Softgent · Chief Growth Officer
We are looking for an experienced Embedded Product Security Engineer to strengthen the security posture of our embedded software products and development ecosystem. In this role, you will work at the intersection of embedded software engineering, cybersecurity, and DevSecOps, helping development teams build secure, compliant, and maintainable products.
You will be responsible for implementing and operating vulnerability management processes, integrating security tooling into CI/CD pipelines, supporting secure software supply chain practices, and collaborating closely with engineering teams across complex embedded environments.
This position requires strong hands-on expertise in embedded C/C++ ecosystems, static analysis, software composition analysis, SBOM management, and automation using modern DevSecOps practices.
Your Responsibilities
Build and maintain end-to-end vulnerability management processes, including:
Configure, maintain, and optimize SAST and SCA tooling for embedded C/C++ projects using:
Prepare embedded C/C++ codebases for static analysis by managing:
Generate and maintain Software Bills of Materials (SBOMs) using standards such as:
Integrate security controls and automated security gates into CI/CD workflows using:
Support software repository migrations into GitHub from legacy platforms including:
Work across heterogeneous embedded environments and toolchains, including:
Develop automation and engineering tooling using:
Collaborate closely with software teams and technical stakeholders to:
Contribute to secure software development lifecycle (SSDLC) initiatives and product compliance activities.
Requirements
Proven experience in:
Strong practical knowledge of:
Hands-on experience with static and software composition analysis tools for C/C++ projects, especially:
Experience preparing embedded C/C++ projects for automated security analysis.
Knowledge of SBOM generation standards and software supply chain security practices.
Experience integrating security tooling into CI/CD pipelines, preferably with GitHub Actions.
Strong GitHub experience, including repository administration and migrations from legacy VCS platforms.
Solid understanding of embedded software development environments, including:
Practical scripting and automation skills using:
Strong communication skills and ability to collaborate effectively across multidisciplinary engineering teams.
Ability to work independently in complex, legacy, or heterogeneous technical environments.
Nice to Have
Experience with:
Familiarity with:
Experience supporting compliance or certification activities
Bachelor's
Mid-level (3-4 years) · Senior (5-7 years) · Expert and leadership (8+years)
Embedded C/C++
DevSecOps
Vulnerability Management
Static Analysis
Software Supply Chain
CISSP
CEH
Security+
CISM
CISA
English
IT Services and IT Consulting·11-50 employees
Download MeeBoss