Senior Embedded Product Cybersecurity Engineer

  • Belgrade, Belgrade, Serbia
  • Cybersecurity
  • Full-Time
  • Remote

Job Description:

Senior Embedded Product Cybersecurity Engineer

Belgrade, Serbia | Remote | Full-Time Employment
L4B Software | Headquartered in Munich, Germany

Build cybersecurity into the product — from threat modelling and security architecture to secure implementation and verification.

Before You Apply

This is a full-time employment opportunity. We are not considering B2B, freelance, consulting, or independent-contractor arrangements for this position.

This is a hands-on Embedded Product Cybersecurity engineering role.

We are looking for engineers who can connect product-level cybersecurity with implementation deep within Embedded Linux and Android/AOSP platforms, including BSP, bootloader, Secure Boot, kernel security, TEE/TrustZone, secure storage, key management, SELinux, and hardware-backed security.

This is not an application-level cybersecurity role. Profiles focused primarily on web/application security, Android application security, mobile-app penetration testing, SOC/SIEM, GRC, audit, or compliance do not match the core requirements of this position.

About L4B Software

L4B Software is an embedded software and platform-engineering company headquartered in Munich, Germany, with an engineering presence in Pune, India.

We design, customize, integrate, secure, and maintain operating-system platforms based on technologies such as Embedded Linux and Android/AOSP, tailored to the hardware, security requirements, product architecture, and lifecycle needs of our customers.

Our engineering capabilities span:

Customized Embedded Linux | Android/AOSP | BSP & Platform Integration | Product Cybersecurity | DevOps | System Validation

We support demanding and long-lifecycle products across medical technology, automotive, industrial systems, and other embedded environments where security, reliability, and maintainability are fundamental engineering requirements.

About the Role

We are looking for a Senior Embedded Product Cybersecurity Engineer who can translate cybersecurity risks and requirements into working technical controls within embedded products and platforms.

You will work across both Product Cybersecurity and low-level platform security — from threat modelling and security architecture through implementation, integration, vulnerability remediation, and security verification.

You should be comfortable moving across:

Threat Risk Security Requirement Architecture Technical Control Implementation Verification

and technically across:

SoC Bootloader BSP Kernel TEE Embedded Linux / Android Platform System Services

This is a role for someone who understands not only what needs to be secured, but how to engineer it into the product.

What You'll Do

  • Perform threat modelling, attack-surface analysis, and product cybersecurity risk analysis.
  • Translate identified threats and cybersecurity objectives into technical security requirements, architecture, and engineering controls.
  • Design, implement, and review security mechanisms for Embedded Linux and Android/AOSP platforms.
  • Integrate and troubleshoot Secure Boot, Verified Boot, and chain-of-trust mechanisms across hardware, bootloader, kernel, and operating system.
  • Work with TEE/ARM TrustZone, secure storage, hardware-backed key management, RPMB, cryptographic services, and root-of-trust mechanisms.
  • Implement and troubleshoot Linux and Android platform-security mechanisms such as dm-crypt, dm-verity, fs-verity, AVB, File-Based Encryption, KeyMint/Keymaster, SELinux, and rollback protection.
  • Review kernel, BSP, and userspace configurations for security weaknesses, hardening opportunities, and unnecessary attack surface.
  • Investigate security issues across SoC, bootloader, BSP, Device Tree, kernel, TEE, security firmware, and userspace.
  • Support vulnerability management including CVE analysis, impact assessment, remediation, and verification, as well as SBOM/SCA and other security-analysis activities.
  • Work with platform, validation, software, and quality teams to ensure cybersecurity requirements are correctly implemented, tested, and supported by engineering evidence.

What You Bring

  • Strong professional experience in Embedded Product Cybersecurity, embedded platform security, or security engineering for embedded/connected products.
  • Strong hands-on experience with Embedded Linux security at platform, BSP, system, and/or kernel level.
  • Good understanding of product cybersecurity activities including threat modelling, attack-surface analysis, security requirements, vulnerability management, and security verification.
  • Strong understanding of embedded boot flows and hardware root-of-trust / chain-of-trust concepts.
  • Practical experience implementing or debugging Secure Boot, Verified Boot, or comparable security mechanisms.
  • Experience with ARM TrustZone, OP-TEE, or another Trusted Execution Environment.
  • Understanding of hardware-backed key management, secure storage, and cryptographic services.
  • Experience working with ARM-based embedded SoCs and vendor BSPs.
  • Embedded Linux build-system experience, ideally Yocto Project, OpenEmbedded, and BitBake.
  • Strong C/C++ understanding with the ability to investigate platform-security issues at source-code level.
  • Experience with vulnerability analysis and remediation of low-level platform components.
  • Strong debugging and root-cause-analysis skills across multiple system layers.

Android/AOSP Platform Security

Hands-on Android/AOSP platform-security experience is highly valuable, particularly with:

Android Verified Boot (AVB) | File-Based Encryption | KeyMint/Keymaster | Hardware-backed Keystore | SELinux | TEE Integration | Secure Storage | Rollback Protection | Android Boot-Chain Security

We are looking for platform-level Android security experience — not Android application security.

Technical Experience We Value

Relevant depth across several of these areas would be particularly valuable:

Secure Boot / Verified Boot | U-Boot / UEFI | Yocto | BSP Security | ARM TrustZone / OP-TEE | Kernel Hardening | dm-crypt / LUKS | dm-verity / fs-verity | SELinux / AppArmor | TPM / RPMB / Secure Elements | Secure Key Provisioning | Secure OTA / Firmware Updates | SBOM / SCA | Static Analysis | Fuzzing

Experience with product-cybersecurity standards or regulated environments such as IEC 62443, IEC 81001-5-1, IEC 62304, automotive cybersecurity, or medical-device cybersecurity is an advantage.

The focus, however, is on the ability to translate cybersecurity requirements into real engineering controls, implementation, verification, and evidence — not compliance documentation alone.

What This Role Is Not

This role is not primarily:

  • Application or web security
  • Android application security
  • Mobile-app penetration testing
  • SOC / SIEM operations
  • IT or enterprise cybersecurity
  • GRC, audit, or compliance
  • Pure vulnerability management

You don't need to spend your entire role writing device drivers, but you must be technically comfortable going deep enough into the SoC, BSP, bootloader, kernel, TEE, and hardware-security architecture to solve product cybersecurity problems.

Why Join L4B?

At L4B, Product Cybersecurity sits close to the actual engineering.

You'll work alongside teams designing and customizing Embedded Linux and Android/AOSP platforms, integrating BSPs and hardware, and building products for demanding and long-lifecycle environments.

This is an opportunity to work on cybersecurity where architecture meets implementation — helping engineer security into the product rather than only assessing it from the outside.

We hire for technical depth, relevant hands-on experience, problem-solving ability, and engineering ownership. You don't need to match every technology listed above, but you should have strong embedded Product Cybersecurity foundations and be comfortable solving security problems across system boundaries.

Belgrade, Serbia | Remote | Full-Time Employment
No B2B, freelance, consulting, or independent-contractor arrangements.

If you can connect Product Cybersecurity with what actually happens inside the embedded platform, we'd like to talk.