1

Yocto Jobs in Colorado (NOW HIRING)

Senior DevSecOps Engineer

Denver, CO

$117K - $161K/yr

Create and support Yocto-based embedded Linux distributions, BSP software, device drivers, hypervisors, and platform-level OS components. Establish secure software supply chain practices, including ...

New

Senior DevSecOps Engineer

Denver, CO

$117K - $161K/yr

... Yocto-based embedded Linux distributions, BSP software, device drivers, hypervisors, and platform-level OS components. · Establish secure software supply chain practices, including SBOM generation ...

Posted today

Senior DevSecOps Engineer

Denver, CO · On-site

$117K - $161K/yr

... Yocto-based embedded Linux distributions, BSP software, device drivers, hypervisors, and platform-level OS components. • Establish secure software supply chain practices, including SBOM generation ...

New

next page

Showing results 1-20

Yocto information

See Colorado salary details

$16

$27

$48

How much do yocto jobs pay per hour?

As of Aug 16, 2026, the average hourly pay for yocto in Colorado is $27.43, according to ZipRecruiter salary data. Most workers in this role earn between $20.24 and $32.12 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the Yocto position, and why are they important?

To thrive as a Yocto developer, you need a thorough understanding of embedded Linux systems, build automation, and cross-compilation, often supported by a degree in computer science, electrical engineering, or a related field. Familiarity with the Yocto Project build system, bitbake, and source code management tools such as Git is highly valued, as are relevant certifications in embedded systems or Linux. Strong problem-solving abilities, effective communication, and a collaborative spirit help you excel in cross-functional teams and address hardware-software integration challenges. These skills ensure you can efficiently build, customize, and maintain reliable embedded Linux distributions critical for complex embedded device projects.

What is a Yocto?

A Yocto job typically refers to a role focused on embedded Linux development using the Yocto Project, an open-source framework for creating custom Linux distributions. Professionals in this role work with BitBake recipes, layers, and metadata to configure and build embedded Linux systems. Responsibilities often include BSP (Board Support Package) development, kernel customization, and optimizing system performance for specific hardware. Experience with cross-compilation, package management, and build automation is essential for success in this role.

What are the common challenges faced by Yocto developers in their daily work?

Yocto developers often face challenges related to debugging complex build errors, managing custom hardware configurations, and ensuring compatibility across various embedded platforms. Keeping up with frequent updates in upstream libraries and security patches while maintaining custom code requires careful coordination and version control. Working closely with hardware engineers and application developers is essential to align system requirements and resolve integration issues effectively. These challenges offer opportunities to deepen technical expertise and improve troubleshooting skills within the embedded Linux environment.

What are the most commonly searched types of Yocto jobs in Colorado?

The most popular types of Yocto jobs in Colorado are:

Infographic showing various Yocto job openings in Colorado as of August 2026, with employment types broken down into 89% Full Time, 3% Part Time, and 8% Contract. Highlights an 89% Physical, 6% Hybrid, and 5% Remote job distribution, with an average salary of $57,062 per year, or $27.4 per hour.

$117K - $161K/yr

Full-time

Posted yesterday

New


Job description

NO CLIENT NAME

As a Sr DevSecOps Engineer you will be responsible for;

Define and own the DevSecOps architecture and roadmap for embedded capital equipment platforms, including CI/CD pipelines, build infrastructure, security automation, release evidence, and long-term maintainability.

Develop and maintain secure embedded platform software, build infrastructure, and reusable automation capabilities.

Create and support Yocto-based embedded Linux distributions, BSP software, device drivers, hypervisors, and platform-level OS components.

Establish secure software supply chain practices, including SBOM generation, SOUP/OTS component tracking, license awareness, vulnerability monitoring, end-of-support tracking, and remediation workflows.

Develop reusable CI/CD templates and pipeline controls for static analysis, software composition analysis, unit test automation, artifact signing, provenance tracking, cybersecurity evidence capture, and release readiness.

Lead threat modeling and cybersecurity risk analysis for embedded platform components, including asset identification, attack surface analysis, exploitability assessment, security controls, and traceability to risk mitigations.

Drive CVE intake, enrichment, asset mapping, triage, risk scoring, remediation planning, validation, and reporting in partnership with Product Security, SWQA, Systems, and program teams.

