Senior Embedded Platform Engineer

Wangs Alliance Corporation
Austin, TX, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$130,000.0 - $140,000.0
Working hours
Regular working hours
Languages
Chinese
Job source

Tech stack

Board Bringup C (Programming Language) Application Programming Interfaces (APIs) Amazon Web Services Amazon S3 Bash Shell Booting (BIOS) UClibc (C Standard Library) C++ (Programming Language) Ubuntu (Operating System) Cloud Computing Continuous Integration
+47 more
Dynamic Host Configuration Protocol Debian Linux Software Debugging Linux File Systems Memory Management Linux on Embedded Systems Firmware GNU Debuggers Identity and Access Management Virtual Private Networks (VPN) Joint Test Action (IEEE Standards) Python (Programming Language) PostgreSQL Linux Kernel Linux System Administration Message Queuing Telemetry Transport (MQTT) Networking Basics Network Time Protocols OpenID Performance Tuning Public Key Infrastructure Release Management Cloud Services Prometheus Software Engineering Systems Integration Software Vulnerability Management Datadog Scripting Cloud Platform System Grafana Cloudformation Amazon Relational Database Service Yocto Information Technology Iptables Deployment Automation AWS Fargate Build Tools Route53 Hardware Infrastructure U-Boot Cloudwatch Firewall Services Module Terraform Docker

Job description

WAC Group is seeking a Senior Embedded Platform Engineer to own the on-premises appliance platform for the commercial smart lighting product line. This is a hands-on engineering role: you will design, build, and ship the appliance stack, zero-touch provisioning infrastructure, and OTA update systems that run-in customer facilities ranging from open to air gapped solutions. The ideal candidate combines deep Linux and edge systems expertise with working knowledge of AWS cloud services used to provision, manage, and connect deployed appliances at scale., * Design, build and maintain an embedded Linux platform including boot loaders, kernel, drivers and user space.

  • Board Bring-up: Collaborating with hardware engineers to bring up new hardware, debugging boot issues, configuring the device tree and testing performance.
  • System Building & Imaging: Creating and managing production-ready Linux images using build systems such as Yocto, Buildroot or custom spins of standard distributions such as Debian.
  • Platform Security: Implementing system hardening, secure boot, and managing vulnerability patches.
  • OTA Updates: Developing robust, secure over-the-air update mechanisms. Experience creating robust platforms that are hardened against power loss and failed OTA updates.
  • Performance Optimization: Tuning system boot time, memory usage, and power consumption.
  • Design and maintain the appliance stack - Docker Compose deployment, systemd services, containerized MQTT broker, local Postgres, OIDC auth sidecar, and WireGuard/Relay integration for zero-friction site deployment.
  • Build and maintain VM appliance images (OVA, QCOW2, VHDX) for Tier 1 site distribution.
  • Architect and implement zero-touch provisioning - device identity (serial + certificate), provisioning service integration, and automatic vpn setup. Controllers must boot-to-claimed with zero manual configuration.
  • Design and own the OTA update pipeline - signed manifest validation, atomic container updates, health-check-gated rollback strategies, and offline update paths via signed USB bundle for air-gapped deployments.
  • Partner with firmware, mobile, and cloud teams to define the appliance API surface, deployment contracts, and integration patterns between the on-premises console and Cloud Portal.
  • Evaluate and standardize the AWS cloud services used in the provisioning, relay, and management plane - including Fargate, Aurora, Cognito, and ECR - to meet performance, reliability, and cost targets.
  • Implement best practices for CI/CD, infrastructure-as-code, and release management to ensure reliable and repeatable appliance and cloud deployments.
  • Design and maintain monitoring and alerting for site health - heartbeat telemetry, update status reporting, and local diagnostics accessible to non-technical installers and customer IT staff.
  • Triage and resolve production issues related to device provisioning, updates, local connectivity, VPN tunnels, and on-premises infrastructure - prioritizing based on customer impact and SLA commitments.

Critical Success Factors:

  • Customer-Centered Execution Communicates complex technical concepts clearly, builds trust with customers and partners, and delivers solutions that meet real-world performance.

  • Technical Excellence & Rigor - Sets and enforces high standards for scalability, observability, security, and operational discipline. “Good enough” is not sufficient.
  • Systems Thinking & Intellectual Curiosity - Understands the full IoT ecosystem and anticipates downstream impacts. Continuously evaluates emerging technologies and architectural trade-offs.
  • End-to-End Ownership - Takes full accountability for the appliance platform’s architecture, reliability, security, and performance - proactively identifying risks and driving resolution across both on-premises and cloud tiers.
  • Cross-Functional Leadership - Aligns firmware, application, cloud, and product teams around cohesive architectural decisions that serve both technical and business objectives.

Requirements

Do you have experience in Vulnerability management?, * Bachelor’s degree in computer science, Electrical Engineering, or equivalent practical experience. 7+ years of software engineering experience, including 4+ years building and operating edge/appliance systems or production Linux infrastructure.

  • Expert-level Linux systems administration - Debian/Ubuntu, systems, apt/dpkg packaging, firewall configuration (UFW/iptables), and automated OS provisioning (preseed, cloud-init).
  • Languages: Strong Proficiency in C, C++, and scripting languages (Python, Bash).
  • Linux Internals: Deep understanding of the kernel, device tree, file systems and user-space libraries.
  • Build Systems: Expertise in Yocto/OpenEmbedded, Buildroot and rpi-image-gen.
  • Debugging: Experience with JTAG, GDB, and oscilloscopes for hardware/software debugging.
  • Proven experience with Docker and Docker Compose - service dependency management, container image optimization, health checks, and fleet-wide update strategies.
  • Hands-on experience with networking fundamentals - WireGuard, mDNS, NTP, DHCP, MQTT (EMQX or Mosquitto), and NAT traversal.
  • Working knowledge of AWS services relevant to IoT and edge deployments - Cognito, Fargate (ECS), Aurora/RDS, S3, Route 53, ECR, and IoT Core (or equivalent device provisioning infrastructure).
  • Experience with VM image creation (Packer, cloud-init) and multi-format appliance distribution (OVA, QCOW2, VHDX).
  • Familiarity with PKI and device certificate infrastructure - TLS client certificates, certificate authorities (step-ca or AWS Private CA), and key rotation strategies.
  • Experience with infrastructure-as-code (Terraform or CloudFormation), CI/CD pipeline design, and automated deployment strategies.
  • Hands-on experience with observability tooling (CloudWatch, Prometheus, Grafana, or equivalent).
  • Strong understanding of security best practices - identity and access management, encryption at rest and in transit, and vulnerability mitigation for edge-deployed systems.
  • Mandarin language proficiency is a plus.
  • Willingness to travel domestically and internationally as required.

Benefits & conditions

Pulled from the full job description

  • Tuition reimbursement
  • Health insurance
  • Paid time off
  • Dental insurance, We recognize people as our most valuable asset. Our competitive salary and benefits package include paid time off; medical & dental coverage (including family coverage), vision, life, 401(k); tuition assistance; and continuous training and development. For immediate consideration, please submit your resume as directed. Due to the high volume of applications, only candidates who meet the qualifications will be contacted.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

7:40 min

In-vehicle infotainment systems and graphical functional safety validation

Denis Grahovac · WWC 2021

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · WWC Europe 2026

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

Videos

See all

Related articles

See all