Last updated: August 24, 2026
By Mike Carter, Director of Partnership Success, KORE1
An embedded software engineer costs $145,000 at the median in total compensation and $217,000 at the 75th percentile, and the role is not the same hire as a firmware engineer, whatever your req says. This person lives above the metal. They own the application layer on somebody else’s board support package, which in 2026 also means they own your update path.
A connected-diagnostics manufacturer in Carlsbad called us last October. Not to start a search. To ask whether the engineer they already had could do something.
An advisory had landed on a library sitting inside their Linux image. Not code anyone at the company had written. It arrived with the distribution, the way most of the software on a modern device does, and a hospital customer’s security team had flagged it during a routine scan and wanted a patched build with a date attached.
Their engineer was good. Genuinely good, the kind who reads a datasheet for any part on the board and tells you what the errata means for the driver before you have finished asking, which is a real skill and was not remotely the skill the situation called for. He had never rebuilt a Yocto image in his life. Nobody had. The build ran on a machine under a desk that a contractor had configured in 2021, the layers were pinned to a release that had gone end of life, and the signing key for the update bundle lived in a password manager belonging to somebody who had left.
Six weeks to ship a patch that should have taken four days. They lost the renewal.
Nobody got fired over it. The cost showed up somewhere quieter, in a procurement conversation eleven months later where a competitor could answer the security questionnaire in an afternoon and they still could not.
That is not a firmware problem. It is not a hardware problem either. It is the exact gap the embedded software engineer title is supposed to cover, and most companies do not discover it until something forces a rebuild.
Obligatory conflict note before we go further. KORE1 runs these searches through our embedded software engineer staffing practice and we get paid when one closes, so weigh what follows accordingly. I would rather you hire the right layer than hire through us.
This guide is about that layer. What it is, what it costs, and what changes about the job three weeks from now. If you need the wider engineering picture first, our engineering staffing agency page covers the adjacent roles, and the companion guide on hiring embedded systems engineers handles the architect tier above this one, which we staff through a separate embedded systems engineer staffing practice.

The Layer Nobody Writes Into the Req
An embedded software engineer builds application software that runs on top of an operating system somebody else brought up, on hardware somebody else designed. Usually that operating system is Linux.
Usually is doing real work in that sentence. The Eclipse Foundation’s 2024 IoT and Embedded Developer Survey, which polled roughly 750 developers and architects, found Linux leading operating system choice at 46%, ahead of FreeRTOS at 29%, Zephyr at 21%, and ThreadX at 13%. Almost half the market. And the half running Linux hires differently, differently enough that the two searches barely share a candidate, because a Linux device drags along a package manager and a network stack and a service supervisor and a few hundred pieces of software nobody at the company picked on purpose. Ask a team to list them. Watch what happens.
So. Here is the split that matters when you write the req.
| Role | Sits Where | Owns | Tells on the Resume |
|---|---|---|---|
| Firmware engineer | On the microcontroller | Registers, interrupt handlers, peripheral drivers, bootloaders, RTOS configuration | Part numbers. Oscilloscope traces. FreeRTOS or bare metal |
| Embedded software engineer | On the application processor | Services and applications on embedded Linux, IPC, device integration, the update mechanism, the software bill of materials | Yocto or Buildroot. systemd. Cross-compilation. Release engineering |
| Embedded systems engineer | Above both | Silicon selection, partitioning across the device and the cloud, board support package ownership, lifecycle | Architecture memos. Vendor evaluations. Multi-product platforms |
| Hardware engineer | The board | Schematic capture, layout, power, signal integrity, compliance testing | Altium or KiCad. EMC test reports |
Read across the second row. If what you actually need is someone to add a feature to a device that already boots, integrate a new sensor into a service that already runs, and get a signed update out the door without bricking the fleet, you want row two. Post row one and you will interview twelve people who can tell you why your I2C bus is glitching and none of them will have shipped an over-the-air update.
The reverse costs more. Hire a Linux applications person for a bare-metal role and they will spend four months learning the parts of the job the firmware candidate you passed on already knew. We keep a separate firmware engineer staffing practice for exactly that reason. If you are writing the posting now, the embedded software engineer job description template has the layer language ready to paste.
