, and validation results. Track and report CVE remediation progress to stakeholders and external auditors.

Buildroot-Based Embedded Linux System Maintenance

Configure, customize, and maintain the Buildroot build environment used to compile U-Boot, Linux kernel, and ramdisk/root filesystem images. Ensure secure configuration of Buildroot-generated packages, system services, and network daemons. Optimize build configurations for minimal attack surface and reduced package footprint. Manage cross-compilation toolchains, package dependencies, and library versions.

Secure Boot & Firmware Hardening

Implement and validate secure boot mechanisms on Zynq platforms using Xilinx PetaLinux / Vitis toolchain. Harden the Linux OS, kernel configuration (kconfig), and boot chain against common attack vectors. Implement kernel module signing and enforce boot chain integrity.

Required Skills & Experience

  • Strong hands-on experience with Linux kernel patching, including CVE remediation, patch backporting, and diff/patch workflows.
  • Deep knowledge of Buildroot build systems — package configuration, filesystem generation, and toolchain management.
  • Expertise in U-Boot bootloader configuration, customization, secure boot implementation, and boot chain hardening.
  • Proficiency in Embedded Linux development for ARM platforms, specifically Xilinx Zynq or similar SoCs.
  • Familiarity with Xilinx-specific kernel and bootloader repositories; experience with PetaLinux or Vitis toolchain is a strong plus.
  • Solid understanding of cross-compilation toolchains (gcc-arm, Buildroot toolchain, Yocto SDK).
  • Kernel debugging skills using JTAG, GDB, kernel logs, and tracing tools.
  • Knowledge of the target Linux kernel version family (Xilinx downstream / LTS 5.x or later).
  • Security & Vulnerability Management Skills: Proven experience in CVE analysis, CVSS scoring, vulnerability triage, and remediation prioritization. Familiarity with vulnerability databases and tools: NVD, AMD/Xilinx Security Bulletins, Trivy, or similar. Knowledge of secure boot mechanisms and kernel module signing. Experience hardening embedded Linux OS configurations.
  • Programming & Scripting Skills: Proficiency in C for kernel module development, patching, low-level debugging, and userspace-kernel interaction. Shell scripting (Bash) for build automation and patch workflows.

Similar jobs

Embedded Linux Engineer

Anduril IndustriesSeattle, WA· 1 mo ago
Information Technology$166k–$220k/yrapply on boards.greenhouse.io

Embedded Linux Engineer

Santcore TechnologiesPalo Alto, CA· 1 wk ago
Information Technologyapply on candidateportal.ceipal.com

Embedded Linux Engineer

Anduril IndustriesCosta Mesa, CA· 1 mo ago
Information Technology$166k–$220k/yrapply on boards.greenhouse.io