Design and implement secure boot, firmware signing, cryptographic configuration, key/certificate lifecycle support, authenticated update mechanisms, and secure device communication patterns.

Define runtime security monitoring requirements and support post-market cybersecurity monitoring and vulnerability response workflows.

Review reported anomalies, assess cybersecurity impact, and support incident-response activities as needed.

Support regulatory submissions and audits by ensuring cybersecurity, software lifecycle, and DevSecOps evidence is complete, traceable, reproducible, and aligned with internal quality system expectations.

Define platform-level OS and BSP maintenance strategies, including Linux kernel support, Yocto release planning, driver update strategy, patchability, and security update governance across the product lifecycle.

Collaborate with external vendors and internal partners to evaluate security tooling, embedded Linux support models, vulnerability intelligence, penetration testing outputs, and long-term maintenance approaches.

Provide technical leadership and mentoring to software engineers, DevOps engineers, and platform teams on secure coding, build automation, vulnerability handling, and regulated software development practices.

Partner with product teams to define platform capabilities that are reusable, secure, testable, and scalable across multiple capital equipment programs.

Technologies & Tools

AMD Zynq and Zynq UltraScale+ SoCs, NVIDIA ORIN, SafeRTOS, FreeRTOS

Yocto-based embedded Linux package development

Embedded hypervisors, Linux device drivers, BSPs, and boot flows

Custom build systems and CI/CD pipelines

Docker, Snyk, SonarQube, and software composition analysis tools

Static analysis, software composition analysis, artifact signing, and vulnerability management tools

Python, Bash, and Go

Atlassian tools including Bitbucket, Jira, Bamboo, and Confluence

GitHub and GitLab

Networking security, secure boot, firmware signing, and secure update technologies

Qualifications;

Strong experience in embedded Linux platform development for regulated, safety-critical, or high-reliability products.

Hands-on experience with AMD/Xilinx SoC-based embedded systems, including AMD Zynq 7000 series, Zynq UltraScale+, Kria SOM, and the NVIDIA ORIN platform. Experience with real-time operating systems such as SafeRTOS and QNX Neutrino.

Experience with Yocto, BSPs, OS layers, kernel configuration, boot flows, device drivers, and embedded platform security.

Experience developing or governing DevSecOps practices in regulated medical device, safety-critical, aerospace, automotive, or industrial control environments.

Strong understanding of FDA cybersecurity expectations, IEC 62304, ISO 14971, ISO 13485, SOUP/OTS software management, SBOM practices, and software lifecycle evidence generation.

Experience implementing security automation in CI/CD pipelines, including SAST, SCA, container scanning, artifact signing, build reproducibility, traceability, and vulnerability reporting.

Strong experience with threat modeling, vulnerability assessment, cybersecurity risk analysis, and secure-by-design architecture reviews.

Experience with CVE triage methods that include exploitability, asset exposure, configuration applicability, runtime reachability, known exploited vulnerabilities, and remediation validation.

Ability to collaborate across hardware, software, systems, product security, quality, regulatory, program management, and product management stakeholders.

Demonstrated ability to influence cross-functional engineering and leadership decisions without direct authority.

Experience defining reusable platform practices across multiple products, programs, hardware variants, or software release branches.

Strong debugging, problem-solving, and root-cause analysis skills.

Strong technical communication skills with the ability to translate cybersecurity and DevSecOps risks into actionable engineering and leadership decisions.

Salary Range: $125k-$150k

The actual salary offered is dependent on various factors including, but not limited to, location, the candidate's combination of job-related knowledge, qualifications, skills, education, training, and experience 

MANDATORY FOR ALL REMOTE/HYBRID AND/OR CALIFORNIA, DISTRICT OF COLUMBIA, HAWAII, COLORADO, MARYLAND, CONNECTICUT, ILLINOIS, MINNESOTA, VERMONT, MASSACHUSETTS, NEVADA, NEW YORK, RHODE ISLAND, WASHINGTON STATE & CINCINNATI, OHIO, JERSEY CITY, NEW JERSEY, TOLEDO, OHIO BASED ROLES. 

Note: Due to the nature of the work, only US Persons (citizens or permanent residents) need apply for this position. - OPTIONAL