Technical Lead - Embedded Systems Security (Certification & Assurance)
CENSUS Α.Ε.
- Abu Dhabi
- Permanent
- Full-time
- Lead security compliance preparation activities, including gap analysis, remediation planning, and validation procedures.
- Navigate the full system stack (application layer, middleware, drivers, kernel, firmware, TEEs, etc.) to implement targeted security modifications aligned with project security requirements.
- Review, document, and refine cryptographic implementations, ensuring they meet security standards.
- Coordinate testing and validation activities to demonstrate compliance with specified criteria.
- Compile and organize technical security documentation, including architecture descriptions and assurance evidence.
- Interface with external auditors and assessors to clarify technical requirements and respond to findings.
- Guide a small team of engineers through technical implementation tasks and documentation requirements.
- MSc or BSc in Electrical Engineering, Computer Science, Computer Engineering, Electronics Engineering, or equivalent practical experience.
- 8+ years of experience in embedded, general- or special-purpose computer system-level software or firmware security. Experience can be an engineering / development position (e.g., consumer or enterprise), an assessment / consultancy role, an equivalent role in other engineering organizations, or a combination of them.
- Proven experience of 2+ years in leading embedded system security projects.
- Prior involvement in security certification or compliance initiatives.
- Proficient in English and great communication skills.
- Deep understanding of embedded system security architectures and platform security mechanisms.
- Extensive experience with cryptographic implementations in embedded devices (key management, secure storage, attestation).
- Strong programming skills in C, C++, and Java for system-level development.
- Experience with secure boot, verified boot, and hardware-backed security mechanisms.
- Familiarity with TEE environments and secure execution technologies.
- Understanding of security certification processes and documentation requirements.
- Experience with security architecture documentation, threat modeling, and security requirement compliance analysis.
- Strong analytical skills for reviewing security implementations and identifying potential weaknesses.
- Excellent leadership, ownership, problem solving skills, and willingness to learn/grow.
- Hands-on experience with security certification schemes and evaluation methodologies, such as Common Criteria and FIPS.
- Knowledge of smartphone and mobile platform security foundation, including cryptographic implementations across the different components of the stack.
- Experience with security testing tools and cryptographic validation frameworks.
- Familiarity with hardware or software side-channel attacks.
- Experience working with international teams located in other regions and time zones around the world.