Senior Software Security Engineer (Linux Appliances)
Company Overview
PreciseFrame is a Singapore deep tech company revolutionizing video storage and streaming. Its PreciseFlow™ engine reduces camera network data by up to 90% while preserving quality, running on standard CPUs without GPUs, integrating seamlessly with existing video systems.
Job Summary
Own the security architecture and secure platform engineering of appliance products, focusing on software security to protect devices and intellectual property. Collaborate on media streaming integration and work hands-on with appliance hardware. Reports to R&D Manager.
Responsibilities
- Design and maintain appliance trust architecture including UEFI Secure Boot key hierarchy, signing workflows, measured boot, and TPM-anchored secrets to ensure device integrity
- Manage TPM 2.0 in production by creating keys, defining PCR measurements and policies, implementing sealed storage, remote attestation, and integrating LUKS/Clevis disk encryption
- Harden Linux platforms end to end by configuring kernel lockdown, implementing IMA appraisal policies, enforcing AppArmor confinement, applying sysctl and module blacklists, and managing audit and sandboxing systems
- Own and improve the secure build pipeline through hardened kernel builds, signed OS image assembly, reproducibility practices, and cryptographic verification at every stage
- Implement applied cryptography workflows correctly, including RSA-PSS and OAEP signature schemes, AES-GCM authenticated encryption, canonical serialization for signed documents, and key ceremony management including compromise response
- Develop verification infrastructure using QEMU/OVMF/swTPM boot testing, self-tests with negative controls, and fail-closed validation gates to ensure security robustness
- Contribute to threat modeling by defining adversaries and trust boundaries, documenting architectural decisions to defend security invariants
- Develop and debug media streaming stack components (RTSP, ONVIF, media pipelines) as required by product needs
- Write operator-grade tooling in bash, Python, and C, and produce comprehensive run books to support operations
Required competencies and certifications
- Minimum 5 years of security-focused systems engineering experience on Linux platforms
- Expertise in UEFI Secure Boot including key hierarchy (PK/KEK/db), image signing, and enrollment workflows
- Hands-on experience with TPM 2.0 covering key attributes, PCR policies, sealing, and attestation concepts (EK, AK, quotes)
- Practical experience with disk encryption in production environments using LUKS2, cryptsetup, and TPM binding (Clevis or equivalent)
- Proficient in Linux hardening techniques including mandatory access control (AppArmor or SELinux), kernel lockdown, IMA/EVM or comparable integrity frameworks, and audit systems
- Applied cryptography skills to implement, review, and detect misuse of asymmetric signatures, authenticated encryption, and verification chains
- Experience in threat modeling and secure design review processes
- Deep understanding of Linux internals including boot process (UEFI, bootloader, kernel, init), systemd, udev, initramfs, custom image building, and kernel configuration
- Expert-level bash scripting and strong Python programming skills; proficiency in C for systems programming
- Working knowledge of streaming protocols (RTSP/RTP), ONVIF standards, and media frameworks such as GStreamer or FFmpeg
Preferred competencies and qualifications
- Experience with anti-tamper and reverse engineering resistance techniques including encrypted payloads, secure loaders, and self-integrity checks
- Familiarity with airgapped or no-update channel deployment models and associated operational discipline
- Knowledge of secure provisioning at scale, per-unit key management, reproducible builds, and supply chain security awareness
- Experience integrating with Video Management Systems (VMS) or Network Video Recorders (NVR) and performance engineering
Other Information
Location Full time, permanent position based at PreciseFrame’s office in Singapore.
Work Eligibility Applicants must be eligible to work in Singapore.
How We Work We operate as a small, high-trust team with high ownership. Architecture decisions are documented and reviewed. Our security-critical units require rigorous quality and traceability to prevent compromises that would necessitate hardware recalls.