Embedded DevSecOps Engineer (Pune)

Embedded DevSecOps Engineer (Pune)

02 Aug
|
L4B Software
|
Pune

02 Aug

L4B Software

Pune

Pune · Hybrid · 5+ years

Build infrastructure, CI/CD, release automation, SBOM generation, and supply-chain security for Android and Linux platform development.

Hands-on builder. Not cloud DevOps.

If your instinct when a pipeline goes red is to SSH into the build box and find out why — not file a ticket for someone else to look at — keep reading. This isn't a Kubernetes-and-Terraform seat. It's the person who keeps Android and Linux builds actually building, and who can prove exactly what shipped inside them.

Why this role exists

This role sits across — MediTUX, AutoTUX, SpaceTUX, and TUX Core. Every one of them depends on Android and Linux builds that just work, releases that can be reproduced and trusted, and a explicit, provable record of what's actually inside what ships. That's what this role owns: the infrastructure and automation that turns engineering work into something releasable, with the evidence to back it up. This enables engineering velocity and release confidence — not as a slogan, as the actual job.

What you'll own

Build Infrastructure

- Own Ubuntu build systems, build agents, build runners, and build farm health
- Debug builds across Android, AOSP, Yocto, and embedded Linux

CI/CD

- Set up and maintain GitLab CI, Jenkins, GitHub Actions, and Azure DevOps
- Be comfortable building everything from scratch — no inherited pipeline is sacred

Build Failure Analysis

- Diagnose toolchain, disk, memory, dependency, permission, and environment issues
- Independently recover broken pipelines — that's the , not an escalation

Release Engineering

- Own release packaging, artifact publishing, release versioning, and release notes




- Guarantee build reproducibility and generate real release evidence

SBOM & Supply Chain

- Implement Syft, SPDX, and CycloneDX
- Maintain the software bill of materials and open-source visibility across products

Security Pipeline

- Integrate Trivy, Grype, Snyk, Black Duck, Dependency-Track, and Yocto CVE checks into the build itself

Automation

- Build it yourself: Bash automation, Python tooling, validation automation, release automation

What you bring

- A Linux-first engineer — not someone who happens to touch Linux occasionally
- Real Jenkins/GitLab CI experience
- Build server administration
- Bash scripting
- Python scripting
- Experience with large native builds
- At least one of: AOSP, Android BSP, Yocto, firmware, or embedded Linux

Strong plus

- Artifactory, Nexus, or JFrog
- SBOM generation
- CVE pipelines
- Release evidence generation

Who this isn't for Not a fit for a Kubernetes administrator, a Terraform engineer, an AWS migration specialist, a cloud-only DevOps engineer, or someone whose CI/CD experience begins and ends with web apps. Those are all real, valuable skill sets — they're just not this one. This role lives in build farms, toolchains, and native compilation, not cloud consoles.

What success looks like after year one

- Linux and Android builds are fully automated
- The release process is reproducible, not tribal knowledge
- SBOM generation is automated
- CVE monitoring is automated
- Every release comes with a real evidence package
- Manual release activity is the exception, not the routine

How we hire Two rounds. Both hands-on, both with people who'll ask you to actually debug a broken build, not describe one in the abstract.

📌 Embedded DevSecOps Engineer (Pune)
🏢 L4B Software
📍 Pune

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: embedded devsecops engineer (pune) / pune

Subscribe to this job alert:

Get the latest job offers by email for: embedded devsecops engineer (pune) / pune