> Markdown version of [/jobs/ext/2162643-senior-embedded-software-engineer-security-rust-c](https://www.wearedevelopers.com/jobs/ext/2162643-senior-embedded-software-engineer-security-rust-c). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Embedded Software Engineer - Security / Rust & C++ - **Company:** APRIORI - business solutions AG - **Location:** Berlin, Germany - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software Applications, User Authentication, Automation of Tests, UClibc (C Standard Library), C++ (Programming Language), Code Review, Cyber Security, Computer Programming, Continuous Integration, Linux on Embedded Systems, Embedded Software, Firmware, Python (Programming Language), Public Key Infrastructure, Software Engineering, Yocto, Gitlab-ci, Information Technology, Operational Systems, Devsecops - **Published:** August 21, 2026 - **Apply:** https://www.adzuna.de/details/5849650704 ## About the Role * Ausbildung: Abgeschlossenes Studium der Elektrotechnik, Informatik oder eine vergleichbare Qualifikation. * Berufserfahrung: Mehrjährige Erfahrung (ab ca. 5 Jahren) in der Embedded-Fullstack-Entwicklung, von der Low-Level-Firmware bis zur Anwendungssoftware. * Programmiersprachen: Solide Praxis in Rust sowie C/C++ (insb. C++23). * Betriebssysteme: Sicherer Umgang mit Embedded Linux (z. B. Yocto, Buildroot). * Embedded Security: Praktische Erfahrung mit Secure Boot, Image-Signierung, Kryptografie und Hardening. * Regulatorische Standards: Verständnis und Erfahrung bezüglich des EU Cyber Resilience Act (CRA) oder vergleichbarer regulatorischer Vorgaben. * Software-Engineering: Fundiertes Verständnis für saubere Softwareentwicklung (modulare Architektur, reproduzierbare Builds, nachvollziehbare Abhängigkeitsverwaltung). * Tools & KI: Aktiver Einsatz von KI-Coding-Tools im alltäglichen Entwicklungs-Workflow. * Sprachkenntnisse: Sehr gute Deutsch- und Englischkenntnisse (Teamkommunikation erfolgt überwiegend auf Deutsch, technische Dokumentationen teils auf Englisch). Damit punkten Sie zusätzlich (Nice-to-Have): * Python-Kenntnisse: Einsatz von Python für interne Tools und Test-Automatisierung. * DevSecOps & CI/CD: Praktische DevSecOps-Erfahrung in CI/CD-Pipelines (z. B. GitLab CI, Dependency- und Secret-Scanning). * Hardware-Sicherheit: Erfahrung im Umgang mit TPM, Secure Element oder PKI. * Domain-Know-how: Erfahrung im Bereich RF-/HF-Produkte. ## Description * Sichere Firmware & Anwendungssoftware entwickeln: Fullstack-Entwicklung von HAL/Treibern bis hin zu UI/API in Rust und C/C++23. * CRA-Compliance umsetzen: Gestaltung sicherer Update-Mechanismen, Mitwirkung an Software Bills of Materials (SBOMs), Vulnerability Handling und Erstellung von Release-Nachweisen entlang des gesamten Produktlebenszyklus. * Security-Architektur mitgestalten: Integration von Secure Boot, Kryptografie, Hardening, Secrets- und Zertifikatsmanagement sowie Threat Modeling in die Produktentwicklung. * HW/SW-Schnittstellen absichern: Implementierung sicherer Kommunikation, Authentifizierung und Schutz sensibler Daten auf dem Gerät. * Code-Qualität & Reviews verankern: Etablierung security-relevanter Code-Reviews, statischer Analysen und Prinzipien sauberer Softwareentwicklung im Team. * KI-gestützte Entwicklung nutzen: Produktives Arbeiten mit AI-Coding-Tools und aktiver Wissensaustausch über bewährte Verfahren im Team. ## Related Videos - [Agile work at CARIAD – Creating a customer web application for controlling the vehicle ](https://www.wearedevelopers.com/videos/200-agile-work-at-cariad-creating-a-customer-web-application-for-controlling-the-vehicle) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Navigating the Corporate Jungle: Life as a Developer in a large Company](https://www.wearedevelopers.com/videos/621-navigating-the-corporate-jungle-life-as-a-developer-in-a-large-company) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) ## Related Articles - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)