remotely.living

Senior C++ Developer

Codemotion · Remote - Worldwide · 2026-09-15

Apply for this job

Job description

We are looking for a strong Embedded Developer with Product Security experience to join a hands-on project focused on bringing an existing embedded product in line with the EU Cyber Resilience Act (CRA) requirements ahead of the 2027 deadline.

This is not a pure compliance or audit role. You will work directly with firmware, product security, and a large, long-lived codebase alongside an experienced in-house engineering team.

What you will do

- Implement Secure-by-Design / Secure-by-Default practices in firmware;

- Work on authentication, access control, encryption, and attack-surface reduction;

- Implement signed and authenticated firmware updates, including automatic updates, opt-out, and rollback;

- Develop device identity management and PKI integration;

- Implement security logging, monitoring, and secure data deletion;

- Set up machine-readable SBOM tooling and integrate it into the build process;

- Establish vulnerability triage and remediation workflows;

- Support security fixes that can be released independently from functional releases;

- Perform firmware security testing, including fuzzing and penetration testing;

- Use AI assistants to understand unfamiliar parts of the codebase, trace data flows, and identify security risks;

- Create technical documentation covering architecture, risk assessment, and SBOM references.

What we are looking for

- Strong hands-on experience with C/C++;

- Solid Embedded Linux experience;

- Experience with Yocto;

- Proven product security experience on shipped hardware;

- Practical knowledge of Secure Boot, firmware signing, and secure firmware updates;

- Experience with PKI and device identity;

- Experience with vulnerability triage, remediation, coordinated disclosure, and security advisories;

- Experience with firmware fuzzing and penetration testing;

- IoT or Industrial Control Security experience is highly desirable;

- Comfortable working in a large legacy codebase;

- Experience using AI assistants as part of everyday engineering workflows.

Tech Stack

C, C++, Embedded Linux, Yocto, PKI, Secure Boot, Firmware Signing, SBOM, Fuzzing, Penetration Testing