Senior DevSecOps Engineer
Denver, CO - USA
Job Summary
Were ALTEN Technology USA an engineering company helping clients bring groundbreaking ideas to lifefrom advancing space exploration and life-saving medical devices to building autonomous electric vehicles. With 3000 experts across North America we partner with leading companies in aerospace medical devices robotics automotive commercial vehicles EVs rail and more.
As part of the global ALTEN Group57000 engineers in 30 countrieswe deliver across the entire product development cycle from consulting to full project outsourcing.
When you join ALTEN Technology USA youll collaborate on some of the worlds toughest engineering challenges supported by mentorship career growth opportunities and comprehensive benefits. We take pride in fostering a culture where employees feel valued supported and inspired to grow.
NO CLIENT NAME
As a Sr DevSecOps Engineer you will be responsible for;
Define and own the DevSecOps architecture and roadmap for embedded capital equipment platforms including CI/CD pipelines build infrastructure security automation release evidence and long-term maintainability.
Develop and maintain secure embedded platform software build infrastructure and reusable automation capabilities.
Create and support Yocto-based embedded Linux distributions BSP software device drivers hypervisors and platform-level OS components.
Establish secure software supply chain practices including SBOM generation SOUP/OTS component tracking license awareness vulnerability monitoring end-of-support tracking and remediation workflows.
Develop reusable CI/CD templates and pipeline controls for static analysis software composition analysis unit test automation artifact signing provenance tracking cybersecurity evidence capture and release readiness.
Lead threat modeling and cybersecurity risk analysis for embedded platform components including asset identification attack surface analysis exploitability assessment security controls and traceability to risk mitigations.
Drive CVE intake enrichment asset mapping triage risk scoring remediation planning validation and reporting in partnership with Product Security SWQA Systems and program teams.
Design and implement secure boot firmware signing cryptographic configuration key/certificate lifecycle support authenticated update mechanisms and secure device communication patterns.
Define runtime security monitoring requirements and support post-market cybersecurity monitoring and vulnerability response workflows.
Review reported anomalies assess cybersecurity impact and support incident-response activities as needed.
Support regulatory submissions and audits by ensuring cybersecurity software lifecycle and DevSecOps evidence is complete traceable reproducible and aligned with internal quality system expectations.
Define platform-level OS and BSP maintenance strategies including Linux kernel support Yocto release planning driver update strategy patchability and security update governance across the product lifecycle.
Collaborate with external vendors and internal partners to evaluate security tooling embedded Linux support models vulnerability intelligence penetration testing outputs and long-term maintenance approaches.
Provide technical leadership and mentoring to software engineers DevOps engineers and platform teams on secure coding build automation vulnerability handling and regulated software development practices.
Partner with product teams to define platform capabilities that are reusable secure testable and scalable across multiple capital equipment programs.
Technologies & Tools
AMD Zynq and Zynq UltraScale SoCs NVIDIA ORIN SafeRTOS FreeRTOS
Yocto-based embedded Linux package development
Embedded hypervisors Linux device drivers BSPs and boot flows
Custom build systems and CI/CD pipelines
Docker Snyk SonarQube and software composition analysis tools
Static analysis software composition analysis artifact signing and vulnerability management tools
Python Bash and Go
Atlassian tools including Bitbucket Jira Bamboo and Confluence
GitHub and GitLab
Networking security secure boot firmware signing and secure update technologies
Qualifications;
Strong experience in embedded Linux platform development for regulated safety-critical or high-reliability products.
Hands-on experience with AMD/Xilinx SoC-based embedded systems including AMD Zynq 7000 series Zynq UltraScale Kria SOM and the NVIDIA ORIN platform. Experience with real-time operating systems such as SafeRTOS and QNX Neutrino.
Experience with Yocto BSPs OS layers kernel configuration boot flows device drivers and embedded platform security.
Experience developing or governing DevSecOps practices in regulated medical device safety-critical aerospace automotive or industrial control environments.
Strong understanding of FDA cybersecurity expectations IEC 62304 ISO 14971 ISO 13485 SOUP/OTS software management SBOM practices and software lifecycle evidence generation.
Experience implementing security automation in CI/CD pipelines including SAST SCA container scanning artifact signing build reproducibility traceability and vulnerability reporting.
Strong experience with threat modeling vulnerability assessment cybersecurity risk analysis and secure-by-design architecture reviews.
Experience with CVE triage methods that include exploitability asset exposure configuration applicability runtime reachability known exploited vulnerabilities and remediation validation.
Ability to collaborate across hardware software systems product security quality regulatory program management and product management stakeholders.
Demonstrated ability to influence cross-functional engineering and leadership decisions without direct authority.
Experience defining reusable platform practices across multiple products programs hardware variants or software release branches.
Strong debugging problem-solving and root-cause analysis skills.
Strong technical communication skills with the ability to translate cybersecurity and DevSecOps risks into actionable engineering and leadership decisions.
Salary Range: $125k-$150k
The actual salary offered is dependent on various factors including but not limited to location the candidates combination of job-related knowledge qualifications skills education training and experience
MANDATORY FOR ALL REMOTE/HYBRID AND/OR CALIFORNIA DISTRICT OF COLUMBIA HAWAII COLORADO MARYLAND CONNECTICUT ILLINOIS MINNESOTA VERMONT MASSACHUSETTS NEVADA NEW YORK RHODE ISLAND WASHINGTON STATE & CINCINNATI OHIO JERSEY CITY NEW JERSEY TOLEDO OHIO BASED ROLES.
Note: Due to the nature of the work only US Persons (citizens or permanent residents) need apply for this position. - OPTIONAL
All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race color religion sex sexual orientation gender identity national origin disability protected veteran status age genetic information or pregnancy.
Please beware of job seeker scams and see this important notice on our careers page for more information about our recruiting process.
Compliance Notice: Alten USA is a federal contractor subject to the requirements of the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA) and Executive Order 11246. We are an Equal Opportunity Employer and consider all qualified applicants without regard to race color religion sex sexual orientation gender identity national origin disability or veteran status.
Drug Screening Requirement: As a federal contractor Alten USA maintains a drug-free workplace. All candidates selected for employment will be required to successfully complete a pre-employment drug screening as a condition of hire.
Required Experience:
Senior IC
About Company
ALTEN Technology is an engineering services company in the USA. As a leading engineering consulting firm, we provide tailored engineering solutions.