Назад
Company hidden
10 дней назад

Firmware Manager, CRA Compliance - Cargo (IoT)

Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Firmware Manager, CRA Compliance - Cargo (IoT) (Embedded C/C++ and IoT cybersecurity): Leading the development of secure, scalable firmware for IoT products while aligning embedded architecture and the SDLC with EU Cyber Resilience Act requirements, with an accent on secure boot, cryptographic hardware, SBOM automation, and resilient OTA updates. Focus on building vulnerability and incident response workflows, integrating security testing into CI/CD, and coordinating technical documentation and conformity audits.

Location: Palm Beach Gardens, Florida, USA. Authorization to work in the United States is required; visa sponsorship will not be provided.

Company

hirify.global develops climate technologies, HVACR systems, cold-chain solutions, and connected software and monitoring products.

What you will do

  • Lead an embedded firmware engineering team building secure, scalable IoT products.
  • Design and implement firmware security controls, including Hardware Root of Trust, Secure Boot, encrypted memory partitions, and secure key storage.
  • Establish automated SBOM generation and dependency management using build pipelines and formats such as CycloneDX or SPDX.
  • Direct secure, cryptographically signed OTA updates and rapid security patch deployment without bricking field devices.
  • Implement vulnerability reporting, incident management, compliance testing, risk assessments, and CRA technical documentation.
  • Collaborate with Product Management, Hardware Design, Legal/Compliance, Cloud IoT teams, auditors, and security researchers.

Requirements

  • Bachelor’s or Master’s degree in Computer Engineering, Electrical Engineering, Computer Science, or equivalent practical experience.
  • 8+ years of embedded firmware development experience with C/C++, RTOS, bare-metal, or Embedded Linux, preferably for IoT devices.
  • 3+ years in engineering management, technical leadership, or a supervisory role.
  • Hands-on experience with Secure Boot, HSM, TPM, Secure Elements, TLS/mTLS, memory protection, and secure storage.
  • Knowledge of the EU Cyber Resilience Act, ETSI EN 303 645, NIST SP 800-213, IEC 62443, and related hardware/software security frameworks.
  • Must be legally authorized to work in the United States; current or future sponsorship is not available.

Nice to have

  • Experience with automated SBOM pipelines, vulnerability scanning, and CVE mapping.
  • Experience with ARM Cortex-M/TrustZone, RISC-V, ESP32, BLE, Wi-Fi, Cellular IoT, Thread, or Matter.
  • Knowledge of global IoT cybersecurity legislation, including the US Cyber Trust Mark and UK PSTI Act.
  • Active CISSP, CSSLP, or CISM certification.

Culture & Benefits

  • Work in a sustainability-focused climate technologies organization.
  • Collaborative culture centered on passion, openness, inclusion, and belonging.
  • Medical, dental, vision, and 401(k) benefits.
  • Flexible time off, paid parental leave, vacation, and holiday leave.
  • Professional development from onboarding through senior leadership.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →