Firmware Manager - CRA Compliance, Marine

Copeland

$110K — $130K *
Telecommunications & Hardware
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s or Master’s degree in Computer Engineering, Electrical Engineering, Computer Science, or equivalent experience.
  • 8+ years of experience in embedded firmware development (C/C++, RTOS, bare-metal, Embedded Linux).
  • 3+ years of engineering management or supervisory experience.
  • Experience with implementing firmware security primitives such as Secure Boot and cryptographic hardware.
  • Hands-on knowledge of security frameworks and regulatory compliance standards, particularly the EU Cyber Resilience Act.

Responsibilities

  • Drive design and implementation of firmware security controls compliant with CRA standards.
  • Establish automated generation and maintenance of Software Bill of Materials (SBOM) in build pipelines.
  • Direct development of secure, cryptographically signed Over-the-Air (OTA) update mechanisms.
  • Implement processes for vulnerability and incident management to meet CRA reporting mandates.
  • Oversee technical documentation and compliance testing for CRA CE marking and audits.
  • Mentor and grow a team of firmware engineers while promoting security principles.
  • Balance feature delivery with compliance and security debt management.

Benefits

  • Opportunity to lead and innovate within a rapidly evolving IoT security landscape.
  • Engagement with cross-functional teams enhancing collaboration and professional growth.
  • Be at the forefront of compliance with the latest EU cybersecurity frameworks.
  • Potential for professional development in embedded systems and security technologies.
Full Job Description

Job Summary

We are seeking an experienced Firmware Engineering Manager to lead our embedded systems team with a dedicated focus on technical execution and regulatory alignment under the EU Cyber Resilience Act (CRA). In this role, you will lead a team of firmware engineers building secure, scalable IoT products while ensuring our entire embedded architecture and software development lifecycle (SDLC) meet mandatory EU cybersecurity requirements.

You will bridge the gap between low-level firmware development, security architecture, and regulatory compliance—ensuring our devices are secure by design, maintain continuous vulnerability management, and support robust over-the-air (OTA) updates throughout their support lifecycle.

Key Responsibilities

Technical Leadership & CRA Implementation

  • Secure Architecture: Drive the design and implementation of firmware security controls aligned with CRA standards (e.g., ETSI EN 303 645, IEC 62443, ISO 27001), enforcing Hardware Root of Trust, Secure Boot, encrypted memory partitions, and secure key storage.
  • Automated SBOM & Dependency Management: Establish automated generation and maintenance of Software Bill of Materials (SBOM) (e.g., CycloneDX, SPDX) within build pipelines to maintain component transparency and track open-source dependencies.
  • Over-the-Air (OTA) & Patch Management: Direct the development of secure, cryptographically signed, and resilient OTA update mechanisms capable of delivering rapid security patches without bricking devices in the field.
  • Vulnerability & Incident Management: Implement processes to meet CRA reporting mandates—including 24-hour initial vulnerability alert capabilities, 72-hour notifications, and rapid patch deployment workflows.
  • Conformity & Technical Documentation: Oversee technical file generation, risk assessments, and compliance testing required for CRA CE marking and third-party conformity audits.

People & Team Management

  • Lead, mentor, and grow a team of embedded firmware engineers, fostering a culture prioritizing security-by-design and security-by-default principles.
  • Balance feature delivery roadmaps with compliance deadlines, security debt reduction, and refactoring efforts.
  • Conduct code reviews, establish secure coding standards (MISRA, CERT C), and integrate SAST/DAST/fuzz testing tools into CI/CD build environments.

Cross-Functional Collaboration

  • Partner closely with Product Management, Hardware Design, Legal/Compliance, and Cloud IoT teams to align hardware selection (e.g., Secure Elements, TPMs) with security standards.
  • Serve as the technical point of contact for external auditors, compliance bodies, and security researchers conducting vulnerability assessments or penetration testing.

Required Qualifications

  • Education: Bachelor’s or Master’s degree in Computer Engineering, Electrical Engineering, Computer Science, or equivalent practical experience.
  • Experience:
    • 8+ years of experience in embedded firmware development (C/C++, RTOS, bare-metal, or Embedded Linux), preferably for IoT devices.
    • 3+ years of experience in an engineering management, tech lead, or supervisory role.
    • Demonstrated experience implementing firmware security primitives: Secure Boot, cryptographic hardware (HSM, TPM, Secure Elements), TLS/mTLS, memory protection, and secure storage.
    • Hands-on knowledge of hardware/software security frameworks and regulatory compliance standards (e.g., EU Cyber Resilience Act, ETSI EN 303 645, NIST SP 800-213, IEC 62443).
    • Authorization to work in the United States - sponsorship will not be provided for this role.

Preferred Qualifications

  • Experience establishing automated SBOM pipelines and vulnerability scanning (e.g., CVE mapping).
  • Deep experience with microcontroller architectures (ARM Cortex-M/TrustZone, RISC-V, ESP32) and wireless protocols (BLE, Wi-Fi, Cellular IoT, Thread/Matter).
  • Knowledge of global IoT cybersecurity legislation beyond the EU (e.g., US Cyber Trust Mark, UK PSTI Act).
  • Active cybersecurity certification (e.g., CISSP, CSSLP, or CISM).

Similar Jobs

More Jobs at Copeland

More Telecommunications & Hardware Jobs

Find similar Firmware Manager - CRA Compliance, Marine jobs: