ForgeApply · Job listing
Senior DevSecOps Engineer
ALTEN Technology USA
See all 142 open roles at ALTEN Technology USA →
Tailor your resume for this ALTEN Technology USA job in about a minute.
ForgeApply rewrites your resume for this exact posting, then autofills the application on ALTEN Technology USA's site with it. You review everything before it's sent. Free trial, no card required.
About this role
We’re ALTEN Technology USA, an engineering company helping clients bring groundbreaking ideas to life—from advancing space exploration and life-saving medical devices to building autonomous electric vehicles. With 3,000+ experts across North America, we partner with leading companies in aerospace, medical devices, robotics, automotive, commercial vehicles, EVs, rail, and more.
As part of the global ALTEN Group—57,000+ engineers in 30 countries—we deliver across the entire product development cycle, from consulting to full project outsourcing.
When you join ALTEN Technology USA, you’ll collaborate on some of the world’s toughest engineering challenges, supported by mentorship, career growth opportunities, and comprehensive benefits. We take pride in fostering a culture where employees feel valued, supported, and inspired to grow.
NO CLIENT NAME
As a Sr DevSecOps Engineer you will be responsible for;
· Define and own the DevSecOps architecture and roadmap for embedded capital equipment platforms, including CI/CD pipelines, build infrastructure, security automation, release evidence, and long-term maintainability.
· Develop and maintain secure embedded platform software, build infrastructure, and reusable automation capabilities.
· Create and support Yocto-based embedded Linux distributions, BSP software, device drivers, hypervisors, and platform-level OS components.
· Establish secure software supply chain practices, including SBOM generation, SOUP/OTS component tracking, license awareness, vulnerability monitoring, end-of-support tracking, and remediation workflows.
· Develop reusable CI/CD templates and pipeline controls for static analysis, software composition analysis, unit test automation, artifact signing, provenance tracking, cybersecurity evidence capture, and release readiness.
· Lead threat modeling and cybersecurity risk analysis for embedded platform components, including asset identification, attack surface analysis, exploitability assessment, security controls, and traceability to risk mitigations.
· Drive CVE intake, enrichment, asset mapping, triage, risk scoring, remediation planning, validation, and reporting in partnership with Product Security, SWQA, Systems, and program teams.
· Design and implement secure boot, firmware signing, cryptographic configuration, key/certificate lifecycle support, authenticated update mechanisms, and secure device communication patterns.
· Define runtime security monitoring requirements and support post-market cybersecurity monitoring and vulnerability response workflows.
· Review reported anomalies, assess cybersecurity impact, and support incident-response activities as needed.
· Support regulatory submissions and audits by ensuring cybersecurity, software lifecycle, and DevSecOps evidence is complete, traceable, reproducible, and aligned with internal quality system expectations.
· Define platform-level OS and BSP maintenance strategies, including Linux kernel support, Yocto release planning, driver update strategy, patchability, and security update governance across the product lifecycle.
· Collaborate with external vendors and internal partners to evaluate security tooling, embedded Linux support models, vulnerability intelligence, penetration testing outputs, and long-term maintenance approaches.
· Provide technical leadership and mentoring to software engineers, DevOps engineers, and platform teams on secure coding, build automation, vulnerability handling, and regulated software development practices.
· Partner with product teams to define platform capabilities that are reusable, secure, testable, and scalable across multiple capital equipment programs.
· Technologies & Tools
· AMD Zynq and Zynq UltraScale+ SoCs, NVIDIA ORIN, SafeRTOS, FreeRTOS
· Yocto-based embedded Linux package development
· Embedded hypervisors, Linux device drivers, BSPs, and boot flows
· Custom build systems and CI/CD pipelines
· Docker, Snyk, SonarQube, and software composition analysis tools
· Static analysis, software composition analysis, artifact signing, and vulnerability management tools
· Python, Bash, and Go
· Atlassian tools including Bitbucket, Jira, Bamboo, and Confluence
· GitHub and GitLab
· Networking security, secure boot, firmware signing, and secure update technologies
Qualifications;
· Strong experience in embedded Linux platform development for regulated, safety-critical, or high-reliability products.
· Hands-on experience with AMD/Xilinx SoC-based embedded systems, including AMD Zynq 7000 series, Zynq UltraScale+, Kria SOM, and the NVIDIA ORIN platform. Experience with real-time operating systems such as SafeRTOS and QNX Neutrino.
· Experience with Yocto, BSPs, OS layers, kernel configuration, boot flows, device drivers, and embedded platform security.
· Experience developing or governing DevSecOps practices in regulated medical device, safety-critical, aerospace, automotive, or industrial control environments.
· Strong understanding of FDA cybersecurity expectations, IEC 62304, ISO 14971, ISO 13485, SOUP/OTS software management, SBOM practices, and software lifecycle evidence generation.
· Experience implementing security automation in CI/CD pipelines, including SAST, SCA, container scanning, artifact signing, build reproducibility, traceability, and vulnerability reporting.
· Strong experience with threat modeling, vulnerability assessment, cybersecurity risk analysis, and secure-by-design architecture reviews.
· Experience with CVE triage methods that include exploitability, asset exposure, configuration applicability, runtime reachability, known exploited vulnerabilities, and remediation validation.
· Ability to collaborate across hardware, software, systems, product security, quality, regulatory, program management, and product management stakeholders.
· Demonstrated ability to influence cross-functional engineering and leadership decisions without direct authority.
· Experience defining reus
Salary insight
The midpoint of this range ($138k) is about 12% above the median disclosed salary for Denver roles listed on ForgeApply ($123k across 912 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this ALTEN Technology USA role before you apply.
Tailor my resume for this jobSimilar jobs
- Senior DevSecOps Engineer — Pactfi · New York, NY
- Senior DevSecOps Engineer — Campminder · Boulder, CO or remote
- Senior DevSecOps Engineer — Trexsolutions · Remote
- Senior DevSecOps Engineer — Hyperproof · Portland, OR
- Senior DevSecOps Engineer — Generac · Denver, CO - USA | Waukesha, WI - USA
- Senior DevSecOps Software Engineer — TTM · Farmingdale, NY
- Senior DevOps Engineer — Copart · Dallas, TX - Headquarters
- Senior DevOps Engineer — NTT · Michigan, United States
Free ATS checker · How to Autofill Greenhouse Job Applications (Without Sending Junk)