Software Engineer, Device Management
Job description
About the role
You will own the secure OS layer and the lightweight host services that bring Rivet hardware to life in the field. This position requires you to design and implement core device management capabilities that enforce policy and enable secure communication at scale. You will be responsible for ensuring that every device in the fleet remains verifiable and manageable from end to end. Your work will directly support regulated customers who depend on the integrity and reliability of our systems. You will collaborate closely with systems engineers and security architects to align implementation with strict compliance standards. This role demands a hands-on owner who writes pragmatic code while maintaining a security-first mindset. You will play a central role in bridging embedded infrastructure with enterprise manageability.
Key facts
What you'll do
- Design and maintain low-level Android/Linux platform code, including AOSP customizations, system services, HALs, and kernel-level integration.
- Build lightweight host services that manage device communication, policy distribution, and telemetry ingestion in constrained environments.
- Ship secure device management end to end, handling enrollment, provisioning, attestation, policy enforcement, and over-the-air updates.
- Define and enforce secure software and system configurations across the device fleet to meet operational and regulatory requirements.
- Build and manage secure, reproducible environments that support certificate signing, sandboxing, and runtime hardening.
- Integrate with third-party MDM systems used by some of our customers to ensure compatibility and seamless deployment.
- Align deployment practices to regulatory and high-assurance frameworks, ensuring traceability and auditability.
- Act as a key owner across the stack, delivering secure, scalable, and well-documented systems that support real-world field conditions.
- Implement robust update mechanisms that maintain device integrity while operating under intermittent connectivity.
- Troubleshoot complex device-level issues using logs, telemetry, and secure diagnostic channels in production scenarios.
- Collaborate with hardware and firmware teams to resolve low-level integration challenges and ensure platform stability.
- Optimize system performance and reliability for environments that demand resilience and minimal downtime.
- Contribute to design reviews and threat modeling sessions to surface risks early in the development lifecycle.
- Mentor and guide junior engineers on best practices for secure systems programming and device lifecycle management.
Requirements
- 5+ years building Android system-level code, including experience with AOSP, custom ROMs, HALs, and system services.
- Strong Linux systems programming experience and proficiency in Go or a similar modern systems language for backend services.
- Practical experience with MDM/EMM systems, including secure enrollment, device posture checks, and policy enforcement mechanisms.
- Familiarity with secure boot, TPM, certificate chains, attestation protocols, and other low-level security primitives.
- Experience building hardened Android images tailored for regulated or high-assurance deployments and operational constraints.
- Working understanding of containerization and sandboxing techniques on Linux or Android platforms.
- Ability to design and implement HTTP APIs that are secure, scalable, and observable in production environments.
- BS in Computer Science, Computer Engineering, or equivalent experience demonstrating mastery of systems software fundamentals.
Nice to have
- Device Owner or Device Policy Controller experience on Android, including work with DPM APIs, COSU/COPE models, and managed profiles.
- Familiarity with third-party MDM/EMM stacks such as Intune or Omnissa, along with Android Enterprise and server-side integration APIs.
- Hands-on experience authoring SELinux policies to enforce mandatory access controls in hardened environments.
- Experience with Protobuf and associated code-generation pipelines for efficient data interchange.
- Background in cross-compile toolchains and static ARM64 builds, as well as Yocto and AOSP device-tree authoring.
- C++ expertise at the NDK or vendor-SDK level for performance-critical or legacy integration needs.
- A demonstrated security-first mindset with a track record of hardening real-world systems in regulated and high-assurance environments.
Practical notes
Work Authorization Requirement: Due to the nature of our business and compliance with federal regulations, all candidates must be a U.S. Person. Upon hire, you will be required to provide documentation verifying your status as a U.S. Citizen, a lawful permanent resident, or a protected individual under 8 U.S.C. 1324b(a)(3).
Compensation may vary within the posted range based on relevant experience, skills, education, and other job-related factors. In addition to base salary, this role may be eligible for equity and other forms of compensation. Eligible employees also receive a competitive benefits package, including unlimited PTO.
Rivet is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to any characteristic protected by applicable law. Certain roles may require U.S. Person status, security clearance eligibility, or other requirements imposed by law or government contract.