Backed by Sequoia and Lux.
About the role
You'll own firmware end-to-end on safety-critical embedded systems. Our products run on ARM Cortex-M class hardware in demanding field environments. The current codebase is Rust-on-Embassy, but we are language-agnostic — strong C, C++, or Rust embedded engineers are equally welcome. You'll work closely with the hardware engineer from bring-up through qualification.
What they're looking for
- 7+ years of professional embedded firmware on ARM Cortex-M (or comparable) in C, C++, or Rust — show us something you shipped or fielded
- Deep comfort with the bare-metal stack: interrupts, DMA, clocks, timers, low-power modes, linker scripts, and memory maps
- Strong with peripheral protocols — I²C, SPI, UART, USB CDC — and with debugging them on a scope or logic analyzer when the abstraction layer is lying
- Experience building and reasoning about real-world safety-relevant state machines, including guard conditions and timer-driven transitions
- Discipline around testability: pure-logic code separated from HAL, host tests for everything that doesn't strictly need the target
- Working English, written and verbal
More about this role
You'll own firmware end-to-end on safety-critical embedded systems. Our products run on ARM Cortex-M class hardware in demanding field environments. The current codebase is Rust-on-Embassy, but we are language-agnostic — strong C, C++, or Rust embedded engineers are equally welcome. You'll work closely with the hardware engineer from bring-up through qualification.
- Own firmware end-to-end: drivers, state machines, communication protocols, command surface, bring-up, qualification, and programming flows.
- Build and maintain a host-testable simulation layer — the state machine should be testable on a laptop without flashing a board, and stay that way.
- Work shoulder-to-shoulder with the HW engineer on bring-up, register-map ergonomics, and timing decisions.
- Carry firmware through environmental qualification (thermal, EMC, vibration) — you'll be on the bench when something is acting wrong at -20°C.
- Define and enforce the firmware-side safety case: what we test, what we prove, what is allowed to ship.
- Write code that is terse, testable, and obvious about its safety story.
- 7+ years of professional embedded firmware on ARM Cortex-M (or comparable) in C, C++, or Rust — show us...
Browse similar: Startup jobs