> Markdown version of [/jobs/ext/2170868-firmware-engineer](https://www.wearedevelopers.com/jobs/ext/2170868-firmware-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Firmware Engineer - **Company:** Insight Global - **Location:** Saint Paul, MN, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Agile Methodology, Software System Penetration Testing, Booting (BIOS), Software Bug Management, C++ (Programming Language), CAN Bus, Code Review, Cyber Security, Computer Engineering, Linux, File Systems, Embedded Software, Firmware, Hardware Security Module, Joint Test Action (IEEE Standards), Network Security, Modbus, Open Web Application Security, Package Development Process, Scrum Methodology, Program Analysis, Real-Time Operating Systems, Secure Coding, Serial Communications, Software Engineering, Software Requirements Analysis, Transmission Control Protocol (TCP), Universal Asynchronous Receiver/Transmitter, Software Vulnerability Management, EndPointSecurity, SSL Certificate Management, Data Logging, Serial Peripheral Interface, Backend, Information Technology, Bare Metal, U-Boot, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 21, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3361171111&tx=JP8781FFQ&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role Bachelor's degree in Computer Engineering, Computer Science, Electrical Engineering, Cybersecurity, or a similar technical degree. - 5 or more years' experience in software or firmware development in a fast-moving product development environment. - 3 or more years working in C or C++ for embedded firmware development. - Experience applying secure software development practices, including secure coding, code review, vulnerability remediation, and security defect management. - Experience with embedded RTOS or bare-metal development and security considerations for constrained devices. - Experience with serial communication protocols, such as UART, SPI, and I2C, and secure communication concepts for connected systems. - Experience with ARM-based microcontrollers, such as Microchip, NXP, Silicon Labs, or STMicroelectronics. - Experience with vulnerability management processes, CVE analysis, SBOM usage, dependency scanning, penetration test findings, and remediation verification. - Experience with cybersecurity frameworks or secure development standards such as NIST SSDF, IEC 62443, ISO 27001, OWASP, or secure product lifecycle practices. - Experience supporting embedded firmware platforms, board support package development, secure boot, secure storage, cryptographic services, or firmware update mechanisms. - Experience in one or more of the following areas: bootloaders, embedded file systems, Linux, CAN Bus, Modbus RTU, Modbus TCP, network security, device identity, or certificate management. - Experience with Agile development methodologies and integrating security activities into sprint planning, backlog management, release readiness, and defect triage. - Initiative and ability to work independently and as a member of a multi-disciplinary team while managing multiple security, development, or remediation priorities. - Strong communication skills, both verbal and written, with the ability to clearly explain technical security risks, remediation plans, and release impacts to technical and non-technical stakeholders. ## Description Partner with stakeholders, product teams, and security teams to define secure system requirements for embedded firmware, IoT edge devices, gateways, and backend-connected components. - Design, develop, and test secure firmware and IoT software using secure-by-design principles, including authentication, authorization, secure communications, encryption, logging, and secure update mechanisms. - Implement hardware security controls including secure elements, TPMs, hardware root of trust, and JTAG/SWD lockdown. - Apply memory safety practices and compiler hardening techniques to mitigate common C/C++ vulnerabilities. - Develop secure device provisioning workflows including key injection, certificate enrollment, and device identity lifecycle management. - Integrate secure cloud to device communication patterns such as mutual TLS, token based authentication, certificate rotation, and secure onboarding using cloud to device security. - Lead vulnerability triage, root-cause analysis, remediation planning, patch development, verification, and release coordination for embedded and IoT software components. - Perform and support threat modeling, secure code reviews, static and dynamic analysis, dependency scanning, and security testing throughout the software development lifecycle. - Participate in embedded incident response, coordinated disclosure, and rapid hotfix development for fielded devices. - Design and implement secure OTA update pipelines including signing, encryption, rollback protection, A/B partitioning, and update integrity validation using secure OTA lifecycle best practices. - Integrate SAST, DAST, dependency scanning, and firmware specific security checks into CI/CD pipelines using secure CI/CD pipelines principles. - Collaborate with cross-functional teams, including hardware, software, product management, quality, regulatory, and external partners, to deliver secure connected products. - Stay current with cybersecurity standards, secure development practices, emerging vulnerabilities, tools, and techniques relevant to embedded systems and industrial IoT environments. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Optimizing Land-Based Fish Feeding with Node-RED](https://www.wearedevelopers.com/videos/2032-optimizing-land-based-fish-feeding-with-node-red) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [What is Software Engineering?](https://www.wearedevelopers.com/magazine/289-what-is-software-engineering) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Is Software Engineering Hard?](https://www.wearedevelopers.com/magazine/448-is-software-engineering-hard)