Two Regulators Just Made This a Different Job
On 11 September 2026, the reporting obligations of the EU Cyber Resilience Act start applying. Manufacturers of products with digital elements sold into the EU have to report actively exploited vulnerabilities and severe incidents, with an early warning inside 24 hours, full notification inside 72, and a final report no later than 14 days after a fix is available. The broader obligations, including secure by design requirements and a software bill of materials, apply in full from 11 December 2027.
One day. Think about what that actually requires on a Tuesday, when the one person who understands the build is somewhere over Kansas, the customer’s security team has already opened a ticket, and somebody has copied legal.
It requires somebody who can tell you, that morning, exactly which software versions are on which units in the field. It requires a build that reproduces. It requires an update path that has been exercised recently enough that nobody is guessing. Those are not security-team capabilities. They are release engineering capabilities, and on a device they belong to whoever owns the application layer.
Medical device manufacturers have been living with a version of this since March 2023, when section 524B of the FD&C Act took effect and made a software bill of materials part of the premarket submission for cyber devices, covering commercial, open source, and off-the-shelf components. The FDA refreshed its guidance in June 2025. Companies in that space have already absorbed the cost. Everyone else is about to.
The hiring consequence is small and expensive. A req written like it is still 2019 pulls in candidates who solve 2019 problems. You find that out eighteen months later, in a week you will remember for other reasons, when it emerges that nobody has ever generated a bill of materials from a build, or watched an update roll back on a unit that lost power at exactly the wrong moment.
Cheap to prevent. Painful to discover.
Add three lines. Ask for the build system by name. What have they pushed an update through, and did it roll back cleanly when it had to? Then the one that separates everybody: have you ever had to prove where a specific library version came from?
What They Cost, and Why the Sources Disagree by $58,000
Compensation for this role reads like four different jobs depending on which site you open, and the spread is not noise. It is a methodology difference. Worth ten minutes before you set a band.
| Source | What It Measures | Headline Figure | Spread |
|---|---|---|---|
| Levels.fyi | Total compensation, median | $145,000 | $113,000 at the 25th, $217,000 at the 75th, $294,000 at the 90th |
| Glassdoor | Total pay, average | $174,217 | $118,304 to $262,575, with additional pay averaging $39,746 |
| Salary.com | Base only, average | $115,896 | $140,750 at five to eight years, $159,693 past eight |
| Bureau of Labor Statistics | Median wage, all software developers, May 2024 | $133,080 | 15% projected growth through 2034, about 129,200 openings a year |
| KORE1 placements | Base, senior, what we actually close | $155,000 to $205,000 | Mid-level lands $125,000 to $150,000 in most metros |
Salary.com is base. Levels.fyi and Glassdoor include equity and bonus, and Levels.fyi skews toward large public employers where the equity component is real money rather than a number on a term sheet. That is most of your $58,000 gap right there. The rest is title drift, since some of these datasets sweep in embedded systems engineers, who genuinely earn more.
Geography moves the number less than it used to for this role and more than the remote-work discourse suggests. Boston, San Jose, and the Bellevue and Redmond corridor outside Seattle still carry a premium, mostly because that is where the medical device, silicon, and consumer hardware employers cluster. Huntsville, Raleigh, and the Detroit suburbs run 10 to 15% under, with defense and automotive work concentrated enough to keep the market competitive anyway. If you want to sanity-check a band against your own market, our salary benchmark assistant will do it faster than a spreadsheet, and the embedded systems engineer salary guide breaks out the tier above this one.
One warning on the low end. A posting at $110,000 for a role that requires Yocto experience and regulated-industry release discipline will not fail loudly. It will just sit, and you will conclude there is a talent shortage, and the actual problem will be forty grand.

Read the Resume for the Build System
Most screening advice for this role says look for C and C++, which barely narrows anything. Stack Overflow’s 2025 Developer Survey put C++ usage at 23.5% of respondents over the prior year, with Rust at 14.8%. Big pool. Almost none of them have shipped a device that a stranger has to update in the field two years after it left the factory.
Look at the build system instead. Highest-signal item on the page. Nobody claims Yocto experience casually, so it is almost never padded.
- Yocto or Buildroot named explicitly, with a layer or a recipe they maintained. This is the strongest signal on the page. If the resume says “Linux” and stops, they may have written applications for a device without ever owning the image that ships it, which is a different job.
