VIZIO works with open-source software to provide innovative and cutting-edge solutions to our clients. We are seeking a Staff-level engineer who thrives on autonomy, engineering latitude, and self-determination—someone who relishes the freedom to architect solutions, drive compliance, and innovate in a fast-moving environment. In this Dallas-based, onsite role (five days a week), you’ll join an incredibly dynamic and highly competent Security team, where your expertise will be valued and your voice heard. This is a rare opportunity to collaborate with top-tier professionals, shape technical direction, and make a tangible impact on both product and process. The ideal candidate brings at least eight years of hands-on embedded software development experience, with a proven track record of transitioning into security-focused roles. You’ll demonstrate mastery in open-source license compliance, CI/CD automation, vulnerability management, and technical communication—showcasing both self-reliance and the ability to lead initiatives from concept to production. If you’re ready to join a team that sets the standard in Security and empowers its members to excel, this is your chance to make your mark. What you'll do... What You Will Do: Engineering & Automation (Embedded + SDLC) Automate audits of binaries and source for license usage; run SCA and produce SBOMs (CycloneDX/SPDX). Standardize reproducible build engineering with CMake and Clang/LLVM; manage dependencies via Conan and Snapcraft(where applicable). Govern artifacts in JFrog Artifactory with dependency health checks via JFrog Xray. Operationalize GitOps (GitHub/GitLab) and design CI/CD pipelines using GitHub. Integrate SAST/DAST/IAST into embedded and app pipelines (C/C++/C#, Python, JavaScript, XML); enforce gates, SLAs, and remediation workflows. Triage third-party vulnerabilities and assess results from CodeQL, SonarQube, and related scanners; drive fix plans across firmware and supporting services. Create, publish, and continually revalidate Open Source Candidates (GPL/MPL and others) with reproducible build scripts, license texts, copyright notices, and end user. Triage and resolve revalidation build errors (toolchain, linking, dependency, packaging), ensuring public distribution materials remain accurate. Conduct formal risk assessments to identify threats and vulnerabilities and recommend mitigating controls. Ensure compliance with opensource licenses and applicable standards (e.g., ISO 27001, ISO/IEC 5230:2020, SOC 2) in partnership with Engineering, Legal, and external stakeholders. Evaluate proposed libraries before integration (GPL/LGPL/MPL/MIT/Apache), document obligations (attribution, source offer, relinking), and guide compliant implementation patterns (static vs. dynamic link, dual license scenarios). Documentation, Training & Enablement Author/update SOPs, Working Instructions, developer facing runbooks, and public distribution READMEs. Develop and deliver opensource and product based GRC training to employees and contractors. Communicate complex build processes, package management, and license implications to technical and nontechnical audiences. Incident Response & Continuous Improvement Lead incident response (identify, contain, recover), conduct post incident reviews, and recommend program and control improvements. Monitor industry trends and best practices in Open Source License Compliance; propose program updates proactively. Data & Reporting Publish compliance/security dashboards in Power BI; use SQL to analyze SBOM coverage, license risk, vulnerability posture, and release readiness for executive decisioning. Collaboration & Stakeholder Management Work cross functionally with engineering teams, Legal, and senior leadership for status updates, new requirements intake, and policy alignment; engage external partners (ODMs, vendors, consultants) to meet compliance obligations.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
11-50 employees