Sr. Staff Firmware Engineer (Secure Boot & OTA implementation)
We are looking for the best
About Us
42dot is a mobility AI company committed to solving mobility challenges with software and AI. As the Global Software Center of Hyundai Motor Group, 42dot pioneers the future of mobility by advancing the development of software-defined vehicles.
We develop safety-first, user-centric software-defined vehicle technologies that deliver the latest performance through continuous updates like smartphones. By advancing software and AI technology, 42dot envisions a world where everything is connected and moves autonomously through a self-managing urban transportation operating system.
About the Role
As a Sr. Staff Firmware Engineer, you will build the two components everything else on the platform depends on: the multi-stage secure boot chain and the Uptane update client. The platform is a greenfield, ASIL-D safety firmware platform (ISO 26262 Safety Element out of Context) for a microzonal vehicle E/E architecture, running on NXP S32K3-class lockstep MCUs with a hardware security engine. JTAG is used once per board — to bring up the silicon and flash the immutable bootloader — and every deployment after that, including continuous integration, goes through Uptane. Until your code works, nothing ships; once it works, every engineer on the program runs it daily.
You implement to a security architecture owned by the platform's Firmware Security Architect and to the platform's ASIL-D rules: MISRA C, zero-deviation static analysis, static memory, requirements-based test with MC/DC coverage, and full traceability. Requirement sets for the immutable bootloader, the mutable bootloader and the update client already exist; you inherit, complete and implement them. You are the hands — and you are expected to push back when the hardware or the timing says the architecture is wrong.
Responsibilities
Secure Boot-Chain Implementation: Write and own the multi-stage boot sequence on the target MCU — startup code, linker command files and memory maps, flash drivers, hardware security engine integration (key catalogs, secure-boot configuration, signature-verification services), anti-rollback counters in HSE-protected storage or OTP, and recovery and fail-safe boot — with boot time measured against budget.
Fail-Safe A/B Update Layouts: Implement atomic A/B firmware-slot and dual-bank schemes: the low-level state machines for partition switching, background flashing, verify-before-activate and automatic runtime fallback.
Uptane Client: Implement the on-device update client — metadata parsing and signature/threshold verification across the Root, Timestamp, Snapshot and Targets roles in constrained, statically allocated C; image transfer from the Primary over the platform's Ethernet middleware; staging to flash; the install → verify → activate → confirm/rollback state machine; delta application; and ECU version reporting — as an ASIL-D mandatory application under the platform's lifecycle manager. [SCOPE DECISION: the partial-verification Secondary is core scope; include the full-verification Primary client on the vehicle's central compute only if it stays in this team.]
Hardware-Enforced Isolation: Configure resource-domain controllers (NXP XRDC-class domain IDs, MDAC, PAC) and core MPUs across boot stages and the handoff to the application, to the isolation policy set by the Security Architect, and validate the resulting memory protections and security states in the lab.
Bandwidth & Storage Optimization: Implement delta application and compression-aware flash budgeting on embedded MCU flash to minimize bus bandwidth and program/erase cycles.
Diagnostic Reprogramming: Implement the diagnostic reprogramming entry (security access, transfer services) where OEM service processes require it, on the platform's transport, without importing an AUTOSAR diagnostic stack.
Defensive Engineering: Harden the verification path against voltage and clock glitching, fault injection and side channels — redundant checks, constant-time comparisons, fail-closed defaults — and feed findings back into the threat model.
Deterministic Firmware Development: Write high-performance, deterministic embedded C for bare-metal and RTOS targets with freedom from interference, using Python exclusively for host-side tooling such as secure payload wrapping and test automation.
Certification Evidence: Produce the ISO 26262 work products for your components: requirements and design in the traceability system, unit and integration tests with structural coverage, static-analysis results, WCET and boot-timing evidence, and freedom-from-interference analysis between bootloader stages and the application.
Low-Level Hardware Integration: Lead bring-up on bench EVKs and production silicon with JTAG/SWD debuggers, logic analyzers and oscilloscopes; integrate the boot chain with the safety SBC's watchdog and safe-state behavior; and make the Uptane path the deployment mechanism for the platform's hermetic CI.
Engineering Leadership: Set the implementation pattern others follow, review the work of engineers who later join the boot/OTA area, and own the bench when it breaks.
Qualifications
Tenure: 15+ years of firmware engineering; expert-level C for bare-metal and RTOS targets.
Bootloader Authorship: Have personally written and shipped a bootloader on a Cortex-M or automotive MCU (S32K, AURIX/TriCore, RH850, STM32-class): the flash drivers, linker scripts, startup code and memory map were yours, not a vendor's. Linux/U-Boot-only experience does not meet this bar.
Verified Boot & A/B: Have integrated cryptographic verification into a boot or update path — signature verification through an HSM/secure element or a crypto library, key handling, anti-rollback — and implemented A/B or dual-bank activation with a recovery path.
On-Target Update Agent: Have built or substantially owned a software-update agent for constrained embedded devices (vehicle strongly preferred): flash management, resumable transfer, verify-before-activate, rollback. Cloud or campaign-tooling-only experience does not meet this bar.
Certification Evidence: ISO 26262 (or DO-178C / IEC 61508) work products as an author: MISRA C compliance, static analysis to zero deviations, requirements-based testing with structural coverage (MC/DC at the highest levels), and traceability tooling.
Bench Fluency: JTAG/SWD, logic analyzer, oscilloscope; reads schematics; works from the reference manual at register level.
Preferred Qualifications
Silicon: NXP S32K3 with HSE_B (key catalogs, secure boot, A/B swap); FS26-class safety SBC integration.
Open-Source Fingerprints: Uptane / TUF / aktualizr / MCUboot / SUIT — contributor rather than user.
Delta Technology: bsdiff-class delta tooling and compression-aware flash budgeting on MCUs.
Toolchain: Safety-certified RTOS (PX5, SafeRTOS or similar) and hermetic build systems (Bazel).
Diagnostics: UDS (ISO 14229) security access and reprogramming services ($27/$29, $34/$36/$37).
Networking & Middleware: Embedded pub/sub middleware (Zenoh / zenoh-pico, DDS) and automotive Ethernet (100BASE-T1, 10BASE-T1S).
Hardening: Fault-injection or side-channel countermeasure experience in a boot path.
Assessor Exposure: Direct interaction with certification bodies (TÜV, exida, UL) during assessment.
Education: MS or PhD in Computer Engineering, Electrical Engineering or a related field.
Interview Process
Application Review - Coding Test - 1st interview - 2nd interview - Offer Negotiation - Hiring
The screening procedures may vary depending on the position, schedule, or other circumstances.
You will be individually notified of the screening schedule and results via the email address provided in your application.
Compensation
$189,240 - $266,760
Additional Information
In accordance with fair hiring practices, do not include any personal information unrelated to your job qualifications (e.g., Social Security Number, family relations, marital status, age, photo, physical condition, place of birth, etc.) in your resume.
All documents must be submitted in PDF format and under 30MB in size.
If you experience issues uploading your resume, please send it along with the job posting URL to recruit@42dot.ai.
We strongly encourage applications from U.S. veterans and candidates eligible for employment preference under applicable laws.
Qualified individuals with disabilities are encouraged to apply and will receive consideration under the Americans with Disabilities Act (ADA).
42dot does not accept unsolicited resumes and will not pay fees for any such submissions. Equal Opportunity Statement
42dot is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees, regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or veteran status.
※ Please review the following information before applying.
How to work in 42dot, About 42dot Way →
Post Date : 2026. 06. 19