Summary
✨ AI‑Generated
Join an embedded security team responsible for the vulnerability-management lifecycle of firmware used in connected devices. You will analyze embedded Linux systems, investigate CVEs and vendor advisories, determine real-world security impact using evidence, and support secure, compliant connectivity technologies for automotive and IoT applications.
Highlights
Embedded security role focused on the full vulnerability-management lifecycle for connected-device firmware. The position combines embedded Linux, security analysis, evidence-based CVE assessment, and work on security and compliance for automotive and IoT technologies.
Description
Eagle Wireless is a connectivity company delivering secure, reliable, and scalable cellular modules and solutions for automotive and IoT applications.
With a strong presence in the United States and global R&D teams across North America, Europe, and APAC, Eagle Wireless supports customers worldwide with long-life, compliant, and cyber-secure connectivity products.
Focused on trust, supply chain resilience, and regulatory compliance, Eagle Wireless helps OEMs, Tier 1 suppliers, and IoT innovators deploy connected technologies with confidence in an increasingly complex global environment.
We are looking for: Embedded Security Engineer
Job Summary:
We are seeking a skilled Security Engineer to join our R&D Automotive team, focused on the vulnerability-management lifecycle for our cellular module firmware.
The ideal candidate has a strong background in embedded Linux and security analysis, and is comfortable taking a raw CVE or vendor bulletin and determining, with evidence, whether it's a real risk for our product, then driving the fix across the full stack, from Linux userspace down to baseband code.
Key Responsibilities:
Perform scanning and analyze of CVE/OSS for firmware releasesMaintain an accurate SBOM (software bill of materials) per product/release, covering open-source and proprietary vendor components.Analyze whether a CVE is actually reachable and exploitable in our configurationWrite risk assessments and dispositions (affected / not affected / mitigated / fix planned) per product line and release for customers.Prioritize fixes based on severity, exploitability, and exposure; escalate critical remotely-exploitable issues immediately.Backport upstream fixes into our Yocto buildIntegrate Qualcomm security patches, TrustZone/QTEE, and bootloader trees; adapt patches that conflict with local modifications.Verify fixes end-to-end: rebuild affected images, run regression tests, and re-test proof-of-concept exploits where available.Maintain patch and disposition history per firmware release; feed fixes into release planning and release notes.Support customer security questionnaires, audits, and regulatory/certification needs (UNECE R155/CSMS, ISO/SAE 21434, carrier and RED/CRA requirements).Improve pipeline automation: CVE scanning in CI, SBOM generation, and alerting on new advisories affecting shipped versions.
Qualifications:
Degree in Computer Science, Electrical Engineering, or a related field.3+ years embedded Linux development, with strong C (and working C++) skills.Hands-on Yocto/OpenEmbedded experience: BitBake recipes, layers, .bbappend/patch workflow, devtool.Linux kernel patching experience: backporting fixes from mainline/LTS to a vendor kernel.Solid security fundamentals: vulnerability classes, CVSS scoring, threat modeling of embedded attack surfaces.Good troubleshooting instincts: comfortable with incomplete information, diagnosing on-target with serial console, gdb, and logs.Proficient with git/gerrit on large multi-repo codebases, cross-compilation, and debugging on embedded targets.Excellent written communication skills: able to produce clear, precise technical risk assessments for customers and auditors.
Strongly Preferred:
Qualcomm platform experience: modem/baseband codebase structure (AMSS, Hexagon DSP), TrustZone/QTEE, secure boot chain, EFS/NV configuration.Cellular protocol knowledge (LTE/5G NAS/RRC, IMS/VoLTE, SIM/UICC).Experience with Qualcomm tooling (QXDM/QCAT log analysis, QFIL).SELinux policy, secure coding review, fuzzing, or penetration-testing experience.Familiarity with automotive/regulatory security frameworks: UNECE R155, Cyber Resilience Act, carrier security requirements.
Benefits:
Competitive salary and performance-based bonuses.Opportunities for professional growth and development.Flexible working hours and remote work options.