
DevSecOps Engineer (Yocto, BitBake)
- New Castle, DE
- Permanent
- Full-time
- Support development and management of Yocto-based embedded Linux build systems
- Customize Linux distributions using Yocto tools and recipes
- Troubleshoot build failures and implement timely fixes.
- Research and integrate new technologies to improve build infrastructure and automation workflows.
- Design and implement secure automation for development, test, and production environments.
- Manage and maintain infrastructure security and monitoring systems.
- Maintain detailed documentation of build processes, security protocols, and automation workflows.
- Provide guidance on cloud security best practices (IAM, network segmentation, encryption) and on-premises system hardening.
- Work closely with software QA and product security teams to ensure compliance.
- Develop and maintain CI/CD pipelines across multiple environments (GitHub Actions, Azure Pipelines, Artifactory, etc.)
- Employ version control (Git) best practices for embedded environments.
- Collaborate with cross-functional teams to improve engineering tools, processes, and data security.
- Mentor colleagues on security and automation best practices.
- Actively participate in team meetings and cross-product collaboration
- Take ownership of continuous improvement initiatives
- Share knowledge through formal and informal training sessions and demos
- Demonstrate ongoing technical growth and curiosity
- Bachelor's Degree preferred, or equivalent combination of education, training, and experience
- 5 years of relevant experience building, designing, and implementing CI/CD pipelines for Yocto, Debian or Ubuntu custom Linux-based organization for embedded and IoT devices.
- Experience working with BitBake, receipts, metadata and layers is a must-have
- Experience using Linux software update open-source utility is important
- Proficient with scripting languages such as Python, or Bash.
- Strong understanding of cloud security best practices and IAM management.
- Strong communication and collaboration skills, with experience working in cross-functional teams.
- Proficient with build tools and pipelines such as GitHub Actions, Azure Pipelines, Artifactory, etc.
- Experience with logging, performance monitoring, and performance tuning tools.
- Experience with container runtimes and orchestration tools such as Docker or Kubernetes.