Job Summary
Own the software update and device lifecycle stack for connected edge products — robust A/B and image-based update mechanisms, rollback safety, fleet-scale rollout, and long-lifecycle maintenance across multiple product variants.
Key Responsibilities
- Design and implement robust OTA update mechanisms — A/B (dual-slot) updates, image-based updates (OSTree class), delta updates and container/application-level updates.
- Guarantee power-fail-safe, atomic updates with verified rollback and health-check driven commit logic.
- Integrate update flows with secure boot and signing infrastructure so only authenticated artefacts are installed.
- Build and maintain update agents, update servers/backends integration, and campaign/rollout tooling including staged and canary rollouts.
- Manage partition layouts, bootloader slot switching, filesystem strategy and storage wear considerations.
- Define device lifecycle management flows — enrolment, identity, configuration management, telemetry, remote diagnostics and decommissioning.
- Support long-lifecycle maintenance: LTS branching, CVE monitoring and security patch delivery across fielded variants.
- Build failure-injection and update regression testing including interrupted-update and downgrade scenarios.
Skill Requirements
- 8–10 years in embedded systems with strong ownership of update/lifecycle infrastructure.
- Hands-on with A/B update schemes and at least one framework such as RAUC, SWUpdate, Mender, OSTree/greenboot or Android A/B.
- Strong C and Python; shell scripting; comfort with build systems (Yocto) and image composition.
- Bootloader and partition-level knowledge — slot selection, boot counters, rollback protection.
- Signed-artefact workflows and integration with PKI/signing services.
- Fleet-scale thinking — bandwidth, staged rollout, failure rate monitoring, recovery paths.
- CI/CD pipeline experience for embedded artefact build, sign and publish.
Other Requirements
- Cloud IoT device management platforms (AWS IoT, Azure IoT Hub or equivalent).
- Container-based edge deployment (Docker, Podman, balena-style workflows).
- Filesystem expertise — ext4, F2FS, UBIFS, SquashFS, dm-verity.
- Regulatory-driven update obligations (EU CRA, IEC 62443 patch management).
- Telemetry and observability pipelines for fielded devices.