3 months ago
Sunnyvale, CA, USAStaff+
Base Salary
$189k - $267k/yr
Responsibilities
- Lead the on-device design and implementation of an automotive-grade Uptane client framework.
- Establish separate software verification paths for high-performance Primary ECUs and resource-constrained Secondary ECUs.
- Implement Uptane multi-repository validation using Director and Image repositories to prevent key compromise and mix-and-match attacks.
- Develop low-level firmware state machines that parse and validate cryptographic payloads, signatures, and thresholds for Root, Timestamp, Snapshot, and Targets roles.
- Orchestrate vehicle-level software bundles, including dependency tracking, compatibility resolution across internal networks, and atomic flashing execution.
- Bridge embedded vehicle subsystems with the Cloud/Infrastructure team through edge-to-cloud interfaces, time-attestation protocols, version manifests, and Uptane transport profiles.
- Optimize A/B slot switching, dual-bank execution, runtime validation fallbacks, on-device patching, delta compression, flash lifespan, and bus bandwidth.
- Develop safety-critical firmware in C and host-side tooling and secure payload wrapping in Python.
Requirements
- Experience or capability in designing secure embedded OTA update systems and Uptane architecture.
- Ability to implement cryptographic verification, metadata role validation, signatures, thresholds, and secure update orchestration.
- Ability to manage vehicle software dependencies, compatibility matrices, atomic flashing, and embedded-to-cloud integration.
- Experience with high-durability partition and memory architectures, A/B updates, dual-bank execution, and runtime validation fallback loops is preferred.
- Experience optimizing payload streaming, patching, delta compression, and storage or bandwidth usage across eMMC, UFS, and QSPI is preferred.
- Strong deterministic firmware development skills using C for bare-metal systems, custom bootloaders, and RTOS kernels is preferred.
- Experience using Python for host-side tooling and secure payload wrapping is preferred.
