JOBSEARCHER

Embedded Product Security Engineer

Eagle Wireless is a connectivity company delivering secure, reliable, and scalable cellular modules and solutions for automotive and IoT applications. With a strong presence in the United States and global R&D teams across North America, Europe, and APAC, Eagle Wireless supports customers worldwide with long-life, compliant, and cyber-secure connectivity products. Focused on trust, supply chain resilience, and regulatory compliance, Eagle Wireless helps OEMs, Tier 1 suppliers, and IoT innovators deploy connected technologies with confidence in an increasingly complex global environment.We are looking for: Embedded Product Security Engineer This is a hands-on technical role. You will write and run code, operate tooling in containers, generate customer-facing reports, and work directly with firmware and software engineers to remediate findings. You will also be a key contributor to our CI/CD pipeline, embedding security analysis at the build stage rather than as an afterthought.Key responsibilities:CVE triage and vulnerability managementMonitor CVE feeds and security advisories relevant to our component stacks across all product linesTriage incoming CVEs against maintained SBOMs, assess exploitability, and determine applicability per productAuthor and deliver VEX (Vulnerability Exploitability eXchange) documents to customers within required timelinesMaintain component inventory as products evolve through their lifecycleOperate and maintain vulnerability management tooling (e.g. Dependency-Track or equivalent)SBOM generation and maintenanceGenerate and maintain accurate SBOMs (CycloneDX / SPDX) for all 20+ product linesIntegrate SBOM generation into CI/CD pipelines so artifacts are produced automatically at build timeDeliver SBOMs to customers in required formats (CycloneDX, SPDX) on agreed cadencesTrack third-party component updates, license changes, and EOL status across the product portfolioSecure CI/CD and DevSecOps integrationWork with platform and DevOps engineers to integrate security tooling into build pipelinesDeploy and maintain source code static analysis tools (e.g. Coverity, Clang Static Analyzer) and binary analysis tools (e.g. Binwalk, Finite State, Binary Ninja) — selecting the right tool for the analysis contextImplement and manage code signing and binary signing workflows for firmware and software releases, including key management and certificate lifecycleDefine and enforce security gates in the pipeline — builds that introduce new critical findings do not shipSupport secret scanning, dependency checking, and licence compliance tooling in CIMaintain reproducible, containerised analysis environments so tooling runs consistently across dev, CI, and ad-hoc investigation contextsFirmware and hardware security analysisPerform or coordinate binary firmware analysis using tools such as Binwalk, Ghidra, Binary Ninja, and Finite State to identify vulnerabilities, hardcoded credentials, and insecure configurationsConduct or support source code security review of C/C++ and embedded codebases, identifying memory safety issues, unsafe function usage, and logic flawsAssess hardware debug interfaces (UART, JTAG, SWD) for exposure and insecure defaults; document findings and work with hardware engineers on mitigationsEvaluate boot security: secure boot, chain-of-trust, and firmware signing enforcementIdentify and triage vulnerabilities specific to cellular module threat models — baseband exposure, AT command surface, modem firmware, and OTA update securityProduce structured technical findings reports from firmware and hardware analysis, suitable for engineering remediation and customer-facing disclosure where requiredReporting and automationWrite Python scripts and tooling to automate vulnerability report generation for customer deliveryBuild and maintain containerised analysis workflows that can be run reliably across different environmentsProduce clear, accurate security reports suitable for both technical and non-technical customer contactsMaintain dashboards and metrics for internal tracking of vulnerability status across the product portfolioCustomer and cross-functional supportProduce technical security data packages — SBOMs, VEX documents, and scan results — for customer deliveryProvide technical input to penetration test scoping and support findings reviewWork with firmware and software engineers to communicate vulnerability findings clearly and track remediationEnsure outputs (SBOMs, VEX documents, reports) meet the technical requirements of CRARequired qualifications3+ years in a product security, application security, or security engineering roleHands-on Python development — you write scripts and tooling, not just configure dashboardsPractical experience with SBOM formats (CycloneDX, SPDX) and VEXWorking knowledge of CVE, CVSS, and vulnerability triage methodologyExperience with container-based workflows — building, running, and debugging containers (Docker, Podman)Familiarity with CI/CD systems (Jenkins, Bitbucket Pipelines, Gerrit, or similar) and integrating security tooling into pipelinesExperience with source code static analysis tools (e.g. Coverity, Clang Static Analyzer) — able to tune rules, review findings, and distinguish true positives from noiseHands-on experience with binary firmware analysis tooling — Binwalk for unpacking and filesystem extraction, Ghidra or Binary Ninja for reverse engineering and disassemblyPractical understanding of hardware debug interfaces: UART, JTAG, and SWD — what they expose, how to assess them, and how to advise on hardeningUnderstanding of code signing, certificate management, and PKI as applied to firmware or software releasesStrong written communication — you will author documents that go directly to customersPreferred qualificationsExperience in an embedded systems, firmware, or hardware product company — cellular, IoT, or industrial preferredFamiliarity with cellular module threat models: AT command attack surface, baseband firmware, SIM/eSIM security, and OTA update mechanismsExperience with Finite State or similar commercial firmware security analysis platformsReverse engineering experience with Ghidra, Binary Ninja, or IDA Pro — able to navigate disassembly and identify security-relevant code pathsExperience testing or assessing hardware debug interfaces (UART, JTAG, SWD) in a lab settingKnowledge of EU Cyber Resilience Act requirements and obligationsExperience with Dependency-Track, Grype, Syft, or similar open-source vulnerability management platformsExposure to OpenVEX or other machine-readable VEX formatsUnderstanding of firmware supply chain security concepts (SLSA, sigstore, reproducible builds)Relevant certifications: GREM, GPEN, CSSLP, CompTIA Security+, or similar — firmware/hardware focus preferredComfortable in a lab environment — able to work with hardware, connect to debug interfaces, and run tooling on physical devicesWhat success looks like30 days - Understand our product portfolio, component stacks, and current SBOM coverage. Identify the largest gaps in our CVE triage process.90 days - Vulnerability management tooling deployed. SBOM generation automated for at least a subset of product lines. First VEX documents delivered to customers.6 months - Security gates active in CI/CD. Binary signing integrated. All active products have maintained SBOMs. CVE triage running as a steady-state program rather than reactive firefighting.12 months - Full product security tooling stack operational and producing consistent outputs. Customer SBOM and VEX delivery running as a steady-state automated program. Product security posture measurably improved and demonstrable through data.