- A signed, resumable update mechanism. SWUpdate, RAUC, Mender, or something homegrown they can describe. The word to listen for is rollback. Anyone who has actually bricked a fleet leads with rollback.
- Hardware in the CI loop. Ask how tests ran. “On a board in a rack in the office” is a better answer than any framework name they could give you.
- Rust, if it appears, is worth a question rather than a bonus point. Some of it is real, particularly in automotive and security-sensitive work. Some of it is a side project.
- Silicon families. NXP i.MX, Texas Instruments Sitara, Rockchip, Qualcomm, Renesas. Not because you need a match. Because someone who has worked across two vendors has been through two board bring-ups, and that experience does not transfer from reading.
What I would not filter on. Degree. Years. Or domain. The best embedded software engineer we placed last year moved out of industrial controls into medical devices and was productive in about six weeks, because the regulated part of that job is process and paperwork the company teaches you, while the technical part was already identical.
Five Questions That Sort Real From Adjacent
You do not need to read code to run this screen. You need to listen for whether the answers have texture. If you want a longer bank to pull from, we keep a full set of embedded software engineer interview questions with the answers we listen for.
Walk me through the last update you shipped to devices in the field. A real answer includes the staging percentage, what they watched, and the moment they decided it was safe to continue. A thin answer describes a process. The difference is audible in about forty seconds.
Something in your build is on a version with a published vulnerability. How do you find out which units have it? That is the reporting-deadline question in plain clothes. Listen for a manifest, a bill of materials generated from the build, or device telemetry. Listen for whether they sound like they have done it or like they are describing what one might do.
Tell me about a time the same code worked on your desk and failed on the unit. Everyone has this story. The good ones get specific fast, about timing, memory pressure, a filesystem that filled, a race that only appeared at cold boot. The story is the credential.
How did you keep the image from growing? Underrated. Storage is finite and somebody has to say no. Ask it and then stop talking, because candidates who have actually owned an image have strong opinions about locale files and debug symbols and will happily spend five minutes proving it to you.
Tell me about the part of the codebase nobody touches. Every embedded product has one. What you are listening for is whether they can describe the workaround without contempt for whoever wrote the thing, because the ones who last on a hardware team are the ones who understand that the previous engineer was also shipping under a deadline with the information they had at the time.
Where These People Are Right Now
Not on job boards, mostly. Small market. The good ones are employed and not looking.
Defense and aerospace release talent in waves, and Huntsville, Melbourne on Florida’s Space Coast, and the Denver corridor are worth watching when program funding shifts. Medical device work concentrates in Minneapolis, the Irvine and Carlsbad stretch of Southern California, and around Boston. Automotive has been the largest single source of movement over the last two years as software-defined vehicle programs get restructured, which puts experienced Linux and Android Automotive people in Detroit, Ann Arbor, and increasingly Austin into the market at a rate the job boards never reflect.
Consumer hardware is the other pool, and the one most companies skip, because a doorbell or a fitness tracker looks unserious sitting next to a diagnostic instrument and the hiring manager quietly decides the engineering must be unserious too. It is not. Someone who has pushed an update to a million units in the field has thought harder about rollback and staged rollout than anyone currently in your pipeline, and they have done it with a support organization watching.
Two sourcing notes that actually work. Search on the build system rather than the title, because “Embedded Software Engineer,” “Senior Software Engineer,” and “Platform Engineer” all describe this job at different companies and only one of them is searchable. And look at the Yocto Project and Zephyr contributor lists. Public commit history is a hiring signal that costs nothing to check.
The Order That Works
- Name the layer before you name the title. Write one sentence at the top of the req that says whether this person works below the operating system, on it, or above both. Everything else follows from that sentence, and the reqs that skip it are the ones that run four months.
- Put the build system in the req. Yocto, Buildroot, or whatever you actually run. It costs you nothing, it filters honestly, and it tells senior candidates that the team knows what it is doing.
- Screen on one shipped release. Ask for a single update they took to production and let them talk. Skip the take-home. The people you want are not doing take-homes in this market.
- Decide who owns the 24-hour clock before the offer. If the answer is this hire, say so in the interview, and pay for it. If the answer is a security team that already exists, say that too, because it changes who accepts.
