Responsibilities
- Own and evolve the DevSecOps strategy for embedded systems, covering CI/CD pipelines, build environments, automated security, release documentation, and platform sustainability.
- Build and maintain secure embedded software, foundational build systems, and reusable automation tools.
- Develop and support embedded Linux distributions using Yocto, including board support packages, device drivers, hypervisors, and OS-level components.
- Implement secure software supply chain processes, covering SBOM creation, third-party component tracking, license compliance, vulnerability detection, end-of-support monitoring, and remediation.
- Design standardized CI/CD pipelines with integrated controls for static analysis, software composition analysis, unit testing, artifact signing, provenance, cybersecurity evidence, and release validation.
- Lead threat modeling and cybersecurity risk assessments for embedded platforms, including asset inventory, attack surface evaluation, exploit likelihood, security measures, and risk mitigation traceability.
- Manage CVE lifecycle activities, including intake, enrichment, asset correlation, triage, risk prioritization, remediation planning, verification, and reporting in collaboration with security, QA, systems, and program teams.
- Architect and deploy secure boot processes, firmware signing, cryptographic configurations, key and certificate lifecycle management, authenticated updates, and secure communication protocols.
- Specify requirements for runtime security monitoring and assist with post-deployment cybersecurity surveillance and vulnerability response.
- Evaluate reported security anomalies, determine potential impact, and assist in incident response as required.
- Support regulatory audits and submissions by ensuring cybersecurity practices, software development lifecycle records, and DevSecOps artifacts are complete, traceable, reproducible, and compliant with quality standards.
- Define maintenance strategies for platform OS and BSP components, including Linux kernel updates, Yocto release cycles, driver maintenance, patching capabilities, and security update governance.
- Work with external vendors and internal teams to assess security tools, embedded Linux support models, vulnerability intelligence sources, penetration test findings, and long-term maintenance strategies.
- Provide technical guidance and mentorship to software, DevOps, and platform engineers on secure coding, automation, vulnerability management, and regulated development workflows.
- Collaborate with product teams to define platform features that are reusable, secure, testable, and scalable across multiple equipment programs.
Responsibilities
- Define and own the DevSecOps architecture and roadmap for embedded capital equipment platforms, including CI/CD pipelines, build infrastructure, security automation, release evidence, and long-term maintainability.
- Develop and maintain secure embedded platform software, build infrastructure, and reusable automation capabilities.
- Create and support Yocto-based embedded Linux distributions, BSP software, device drivers, hypervisors, and platform-level OS components.
- Establish secure software supply chain practices, including SBOM generation, SOUP/OTS component tracking, license awareness, vulnerability monitoring, end-of-support tracking, and remediation workflows.
- Develop reusable CI/CD templates and pipeline controls for static analysis, software composition analysis, unit test automation, artifact signing, provenance tracking, cybersecurity evidence capture, and release readiness.
- Lead threat modeling and cybersecurity risk analysis for embedded platform components, including asset identification, attack surface analysis, exploitability assessment, security controls, and traceability to risk mitigations.
- Drive CVE intake, enrichment, asset mapping, triage, risk scoring, remediation planning, validation, and reporting in partnership with Product Security, SWQA, Systems, and program teams.
- Design and implement secure boot, firmware signing, cryptographic configuration, key/certificate lifecycle support, authenticated update mechanisms, and secure device communication patterns.
- Define runtime security monitoring requirements and support post-market cybersecurity monitoring and vulnerability response workflows.
- Review reported anomalies, assess cybersecurity impact, and support incident-response activities as needed.
- Support regulatory submissions and audits by ensuring cybersecurity, software lifecycle, and DevSecOps evidence is complete, traceable, reproducible, and aligned with internal quality system expectations.
- Define platform-level OS and BSP maintenance strategies, including Linux kernel support, Yocto release planning, driver update strategy, patchability, and security update governance across the product lifecycle.
- Collaborate with external vendors and internal partners to evaluate security tooling, embedded Linux support models, vulnerability intelligence, penetration testing outputs, and long-term maintenance approaches.
- Provide technical leadership and mentoring to software engineers, DevOps engineers, and platform teams on secure coding, build automation, vulnerability handling, and regulated software development practices.
- Partner with product teams to define platform capabilities that are reusable, secure, testable, and scalable across multiple capital equipment programs.