Назад
Company hidden
обновлено 4 дня назад

Sr DevSecOps Engineer (Embedded Linux)

124 800 - 187 200$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr DevSecOps Engineer (Embedded Linux): Defining and implementing secure DevSecOps platforms, CI/CD automation, software supply chain controls, and cybersecurity processes for regulated medical devices with an accent on embedded Linux security, vulnerability management, and compliance evidence. Focus on threat modeling, secure boot and firmware signing, reproducible release workflows, and translating cybersecurity risks into actionable engineering decisions.

Location: Lafayette, Colorado, United States

Salary: $124,800–$187,200 annually

Company

hirify.global develops healthcare technologies intended to alleviate pain, restore health, and extend life.

What you will do

  • Define and govern DevSecOps architecture and roadmaps for embedded medical device platforms.
  • Build reusable CI/CD templates and controls for static analysis, software composition analysis, testing, artifact signing, provenance tracking, and release evidence.
  • Establish software supply chain practices covering SBOMs, SOUP/OTS components, licensing, vulnerabilities, support status, and remediation.
  • Lead threat modeling, cybersecurity risk analysis, CVE triage, remediation planning, and validation across product teams.
  • Implement secure boot, firmware signing, cryptographic configuration, certificate and key lifecycle support, authenticated updates, and secure device communications.
  • Support regulatory submissions, audits, post-market monitoring, incident response, vendor evaluation, and technical mentoring.

Requirements

  • Must have unrestricted U.S. work authorization at the time of hire and throughout employment.
  • Experience with embedded Linux, Yocto-based package development, embedded hypervisors, device drivers, BSPs, and boot flows.
  • Experience with CI/CD, software supply chain security, SAST, SCA, container scanning, artifact signing, vulnerability management, and build traceability.
  • Knowledge of threat modeling, vulnerability assessment, cybersecurity risk analysis, secure-by-design architecture, and incident response.
  • Proficiency with Python, Bash, or Go and tools such as Docker, Snyk, SonarQube, GitHub, GitLab, and Atlassian platforms.
  • Experience collaborating across software, systems, product security, quality, regulatory, and program teams in regulated or safety-critical environments.

Nice to have

  • Cloud infrastructure experience with AWS or similar platforms.
  • Infrastructure-as-code and modern DevOps experience.
  • Knowledge of FDA cybersecurity expectations, IEC 62304, ISO 14971, ISO 13485, and regulated software lifecycle evidence.
  • Experience with AMD Zynq, Zynq UltraScale+, NVIDIA ORIN, SafeRTOS, or FreeRTOS.

Culture & Benefits

  • Full-time employment in a technical specialist career stream with opportunities to mentor colleagues.
  • Health, dental, vision, life, and disability insurance options.
  • 401(k) plan with employer contribution and match, paid time off, and paid holidays.
  • Tuition assistance or reimbursement, employee stock purchase plan, incentive plans, and employee assistance resources.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →