Principal DevSecOps Engineer
Own the build, release and runtime security of software that has to keep working in orbit. Go and Kubernetes daily, Rust and embedded Linux often, and a supply chain that has to stand up to defence procurement scrutiny.
The work
Our software runs in places where you cannot send someone to reboot a machine. An update that fails halfway has to roll back on its own. A process that starts misbehaving has to be caught before it takes anything else with it. A build that ships has to be traceable back to the exact source it came from, months later, to a customer who is entitled to ask.
That is the job. You own how software is built, signed, shipped and kept honest across environments that range from constrained embedded targets to standard cloud infrastructure. The same toolchain, the same workflow, at both ends.
This is a hands-on engineering role. You will write code, not policies about code.
What you will work on
- Build and release pipelines that produce reproducible, signed, attestable artefacts, with an SBOM that survives a procurement audit
- Container and image supply chain: provenance, scanning, admission control, and a credible answer to where every dependency came from
- Kubernetes across constrained and conventional targets, including the unglamorous parts, admission policy, secrets handling and node hardening
- Embedded Linux images: reproducible builds, read-only root, verified boot, safe update and rollback
- Runtime hardening and observability, so failures surface early rather than quietly
- Secure development practice across the engineering team, by making the secure path the easy path rather than by writing rules
What we are looking for
You have spent enough years doing this to have opinions, and enough to know which of them are worth defending. Concretely:
- Deep production experience with Go. This is our primary language and you will be writing it from week one
- Kubernetes to a genuine operational depth. Not just deploying to it, but understanding what happens when it goes wrong on hardware you cannot touch
- Embedded Linux, including build systems such as Yocto or Buildroot, and the realities of constrained targets
- Supply chain security as something you have implemented, not read about. Signing, provenance, SBOM generation, reproducible builds
- Linux internals deep enough to debug from first principles
Useful, and we will make room for you to grow into it:
- Rust, particularly in systems and embedded contexts
- Experience in regulated or safety-critical environments, whether aerospace, medical, automotive or industrial
- Exposure to defence, space or other export-controlled work
- Familiarity with NIS2, the EU AI Act or CMMC as they touch engineering practice
We are not asking for all of it. We are asking for real depth in most of it and the judgement to know what you do not know.
How we work
We build capability from people and AI together, deliberately. Senior human systems expertise combined with agentic accelerated engineering, because that combination ships faster and safer than either alone. If you find that idea interesting rather than threatening, you will fit here.
Decisions are made close to the knowledge needed to make them well. There are no support functions. Teams form around missions rather than seats. We document what we decide and we avoid process for its own sake.
We are a small company doing serious work, which means you will have more ownership than at a large prime and fewer people to hide behind.
Practicalities
English is our working language. Swedish is welcome but not required.
We are based in Uppsala and work hybrid. Some of this role needs hardware in front of you, so fully remote is not realistic.
Parts of our work fall under export control and national security requirements. Depending on the projects you join, this may affect which material you can access and may require security vetting. We will be specific about what that means for you before any assessment begins.
This role may be subject to Swedish security vetting. We will explain what that involves before any assessment begins.
