Engineering & Automation (Embedded + SDLC): Automate audits of binaries and source for license usage; run SCA and produce SBOMs (CycloneDX/SPDX). Standardize reproducible build engineering with CMake and Clang/LLVM; manage dependencies via Conan and Snapcraft(where applicable). Govern artifacts in JFrog Artifactory with dependency health checks via JFrog Xray. Operationalize GitOps (GitHub/GitLab) and design CI/CD pipelines using GitHub Actions / GitLab CI. Security Testing & Vulnerability Management: Integrate SAST/DAST/IAST into embedded and app pipelines (C/C++, C #, Python, JavaScript, XML); enforce gates, SLAs, and remediation workflows. Triage third-party vulnerabilities and assess results from CodeQL, SonarQube, and related scanners; drive fix plans across firmware and supporting services. Open Source Candidates & Revalidation: Create, publish, and continually revalidate Open Source Candidates (GPL/MPL and others) with reproducible build scripts, license texts, copyright notices, and end-user instructions. Triage and resolve revalidation build errors (toolchain, linking, dependency, packaging), ensuring public distribution materials remain accurate. Requirements Collaboration & Stakeholder Management: Work cross-functionally with engineering teams, Legal, and senior leadership for status updates, new requirements intake, and policy alignment; engage external partners (ODMs, vendors, consultants) to meet compliance obligations.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
5,001-10,000 employees