Home > Theatre Talks >
Containerized, cloud-enabled, and compliant: embedded DevSecOps at scale
Aaron Bauch - IAR - EOC 2025

As embedded systems evolve and development scales across teams and geographies, maintaining quality, security, and compliance becomes a serious challenge. Manual workflows and fragmented toolchains no longer meet the demands of modern product development, especially when time-to-market and regulatory readiness are critical.
In this session, we’ll explore how engineering teams are implementing DevSecOps best practices to automate embedded CI/CD pipelines, reduce risk, and deliver secure, high-quality software, whether deploying in cloud, hybrid, or on-prem environments.
You’ll learn how containerized, cloud-enabled workflows help:
- Support compliance with standards like ISO 26262, IEC 61508, and IEC 62304 using TÜV-certified tools
- Integrate secure boot, encryption, and IP protection directly into development pipelines
- Adopt architecture-agnostic toolchains across Arm, RISC-V, and more, minimizing vendor lock-in
- Enable CI/CD automation using familiar tools like GitHub, GitLab, Kubernetes, and containers
Whether you're building safety-critical devices or scaling across multiple product lines, this session offers real-world strategies that embedded software teams are using today to modernize, secure, and accelerate development across any deployment model.