1 - Project Overview:
Senior Bootloader & Security Engineer
2 - Job Description:
THE ROLE:
We are seeking Senior engineers who are responsible for developing, hardening, and maintaining the bootloader framework, secure boot chain, and hardware security integrations for zonal network controllers. You will work on bootloader implementations, UDS security access, image verification gates, and Hardware Security Module (eHSM / STSafe-V500) key management.
YOUR IMPACT:
Implement and configure production bootloaders across zonal target modules (supporting VBF and HEX flashing flows, dual-partition memory layouts, and bootloader-to-application jump routines).
Develop secure boot verification gates to validate authenticated image signatures (RSA/ECC), TIM descriptors (TIM#0/TIM#1), content hashes, and CUI / device_software_id readback stamping.
Integrate hardware security features using NXP Hardware Security Engine (HSE / eHSM) and external STSafe-V500 Secure Element ICs over SPI.
Implement UDS Security Access (Seed/Key protocol, security level state machines, 30s unlock delay handling, and session gating).
Support security key management features including SPAKE parameter handling, RKEK generation, and encrypted boot lock state transitions.
Implement fault-tolerant OTA firmware flashing routines, A/B partition bank switching, and crash recovery logic.
3 - Qualifications:
BASIC QUALIFICATIONS:
4+ years of embedded C firmware experience developing secure bootloaders or security stack components.
Direct experience with authenticated boot workflows, digital signature verification, and image integrity hashing.
Hands-on experience with hardware security modules (NXP HSE / eHSM or SPI-connected Secure Elements like STSafe-V500).
In-depth knowledge of UDS (ISO 14229) Security Access services (Service 0x27) and flashing security requirements.
PREFERRED QUALIFICATIONS:
Experience with bootloader development or VBF/HEX image packaging tooling.
Understanding automotive cybersecurity practices and secure key storage workflows