- Move inside two weeks. Our average time to hire across IT roles is 17 days. The searches that beat it are the ones where the client decides within 48 hours of the final conversation instead of adding a fifth.
Contract, Contract-to-Hire, or Direct
The regulatory work suits contract engagements unusually well. Getting a build reproducible, standing up bill-of-materials generation, and exercising an update path are projects with an end. We have placed contract engineers on six-month engagements to do exactly that, and in several cases the client’s existing team absorbed the practice and never needed a permanent seat.
Ongoing product development is different. If this person will own a platform across a product family for the next three years, hire them. Direct hire is the honest structure, and senior embedded candidates read a contract-to-hire offer on a platform role as a signal the company is not certain the product will still exist in eighteen months. They are often right. That is exactly why it reads that way to them.
Six Answers, No Hedging
Embedded software engineer or firmware engineer, which title do we actually post?
Post the one that matches the layer, not the one that sounds more senior. Firmware engineer means code on a microcontroller, close to registers and interrupts. Embedded software engineer means applications and services on an operating system, usually Linux, on an application processor. At the senior end the two titles pay roughly the same, so there is nothing to gain by stretching, and candidates self-select hard on the distinction anyway. Getting it wrong costs you a full interview cycle before anyone notices.
Does the September deadline apply to us if we only sell in the United States?
Short answer, not directly, and it will still reach you. The Cyber Resilience Act binds manufacturers placing products with digital elements on the EU market, so a purely domestic product is outside its scope. The reason it matters anyway is that your enterprise and hospital customers are writing the same expectations into procurement contracts regardless of geography, and if you sell components into a device that ships to Europe, your customer will pass the requirement down to you. Distributors and importers carry obligations too. Check the sales map before deciding you are exempt.
What does the calendar actually look like from req to start date?
Six to nine weeks for a mid-level hire in a metro with real supply, and ten to fourteen for a senior with regulated-industry release experience. Notice periods add two to four on top of that, and defense candidates with active clearances can take longer if a transfer is involved. The step that stretches is not sourcing. It is the gap between the final conversation and the offer, which we watch more closely than any other number in the search.
Can we grow a backend engineer into this instead of hiring?
Sometimes, and it takes longer than anyone budgets. A backend engineer who already works in Linux, understands cross-compilation, and has debugged something without a debugger attached can get there in about six months with a mentor. Without a mentor, closer to eighteen, and the expensive lessons happen on your fleet. The path that works is pairing an internal person with one experienced hire rather than hoping the internal person figures it out alone. The path that does not work is assigning it to whoever has the most availability.
How much of this has to happen in the building?
More than for most software roles, less than hardware teams usually insist on. Bring-up, integration, and anything involving a test rig want hands on the unit, so the first month is genuinely on site. After that, plenty of teams run three days a week and ship fine, provided the candidate has a board at home and someone will overnight them a replacement when it dies. Full remote works for maintenance and update work. It does not work for a new platform, and pretending otherwise costs you the hire around month four.
A software bill of materials, who on the team actually owns it?
The person who owns the build, which for a Linux device is this hire. A bill of materials is a machine-readable inventory of every software component in a shipped image, including the open source and off-the-shelf pieces nobody wrote in house. It has to come out of the build system to be trustworthy, which is why security teams cannot own it and why a spreadsheet maintained by hand goes stale within one release. If nobody currently owns your build, that is the finding, and it is worth knowing before September rather than during an incident.
Working With Us on One of These
KORE1 has placed technical talent since 2005, across more than 30 U.S. metros, with recruiters who average 15-plus years in their markets. Retention runs 92% at twelve months, and on embedded roles that number carries more weight than usual, because the knowledge of why a device is built the way it is tends to live in one head and walk out the door with it.
We also lose money telling clients they do not need us, and we do it anyway. If your device runs a microcontroller and no operating system, you want firmware, not this. If you already have three strong Linux people and one gap in test automation, that is a different search and a cheaper one.
If you are scoping one of these and want somebody to read the req before it goes live, talk to a recruiter on our team. Bring the hardware description and the build system. Those two facts settle most of the argument in the first ten minutes.
Related reading: the embedded systems engineer hiring guide covers the architect tier, and medical device staffing goes deeper on the regulated side of this work.

