You'll own firmware end-to-end on safety-critical embedded systems. Our products run on ARM Cortex-M class hardware in demanding field environments. The current codebase is Rust-on-Embassy, but we are language-agnostic — strong C, C++, or Rust embedded engineers are equally welcome. You'll work closely with the hardware engineer from bring-up through qualification.
What you'll do:
- Own firmware end-to-end: drivers, state machines, communication protocols, command surface, bring-up, qualification, and programming flows.
- Build and maintain a host-testable simulation layer — the state machine should be testable on a laptop without flashing a board, and stay that way.
- Work shoulder-to-shoulder with the HW engineer on bring-up, register-map ergonomics, and timing decisions.
- Carry firmware through environmental qualification (thermal, EMC, vibration) — you'll be on the bench when something is acting wrong at -20°C.
- Define and enforce the firmware-side safety case: what we test, what we prove, what is allowed to ship.
- Write code that is terse, testable, and obvious about its safety story.
Required:
- 7+ years of professional embedded firmware on ARM Cortex-M (or comparable) in C, C++, or Rust — show us something you shipped or fielded.
- Deep comfort with the bare-metal stack: interrupts, DMA, clocks, timers, low-power modes, linker scripts, and memory maps.
- Strong with peripheral protocols — I²C, SPI, UART, USB CDC — and with debugging them on a scope or logic analyzer when the abstraction layer is lying.
- Experience building and reasoning about real-world safety-relevant state machines, including guard conditions and timer-driven transitions.
- Discipline around testability: pure-logic code separated from HAL, host tests for everything that doesn't strictly need the target.
- Working English, written and verbal.
Nice to have:
- Rust embedded experience — Embassy, embedded-hal, defmt, probe-rs, RTIC, no_std ecosystem.
- Modern C++ embedded (C++17/20, freestanding builds).
- Safety-critical firmware background: defense (MIL-STD-882), automotive (ISO 26262/MISRA), aerospace (DO-178C), or medical (IEC 62304).
- Async firmware experience (Embassy, Zephyr, FreeRTOS with event loops, or bare-metal cooperative schedulers).
- Bootloader, DFU, and secure-boot work; factory provisioning and programming flows.
- Experience shipping a C SDK or FFI bindings to external integrators.
How we work: Small team, weekly hardware iterations, real boards on every desk. You'll have a bench, a stack of dev kits, and a direct line to the HW and mechanical engineers. We expect you to defend your timing assumptions — and to be in the room when the next board spin is decided.
Skills Required
- 7+ years of professional embedded firmware experience on ARM Cortex-M or comparable platforms
- Professional embedded firmware experience in C, C++, or Rust, including shipped or fielded systems
- Experience with interrupts, DMA, clocks, timers, low-power modes, linker scripts, and memory maps
- Experience with I²C, SPI, UART, and USB CDC peripheral protocols
- Ability to debug peripheral protocols using an oscilloscope or logic analyzer
- Experience building and reasoning about safety-relevant state machines with guard conditions and timer-driven transitions
- Experience separating pure-logic code from the hardware abstraction layer and writing host tests
- Working English proficiency, written and verbal
- Rust embedded experience with Embassy, embedded-hal, defmt, probe-rs, RTIC, or the no_std ecosystem
- Modern C++ embedded experience with C++17/20 and freestanding builds
- Safety-critical firmware experience in defense, automotive, aerospace, or medical systems
- Async firmware experience with Embassy, Zephyr, FreeRTOS event loops, or cooperative schedulers
- Bootloader, DFU, secure-boot, factory provisioning, or programming-flow experience
- Experience shipping a C SDK or FFI bindings to external integrators
What We Do
Battle-tested tech for modern warfare
.png)







