Senior Firmware Cybersecurity Software Engineer
Indexed description
Title: Senior Firmware Cybersecurity Software Engineer
Location: St. Paul, MN or Naperville, IL (3x per week hybrid, some flexibility)
Employment Type: Long term contract through end of 2026 with expected extension
Salary: 55-85/hr
A large Fortune 500 chemical manufacturing client is seeking a Senior Firmware Cybersecurity Software Engineer to architect, design, develop, and secure embedded firmware and IoT software solutions. This senior-level role will focus on secure software development, vulnerability remediation, threat-informed design, and continuous improvement of cybersecurity practices across connected devices, gateways, and supporting IoT platforms. The candidate will be part of a dynamic team helping support the client’s digital transformation by delivering secure, resilient IoT solutions that protect customer environments and enable trusted business outcomes.
What You Will Do:
- Partner with stakeholders, product teams, and security teams to define secure system requirements for embedded firmware, IoT edge devices, gateways, and backend-connected components.
- Design, develop, and test secure firmware and IoT software using secure-by-design principles, including authentication, authorization, secure communications, encryption, logging, and secure update mechanisms.
- Implement hardware security controls including secure elements, TPMs, hardware root of trust, and JTAG/SWD lockdown.
- Apply memory safety practices and compiler hardening techniques to mitigate common C/C++ vulnerabilities.
- Develop secure device provisioning workflows including key injection, certificate enrollment, and device identity lifecycle management.
- Integrate secure cloud‑to‑device communication patterns such as mutual TLS, token‑based authentication, certificate rotation, and secure onboarding using cloud‑to‑device security.
- Lead vulnerability triage, root-cause analysis, remediation planning, patch development, verification, and release coordination for embedded and IoT software components.
- Perform and support threat modeling, secure code reviews, static and dynamic analysis, dependency scanning, and security testing throughout the software development lifecycle.
- Participate in embedded incident response, coordinated disclosure, and rapid hotfix development for fielded devices.
- Design and implement secure OTA update pipelines including signing, encryption, rollback protection, A/B partitioning, and update integrity validation using secure OTA lifecycle best practices.
- Integrate SAST, DAST, dependency scanning, and firmware‑specific security checks into CI/CD pipelines using secure CI/CD pipelines principles.
- Collaborate with cross-functional teams, including hardware, software, product management, quality, regulatory, and external partners, to deliver secure connected products.
- Stay current with cybersecurity standards, secure development practices, emerging vulnerabilities, tools, and techniques relevant to embedded systems and industrial IoT environments.
Minimum Qualification:
- Bachelor’s degree in Computer Engineering, Computer Science, Electrical Engineering, Cybersecurity, or a similar technical degree.
- 5 or more years’ experience in software or firmware development in a fast-moving product development environment.
- 3 or more years working in C or C++ for embedded firmware development.
- Experience applying secure software development practices, including secure coding, code review, vulnerability remediation, and security defect management.
- Experience with embedded RTOS or bare-metal development and security considerations for constrained devices.
- Experience with serial communication protocols, such as UART, SPI, and I2C, and secure communication concepts for connected systems.
- Experience with ARM-based microcontrollers, such as Microchip, NXP, Silicon Labs, or STMicroelectronics.
- Experience with vulnerability management processes, CVE analysis, SBOM usage, dependency scanning, penetration test findings, and remediation verification.
- Experience with cybersecurity frameworks or secure development standards such as NIST SSDF, IEC 62443, ISO 27001, OWASP, or secure product lifecycle practices.
Preferred Qualifications:
- Experience supporting embedded firmware platforms, board support package development, secure boot, secure storage, cryptographic services, or firmware update mechanisms.
- Experience in one or more of the following areas: bootloaders, embedded file systems, Linux, CAN Bus, Modbus RTU, Modbus TCP, network security, device identity, or certificate management.
- Experience with Agile development methodologies and integrating security activities into sprint planning, backlog management, release readiness, and defect triage.
- Initiative and ability to work independently and as a member of a multi-disciplinary team while managing multiple security, development, or remediation priorities.
- Strong communication skills, both verbal and written, with the ability to clearly explain technical security risks, remediation plans, and release impacts to technical and non-technical stakeholders.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search