Denver, COremote

Salary
$125,000–$150,000from the description
Posted
Aug 14, 2026
Location
Denver, CO
Last confirmed open
Sep 25, 2026

What this job asks for AI summary

A senior-level DevSecOps/security engineering role focused on embedded capital equipment platforms in regulated environments (medical device, aerospace, automotive). The position owns the DevSecOps architecture and roadmap end-to-end — spanning CI/CD pipelines, secure software supply chain, SBOM, threat modeling, CVE triage, secure boot, and firmware signing — while also providing technical leadership and mentoring to cross-functional engineering teams.

Senior level · Remote · Full-time

Must have (18)
YoctoEmbedded LinuxAMD ZynqNVIDIA ORINLinux device driversCI/CDSASTSBOMThreat modelingCVE triageSecure bootFirmware signingIEC 62304ISO 14971FDA cybersecurityPythonBashSafeRTOS, Freertos or Qnx Neutrino
Nice to have (10)
DockerSnykSonarQubeBitbucketJiraBambooConfluenceGitHub or GitLabGoISO 13485

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What gives you an edge
Yocto2%Embedded Linux5%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Python51%CI/CD45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 18, 2026. It is a model, not a headcount.

Why we read it this way (7)

SOC classification is a genuine judgment call: the role blends deep security analysis (threat modeling, CVE triage, cybersecurity risk analysis, secure-by-design architecture) with substantial embedded software development (Yocto, BSPs, device drivers, CI/CD pipeline code in Python/Bash/Go). Information Security Analysts (15-1212) was chosen because the security architecture, threat modeling, vulnerability management, and regulatory cybersecurity evidence work appear to be the primary differentiating scope; Software Developers (15-1252) is a strong runner-up given the hands-on embedded platform coding.

Location is not specified in the posting beyond a multi-state salary-disclosure notice and an indication the role may be remote or hybrid. No CBSA could be determined.

The posting notes 'only US Persons (citizens or permanent residents) need apply' — this is a citizenship/work-authorization gate, not a security clearance requirement.

SafeRTOS and QNX Neutrino are listed as RTOS alternatives in the qualifications; FreeRTOS is listed in the Technologies section as a named platform. All three are captured under the SafeRTOS skill entry as alternatives since the JD treats them as interchangeable RTOS options.

Technologies listed under the 'Technologies & Tools' section (Docker, Snyk, SonarQube, Atlassian tools, GitHub/GitLab, Go) are treated as preferred/stack context rather than hard gates, as that section is a stack narrative rather than a requirements block.

ISO 13485 appears only in the qualifications narrative alongside other regulatory standards; it is marked preferred as the JD's firm language centers on IEC 62304, ISO 14971, and FDA cybersecurity guidance.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): BSP development.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