5 to 8 years of hands-on experience in C/C++ software development on Linux-based embedded or telecom platforms.
Strong experience in analyzing, fixing, and validating software security vulnerabilities reported by tools such as Coverity, Black Duck, Nessus, or similar static/dynamic scanners.
Ability to debug and fix issues in protocol stack components, including memory corruption, buffer handling, race conditions, input validation, resource leaks, and unsafe API usage.
Good understanding of secure coding practices, memory safety, multi-threading, IPC, Linux OS concepts, and performance-aware software design.
Working knowledge of 4G/5G RAN stack architecture and protocol layers such as RRC, NGAP, XnAP, PDCP, RLC, MAC, or related stack components.
Experience in tracing complex call flows, analyzing logs, reproducing defects, preparing patches, and ensuring fixes do not introduce regressions.
Ability to handle security defects in legacy and production code while maintaining stability, scalability, and low-latency behavior of telecom software.
Familiarity with build systems, CI/CD pipelines, code review practices, unit testing, and defect tracking tools.
Good communication skills to work with security teams, stack developers, testers, architects, and release teams for timely vulnerability closure.
Preferred: exposure to threat modelling, CVE analysis, SBOM/open-source vulnerability handling, hardening activities, and telecom security standards.