DevSecOps Engineer – Embedded Firmware Security

Actalentservices — Canada · Posted ~1 day ago

Senior

Skills

DevSecOps Embedded firmware security CI/CD Artifact signing Secrets management PKI OTA update security Vulnerability management Cybersecurity compliance OTA Embedded systems Cloud IoT

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A high-impact DevSecOps role focused on securing the complete lifecycle of connected embedded firmware. Responsibilities include securing CI/CD pipelines, artifact signing, secrets, PKI, OTA updates, vulnerability management, and cybersecurity compliance while collaborating across firmware, hardware, QA, IoT, cloud, product, and manufacturing functions.

Highlights

High-visibility security role with ownership of the full embedded firmware lifecycle, exposure to embedded systems, cloud and cybersecurity, and the opportunity to shape security strategy across development, manufacturing, and deployment.

Description

DevSecOps Engineer (Embedded Firmware Security) Job Description The Embedded DevSecOps Engineer is responsible for securing the full firmware development lifecycle for a next-generation connected embedded controller platform. You will own firmware security across CI/CD pipelines, artifact signing, secrets management, PKI infrastructure, OTA update security, vulnerability management, and cybersecurity compliance initiatives. In this highly visible role, you work closely with firmware, hardware, QA, IoT, product, and manufacturing teams to ensure security is embedded throughout the product lifecycle, from development and manufacturing through deployment and field updates. This position offers the opportunity to shape the security strategy for cutting-edge connected products while operating at the intersection of embedded systems, cloud technologies, and cybersecurity. Responsibilities Own and secure the end-to-end firmware development lifecycle for connected embedded controller platforms, from design through deployment and field updates.Design, build, and maintain secure CI/CD pipelines specifically tailored for firmware and embedded products.Implement and manage firmware artifact signing processes, ensuring integrity and authenticity of all released binaries.Establish and oversee secrets management practices for build environments, deployment workflows, and embedded devices.Design, operate, and maintain PKI infrastructure, including X.509 certificate management and device identity lifecycle.Implement and enforce Secure Boot and hardware Root of Trust mechanisms across embedded platforms.Manage HSM/KMS-backed key management processes, ensuring secure generation, storage, rotation, and usage of cryptographic keys.Lead vulnerability management activities, including CVE triage, remediation planning, and risk management for embedded and IoT products.Configure, integrate, and optimize SAST, SCA, and SBOM tools within firmware CI/CD pipelines to continuously improve code and dependency security.Conduct threat modeling and security risk assessments for embedded controllers, IoT products, and related services, and translate findings into actionable controls.Drive embedded and IoT product security initiatives, ensuring security requirements are integrated into firmware, hardware, and cloud architectures.Collaborate closely with firmware, hardware, QA, product, manufacturing, and IoT teams to embed security best practices into daily engineering workflows.Support OTA firmware update security by defining secure update mechanisms, validation processes, and rollback strategies.Contribute to cybersecurity compliance efforts, including security audit support and evidence collection for standards such as IEC and EN.Develop and maintain DevSecOps metrics and reporting that clearly communicate security posture, vulnerabilities, and progress to engineering leadership.Help build, mature, and continuously improve the embedded cybersecurity function, including processes, tooling, and standards.Provide guidance and technical leadership on embedded, IoT, and industrial automation security topics across the engineering organization.Participate in security incident analysis related to firmware or embedded systems and support remediation and prevention strategies.Document security architectures, processes, and procedures to ensure repeatability, transparency, and effective knowledge sharing. Essential Skills 5+ years of experience in DevOps, DevSecOps, Embedded Software, or Firmware Engineering.2+ years of experience focused specifically on cybersecurity or security engineering.Proven experience building and maintaining CI/CD pipelines for firmware or embedded products.Hands-on experience with firmware artifact signing and secure management of secrets in build and deployment workflows.Strong understanding of Secure Boot, hardware Root of Trust, and core firmware security concepts.Practical experience in vulnerability management, including CVE triage, remediation planning, and risk management.Experience working with SAST tools, software composition analysis (SCA), and generating and managing SBOMs.Solid background in PKI and certificate management, including X.509, device certificates, and full certificate lifecycle management.Experience with HSM/KMS-backed key management solutions for secure cryptographic key handling.Experience working with Docker and containerized build environments to support secure and reproducible firmware builds.Hands-on experience with CI/CD tools such as Jenkins, Bitbucket, GitLab CI, GitHub Actions, or similar platforms.Experience performing threat modeling and security risk assessments for embedded or connected systems.background in embedded, IoT, industrial automation, automotive, or other connected device environments. Additional Skills & Qualifications Experience with RTOS environments such as FreeRTOS, Zephyr, or ThreadX.Knowledge of OTA firmware update security, including secure delivery, validation, and rollback mechanisms.Experience with Embedded Linux in the context of product and platform security.background in manufacturing provisioning and factory certificate injection processes.Familiarity with IEC compliance requirements related to industrial or embedded systems security.Familiarity with EN compliance standards relevant to product and cybersecurity.Understanding of wireless security, including Wi-Fi, BLE, and RF protocol security considerations.Advanced experience with Docker and containerized build environments for secure and scalable firmware pipelines.Experience administering Bitbucket or similar source control and CI/CD platforms with a security focus.Experience with security audit support and cybersecurity compliance evidence management.Strong interest in learning, innovation, and continuous improvement within embedded cybersecurity and DevSecOps.Ability to work effectively in a highly collaborative, cross-functional engineering environment. Work Environment This is a highly collaborative role that works closely with firmware, hardware, QA, product, manufacturing, and IoT teams within a global engineering organization. You will partner with another cybersecurity engineer and engage directly with engineering leadership, giving you significant visibility and influence over product security strategy and best practices. The position follows a hybrid work model, typically requiring 1–2 days per week onsite or one week per month onsite, offering flexibility while maintaining strong team interaction. The environment emphasizes learning, innovation, and continuous improvement, with opportunities to help build and mature the embedded cybersecurity function. You will operate at the intersection of embedded systems, cloud technologies, and cybersecurity, using modern CI/CD tooling, containerized build environments, and advanced PKI and key management solutions to secure next-generation connected products. Job Type & Location This is a Contract position based out of Toronto, ON. Pay And Benefits The pay range for this position is $60.00 - $80.00/hr. Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job-related factors. Workplace Type This is a hybrid position in Toronto,ON. À propos d'Actalent Actalent est un leader mondial dans les services d’ingénierie et de sciences ainsi que dans les solutions de talents. Nous aidons des entreprises visionnaires à faire progresser leurs initiatives d’ingénierie et de science grâce à l’accès à des experts spécialisés qui favorisent l’échelle, l’innovation et la rapidité de mise sur le marché. Avec un réseau de près de 20 000 consultants et 5 000 clients à travers les États-Unis, le Canada, l’Asie et l’Europe, Actalent dessert de nombreuses entreprises du Fortune 500. Nous sommes fiers d’être l’une des 500 meilleures firmes de conception de l’Engineering News-Record (ENR) pour nos services de conception en ingénierie et un lauréat du prix ClearlyRated Best of Staffing® tant pour le service client que pour les talents. Actalent est un employeur souscrivant au principe de l’égalité des chances et accepte toutes les candidatures sans tenir compte de la race, du sexe, de l’âge, de la couleur, de la religion, des origines nationales, du statut d’ancien combattant, d’un handicap, de l’orientation sexuelle, de l’identité sexuelle, des renseignements génétiques ou de toute autre caractéristique protégée par la loi. Si vous souhaitez faire une demande d’accommodement raisonnable, tel que la modification ou l’ajustement du processus de demande d’emploi ou d’entrevue à cause d’un handicap, veuillez envoyer un courriel à actalentaccommodation@actalentservices.com pour connaître d’autres options d’accommodement. Ordonnance sur l’égalité des chances de San Francisco: Conformément à l’Ordonnance sur l’égalité des chances de San Francisco, pour tous les postes situés dans la ville et le comté de San Francisco, nous examinerons les candidatures des personnes qualifiées ayant un casier judiciaire ou des antécédents criminels. Utilisation de l’intelligence artificielle (IA): Nous pouvons utiliser l’intelligence artificielle (IA) pour soutenir certaines étapes de notre processus d’embauche, notamment la recherche, la présélection et l’évaluation des candidatures. L’IA aide à analyser les candidatures et les qualifications, mais les décisions finales sont prises par notre équipe de recrutement. En soumettant votre candidature, vous reconnaissez et acceptez que celle-ci puisse être examinée à l’aide d’outils d’IA. About Actalent Actalent is a global leader in engineering and sciences services and talent solutions. We help visionary companies advance their engineering and science initiatives through access to specialized experts who drive scale, innovation and speed to market. With a network of almost 20,000 consultants and 5,000 clients across the U.S., Canada, Asia and Europe, Actalent serves many of the Fortune 500. We are proud to be an Engineering News-Record (ENR) Top 500 Design Firm for our engineering design services and a ClearlyRated Best of Staffing® winner for both client and talent service. The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law. If you would like to request a reasonable accommodation, such as the modification or adjustment of the job application process or interviewing process due to a disability, please email actalentaccommodation@actalentservices.com for other accommodation options. San Francisco Fair Chance Ordinance: Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records. Use of Artificial Intelligence (AI):We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools.