Full-Time

Senior DevSecOps Engineer

Updated on 8/17/2026

ALTEN Technology

ALTEN Technology

501-1,000 employees

Full-service engineering services for high-tech

Compensation Overview

$125k - $150k/yr

No H1B Sponsorship

Denver, CO, USA

In Person

US Citizenship Required

Category
DevOps & Infrastructure (1)
Required Skills
Bash
Python
Incident Response
Software Testing
Git
SonarQube
Threat modeling
FreeRTOS
Docker
Go
JIRA
Cryptography
Penetration Testing
Confluence
DevOps
Linux/Unix

Get referred to ALTEN Technology

See people who can refer or advise you

Requirements
  • Strong experience in embedded Linux platform development for regulated, safety-critical, or high-reliability products.
  • Hands-on experience with AMD/Xilinx SoC-based embedded systems, including AMD Zynq 7000 series, Zynq UltraScale+, Kria SOM, and the NVIDIA ORIN platform, plus real-time operating systems such as SafeRTOS and QNX Neutrino.
  • Experience with Yocto, board support packages, operating system layers, kernel configuration, boot flows, device drivers, and embedded platform security.
  • Experience developing or governing DevSecOps practices in regulated medical device, safety-critical, aerospace, automotive, or industrial control environments.
  • Strong understanding of FDA cybersecurity expectations, IEC 62304, ISO 14971, ISO 13485, SOUP/OTS software management, SBOM practices, and software lifecycle evidence generation.
  • Experience implementing security automation in continuous integration and continuous delivery pipelines, including static application security testing, software composition analysis, container scanning, artifact signing, build reproducibility, traceability, and vulnerability reporting.
  • Strong experience with threat modeling, vulnerability assessment, cybersecurity risk analysis, and secure-by-design architecture reviews.
  • Experience with CVE triage methods that include exploitability, asset exposure, configuration applicability, runtime reachability, known exploited vulnerabilities, and remediation validation.
  • Ability to collaborate across hardware, software, systems, product security, quality, regulatory, program management, and product management stakeholders.
  • Demonstrated ability to influence cross-functional engineering and leadership decisions without direct authority.
  • Experience defining reusable platform practices across multiple products, programs, hardware variants, or software release branches.
  • Strong debugging, problem-solving, and root-cause analysis skills.
  • Strong technical communication skills with the ability to translate cybersecurity and DevSecOps risks into actionable engineering and leadership decisions.
Responsibilities
  • Define and own the DevSecOps architecture and roadmap for embedded capital equipment platforms, including continuous integration and continuous delivery pipelines, build infrastructure, security automation, release evidence, and long-term maintainability.
  • Develop and maintain secure embedded platform software, build infrastructure, and reusable automation capabilities.
  • Create and support Yocto-based embedded Linux distributions, board support package software, device drivers, hypervisors, and platform-level operating system components.
  • Establish secure software supply chain practices, including software bill of materials generation, SOUP/OTS component tracking, license awareness, vulnerability monitoring, end-of-support tracking, and remediation workflows.
  • Develop reusable continuous integration and continuous delivery templates and pipeline controls for static analysis, software composition analysis, unit test automation, artifact signing, provenance tracking, cybersecurity evidence capture, and release readiness.
  • Lead threat modeling and cybersecurity risk analysis for embedded platform components, including asset identification, attack surface analysis, exploitability assessment, security controls, and traceability to risk mitigations.
  • Drive CVE intake, enrichment, asset mapping, triage, risk scoring, remediation planning, validation, and reporting in partnership with Product Security, software quality assurance, Systems, and program teams.
  • Design and implement secure boot, firmware signing, cryptographic configuration, key and certificate lifecycle support, authenticated update mechanisms, and secure device communication patterns.
  • Define runtime security monitoring requirements and support post-market cybersecurity monitoring and vulnerability response workflows.
  • Review reported anomalies, assess cybersecurity impact, and support incident-response activities as needed.
  • Support regulatory submissions and audits by ensuring cybersecurity, software lifecycle, and DevSecOps evidence is complete, traceable, reproducible, and aligned with internal quality system expectations.
  • Define platform-level operating system and board support package maintenance strategies, including Linux kernel support, Yocto release planning, driver update strategy, patchability, and security update governance across the product lifecycle.
  • Collaborate with external vendors and internal partners to evaluate security tooling, embedded Linux support models, vulnerability intelligence, penetration testing outputs, and long-term maintenance approaches.
  • Provide technical leadership and mentoring to software engineers, DevOps engineers, and platform teams on secure coding, build automation, vulnerability handling, and regulated software development practices.
  • Partner with product teams to define platform capabilities that are reusable, secure, testable, and scalable across multiple capital equipment programs.

ALTEN Technology provides engineering services to help clients design and develop advanced technology products. It works by offering a range of engineering capabilities, including agile software development, custom software solutions, and integration of commercial and open-source software to cut costs. This collaborative model supports projects across high-impact sectors like aerospace, medical devices, and automotive technology by tailoring solutions to each client’s needs and reducing project risks. The company’s goal is to enable customers to bring innovative products to market more efficiently through flexible, end-to-end engineering services and long-term partnerships.

Company Size

501-1,000

Company Stage

M&A

Total Funding

N/A

Headquarters

Greensboro, North Carolina

Founded

1988

Get referred to ALTEN Technology

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • ALTEN posted 2025 revenue growth of 9.4% and 10.8% operating margin.
  • ALTEN Technology’s 2026 job board shows 149 openings, signaling active client demand.
  • June 2026 automotive and May 2026 medtech updates show continued product-line expansion.

What critics are saying

  • ALTEN Group reported Q1 2026 revenue down 0.8%, with North America still weak.
  • Automotive consulting faces OEM and Tier-1 layoffs, squeezing project demand and pricing.
  • A prolonged North American slowdown would hit ALTEN Technology’s U.S. footprint and hiring engine.

What makes ALTEN Technology unique

  • ALTEN Technology merged Syncroness on April 1, 2022, unifying U.S. delivery under one brand.
  • Denver’s AS9100 and ITAR-compliant center serves aerospace programs across design, verification, and manufacturing.
  • The company spans aerospace, automotive, and medtech with 149 open roles across U.S. hubs.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

401(k) Company Match

Paid Vacation

Paid Parental Leave

Company News

PR Newswire
Apr 1st, 2022
ALTEN Technology USA and Syncroness Merge to Strengthen US Engineering Service Offerings

/PRNewswire/ -- ALTEN Technology USA Inc. and Syncroness Inc. have merged under the name ALTEN Technology USA Inc. This merger combines decades of...