Dispel logo
DispelPosted 3 weeks ago

Senior Systems Engineer II - Edge Platform & Packaging (On-Prem)

$150,000–$159,000 year

RemoteUnited States

Full TimeSenior LevelSmall

Job Summary

Own the build and packaging pipeline for on-premises deliverables, ensuring reproducible, signed artifacts with SBOMs that survive customer security review. Design the end-to-end update mechanism for constrained, air-gapped appliances, prioritizing failure recovery and fleet-level release control with canaries. Extend the appliance runtime for local telemetry, buffering, and decisioning while defining the edge-cloud boundary based on bandwidth and latency constraints. Collaborate with field, support, and security teams to reduce friction and produce evidence-producing releases for regulatory audits. Write runbooks, upgrade notes, and architecture documentation to enable other engineers and technicians. Participate in an on-call rotation for incident response and root cause analysis, while mentoring IC1 and IC2 engineers through code review and pairing.

Required Qualifications

  • 5+ years of professional engineering experience with a demonstrated track record of shipping software that runs on infrastructure you do not operate.
  • You have owned a release and update mechanism for deployed systems — edge, appliance, embedded, or on-premises enterprise — and dealt with the consequences when one went wrong in the field.
  • Deep Linux systems fluency: systemd, the boot and init path, filesystem and partition layout, kernel and package lifecycle, and how a distribution actually gets assembled.
  • Strong packaging and distribution experience — Debian/apt packaging, OCI images, image-based or A/B update schemes, or equivalent — including artifact signing and repository operation.
  • Proficiency in at least one systems-capable language (Go, Rust, Python, or C) and comfort reading code across the layers you package.
  • Comfortable using coding agents (e.g., GitHub Copilot, Claude Code) as part of your daily workflow
  • Proficiency with Infrastructure as code, with primary focus using Ansible and Terraform.
  • Container runtime and orchestration experience, with real opinions about what is appropriate on a single constrained node versus in a datacenter.
  • Infrastructure-as-code and CI/CD experience (Terraform, GitHub Actions, or similar), including building pipelines that produce release artifacts rather than just deploying them.
  • Solid network fundamentals — routing, DNS, firewalls, VPN concepts — enough to package and operate networking software without breaking its data path.
  • Demonstrated ability to work with cross-team stakeholders to define requirements and deliver results with minimal oversight.
  • A willingness to accept failure and feedback, learn and try again.
  • A passion for learning new disciplines and gaining a deep understanding of how others on the team do their work.
  • An ability to communicate clearly and succinctly both in-person and over team chat.

Desired Qualifications

  • Experience shipping into OT, ICS, or industrial environments, and familiarity with the change-control and segmentation realities of those networks.
  • Experience with air-gapped or intermittently connected deployments, including offline mirrors and sneakernet update paths.
  • Background in security-focused products where reliability and regulatory compliance matter — IEC 62443, NERC CIP, FIPS-validated cryptography, or FedRAMP-adjacent work.
  • Supply-chain security depth: SLSA, in-toto, Sigstore, SBOM generation and consumption, reproducible builds.
  • Lightweight Kubernetes distributions or single-node orchestration at the edge (K3s, MicroShift, Talos), and honest experience with their operational costs.
  • Image-based Linux and atomic update systems: OSTree, Mender, RAUC, SWUpdate, or similar.
  • On-premises virtualization, hardware bring-up, or hardware qualification experience.
  • Telemetry pipeline experience at the edge — agent-based collection, buffering, and forwarding into customer SIEMs.
  • Experience building or operating commercial VPN, ZTNA, or secure remote access products.

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce