Flight Software Deployment Engineer Verified today
The Role
The Build & Release team owns the path from source to flight-ready software across ICEYE's satellite constellations. Every artifact that reaches satellites in orbit must be reproducible, traceable, and verifiable. A bad update is not a simple rollback; it could mean a satellite becomes at risk.
This is not a generic SRE or DevOps role. The production environment is composed of satellites flying 500 km above Earth, and the software artifacts are cross-compiled embedded binaries. The role sits between build engineering and embedded Linux development. Satellites receive over-the-air (OTA) updates regularly, and your team must ensure they are built and deployed correctly using software development best practices.
Your Responsibilities
- Hands-on software engineering of the satellite on-board updating system for deploying software and firmware updates: features, maintenance, tests and documentation.
- Contribute to the build layer across the flight software domain so every repository is built, versioned and packaged the same way.
- Enforce immutable releases and harden the packaging and signing pipelines: least-privilege permissions, pinned workflows and dependencies, approvals, and proper signing key management.
- Work with the Linux platform team on how updates land on satellite on-board computers, covering packaging format, filesystem layout and access control.
What You Need
Must have:
- Embedded software engineering experience with hands-on embedded Linux development: cross-compilation for ARM or similar targets, kernel configuration, device tree overlays, root filesystem and image construction.
- Production CI/CD experience for compiled artifacts, not only containers or web deployments. GitHub Actions specifically is required, and workflow hardening experience is valuable.
- Working proficiency in C and C++ build environments, and in Python and Bash for automation.
- Experience implementing release integrity controls and immutable artifacts storage. Signing key management, PKI and trust chains, AWS object-lock storage and cloud key management are valuable.
- Shipping software to embedded devices already in the field with a package-based update mechanism, ideally opkg, under controlled release processes and quality gates.
Nice to have:
- Command of CMake, including multi-repository setups, toolchain files, and shared build infrastructure. Buildroot experience is relevant.
Location and Terms
- Location: Espoo, Finland or Warsaw, Poland
- Employment type: Permanent
- Workplace: Hybrid (3 days in the office)
- Security screening applies, including SUPO where required.
Application Process
- Conversation with talent acquisition (30 min)
- Screening with the hiring manager (60 min)
- Technical test: take-home task (3 to 5 working days)
- Technical deep-dive (90 min)
- On-site office visit and director interview (60 min)
