altentechnologyusa logo

Senior DevSecOps Engineer

altentechnologyusa Denver, Colorado, United States


No Relocation

Posted: August 14, 2026

Job Description

NO CLIENT NAME

 

As a Sr DevSecOps Engineer you will be responsible for;

· Define and own the DevSecOps architecture and roadmap for embedded capital equipment platforms, including CI/CD pipelines, build infrastructure, security automation, release evidence, and long-term maintainability.

· Develop and maintain secure embedded platform software, build infrastructure, and reusable automation capabilities.

· Create and support Yocto-based embedded Linux distributions, BSP software, device drivers, hypervisors, and platform-level OS components.

· Establish secure software supply chain practices, including SBOM generation, SOUP/OTS component tracking, license awareness, vulnerability monitoring, end-of-support tracking, and remediation workflows.

· Develop reusable CI/CD templates and pipeline controls for static analysis, software composition analysis, unit test automation, artifact signing, provenance tracking, cybersecurity evidence capture, and release readiness.

· Lead threat modeling and cybersecurity risk analysis for embedded platform components, including asset identification, attack surface analysis, exploitability assessment, security controls, and traceability to risk mitigations.

· Drive CVE intake, enrichment, asset mapping, triage, risk scoring, remediation planning, validation, and reporting in partnership with Product Security, SWQA, Systems, and program teams.

· Design and implement secure boot, firmware signing, cryptographic configuration, key/certificate lifecycle support, authenticated update mechanisms, and secure device communication patterns.

· Define runtime security monitoring requirements and support post-market cybersecurity monitoring and vulnerability response workflows.

· Review reported anomalies, assess cybersecurity impact, and support incident-response activities as needed.

· Support regulatory submissions and audits by ensuring cybersecurity, software lifecycle, and DevSecOps evidence is complete, traceable, reproducible, and aligned with internal quality system expectations.

· Define platform-level OS and BSP maintenance strategies, including Linux kernel support, Yocto release planning, driver update strategy, patchability, and security update governance across the product lifecycle.

· Collaborate with external vendors and internal partners to evaluate security tooling, embedded Linux support models, vulnerability intelligence, penetration testing outputs, and long-term maintenance approaches.

· Provide technical leadership and mentoring to software engineers, DevOps engineers, and platform teams on secure coding, build automation, vulnerability handling, and regulated software development practices.

· Partner with product teams to define platform capabilities that are reusable, secure, testable, and scalable across multiple capital equipment programs.

· Technologies & Tools

· AMD Zynq and Zynq UltraScale+ SoCs, NVIDIA ORIN, SafeRTOS, FreeRTOS

· Yocto-based embedded Linux package development

· Embedded hypervisors, Linux device drivers, BSPs, and boot flows

· Custom build systems and CI/CD pipelines

· Docker, Snyk, SonarQube, and software composition analysis tools

· Static analysis, software composition analysis, artifact signing, and vulnerability management tools

· Python, Bash, and Go

· Atlassian tools including Bitbucket, Jira, Bamboo, and Confluence

· GitHub and GitLab

· Networking security, secure boot, firmware signing, and secure update technologies

Qualifications;

· Strong experience in embedded Linux platform development for regulated, safety-critical, or high-reliability products.

· Hands-on experience with AMD/Xilinx SoC-based embedded systems, including AMD Zynq 7000 series, Zynq UltraScale+, Kria SOM, and the NVIDIA ORIN platform. Experience with real-time operating systems such as SafeRTOS and QNX Neutrino.

· Experience with Yocto, BSPs, OS layers, kernel configuration, boot flows, device drivers, and embedded platform security.

· Experience developing or governing DevSecOps practices in regulated medical device, safety-critical, aerospace, automotive, or industrial control environments.

· Strong understanding of FDA cybersecurity expectations, IEC 62304, ISO 14971, ISO 13485, SOUP/OTS software management, SBOM practices, and software lifecycle evidence generation.

· Experience implementing security automation in CI/CD pipelines, including SAST, SCA, container scanning, artifact signing, build reproducibility, traceability, and vulnerability reporting.

· Strong experience with threat modeling, vulnerability assessment, cybersecurity risk analysis, and secure-by-design architecture reviews.

· Experience with CVE triage methods that include exploitability, asset exposure, configuration applicability, runtime reachability, known exploited vulnerabilities, and remediation validation.

· Ability to collaborate across hardware, software, systems, product security, quality, regulatory, program management, and product management stakeholders.

· Demonstrated ability to influence cross-functional engineering and leadership decisions without direct authority.

· Experience defining reusable platform practices across multiple products, programs, hardware variants, or software release branches.

· Strong debugging, problem-solving, and root-cause analysis skills.

· Strong technical communication skills with the ability to translate cybersecurity and DevSecOps risks into actionable engineering and leadership decisions.

 

 

Salary Range: $125k-$150k

The actual salary offered is dependent on various factors including, but not limited to, location, the candidate’s combination of job-related knowledge, qualifications, skills, education, training, and experience 

MANDATORY FOR ALL REMOTE/HYBRID AND/OR CALIFORNIA, DISTRICT OF COLUMBIA, HAWAII, COLORADO, MARYLAND, CONNECTICUT, ILLINOIS, MINNESOTA, VERMONT, MASSACHUSETTS, NEVADA, NEW YORK, RHODE ISLAND, WASHINGTON STATE & CINCINNATI, OHIO, JERSEY CITY, NEW JERSEY, TOLEDO, OHIO BASED ROLES. 

Note: Due to the nature of the work, only US Persons (citizens or permanent residents) need apply for this position. - OPTIONAL 

Additional Content

NO CLIENT NAME

 

As a Sr DevSecOps Engineer you will be responsible for;

· Define and own the DevSecOps architecture and roadmap for embedded capital equipment platforms, including CI/CD pipelines, build infrastructure, security automation, release evidence, and long-term maintainability.

· Develop and maintain secure embedded platform software, build infrastructure, and reusable automation capabilities.

· Create and support Yocto-based embedded Linux distributions, BSP software, device drivers, hypervisors, and platform-level OS components.

· Establish secure software supply chain practices, including SBOM generation, SOUP/OTS component tracking, license awareness, vulnerability monitoring, end-of-support tracking, and remediation workflows.

· Develop reusable CI/CD templates and pipeline controls for static analysis, software composition analysis, unit test automation, artifact signing, provenance tracking, cybersecurity evidence capture, and release readiness.

· Lead threat modeling and cybersecurity risk analysis for embedded platform components, including asset identification, attack surface analysis, exploitability assessment, security controls, and traceability to risk mitigations.

· Drive CVE intake, enrichment, asset mapping, triage, risk scoring, remediation planning, validation, and reporting in partnership with Product Security, SWQA, Systems, and program teams.

· Design and implement secure boot, firmware signing, cryptographic configuration, key/certificate lifecycle support, authenticated update mechanisms, and secure device communication patterns.

· Define runtime security monitoring requirements and support post-market cybersecurity monitoring and vulnerability response workflows.

· Review reported anomalies, assess cybersecurity impact, and support incident-response activities as needed.

· Support regulatory submissions and audits by ensuring cybersecurity, software lifecycle, and DevSecOps evidence is complete, traceable, reproducible, and aligned with internal quality system expectations.

· Define platform-level OS and BSP maintenance strategies, including Linux kernel support, Yocto release planning, driver update strategy, patchability, and security update governance across the product lifecycle.

· Collaborate with external vendors and internal partners to evaluate security tooling, embedded Linux support models, vulnerability intelligence, penetration testing outputs, and long-term maintenance approaches.

· Provide technical leadership and mentoring to software engineers, DevOps engineers, and platform teams on secure coding, build automation, vulnerability handling, and regulated software development practices.

· Partner with product teams to define platform capabilities that are reusable, secure, testable, and scalable across multiple capital equipment programs.

· Technologies & Tools

· AMD Zynq and Zynq UltraScale+ SoCs, NVIDIA ORIN, SafeRTOS, FreeRTOS

· Yocto-based embedded Linux package development

· Embedded hypervisors, Linux device drivers, BSPs, and boot flows

· Custom build systems and CI/CD pipelines

· Docker, Snyk, SonarQube, and software composition analysis tools

· Static analysis, software composition analysis, artifact signing, and vulnerability management tools

· Python, Bash, and Go

· Atlassian tools including Bitbucket, Jira, Bamboo, and Confluence

· GitHub and GitLab

· Networking security, secure boot, firmware signing, and secure update technologies

Qualifications;

· Strong experience in embedded Linux platform development for regulated, safety-critical, or high-reliability products.

· Hands-on experience with AMD/Xilinx SoC-based embedded systems, including AMD Zynq 7000 series, Zynq UltraScale+, Kria SOM, and the NVIDIA ORIN platform. Experience with real-time operating systems such as SafeRTOS and QNX Neutrino.

· Experience with Yocto, BSPs, OS layers, kernel configuration, boot flows, device drivers, and embedded platform security.

· Experience developing or governing DevSecOps practices in regulated medical device, safety-critical, aerospace, automotive, or industrial control environments.

· Strong understanding of FDA cybersecurity expectations, IEC 62304, ISO 14971, ISO 13485, SOUP/OTS software management, SBOM practices, and software lifecycle evidence generation.

· Experience implementing security automation in CI/CD pipelines, including SAST, SCA, container scanning, artifact signing, build reproducibility, traceability, and vulnerability reporting.

· Strong experience with threat modeling, vulnerability assessment, cybersecurity risk analysis, and secure-by-design architecture reviews.

· Experience with CVE triage methods that include exploitability, asset exposure, configuration applicability, runtime reachability, known exploited vulnerabilities, and remediation validation.

· Ability to collaborate across hardware, software, systems, product security, quality, regulatory, program management, and product management stakeholders.

· Demonstrated ability to influence cross-functional engineering and leadership decisions without direct authority.

· Experience defining reusable platform practices across multiple products, programs, hardware variants, or software release branches.

· Strong debugging, problem-solving, and root-cause analysis skills.

· Strong technical communication skills with the ability to translate cybersecurity and DevSecOps risks into actionable engineering and leadership decisions.

 

 

Salary Range: $125k-$150k

The actual salary offered is dependent on various factors including, but not limited to, location, the candidate’s combination of job-related knowledge, qualifications, skills, education, training, and experience 

MANDATORY FOR ALL REMOTE/HYBRID AND/OR CALIFORNIA, DISTRICT OF COLUMBIA, HAWAII, COLORADO, MARYLAND, CONNECTICUT, ILLINOIS, MINNESOTA, VERMONT, MASSACHUSETTS, NEVADA, NEW YORK, RHODE ISLAND, WASHINGTON STATE & CINCINNATI, OHIO, JERSEY CITY, NEW JERSEY, TOLEDO, OHIO BASED ROLES. 

Note: Due to the nature of the work, only US Persons (citizens or permanent residents) need apply for this position. - OPTIONAL