Joshua Lock is an experienced software engineer and security specialist with 17 years of practice delivering embedded Linux, build-system, and supply-chain security improvements across industry leaders including Intel, VMware, and Verizon. He blends deep open-source craftsmanship—contributions to high-profile projects like TPM2 tools, The Update Framework (python-tuf), BitBake, and OpenEmbedded—with senior engineering leadership roles up to Distinguished Engineer/Associate Fellow. Joshua focuses on improving toolchain reliability, secure update/verification processes, and build reproducibility, often converting TODOs and fragile code into maintainable library functions and configurable systems. He combines hands-on backend and DevOps work with security-first design, evidenced by refactors that harden signature verification and unify mirror and checksum handling in package fetchers. Now balancing industry leadership with doctoral studies at King’s College London, he brings both practical production experience and ongoing research curiosity to complex systems problems. Colleagues describe him as the kind of engineer who quietly fixes brittle infrastructure while making it easier for others to build securely.
17 years of coding experience
19 years of employment as a software developer
BSc (Hons) Software Engineering, BSc (Hons) Software Engineering at Nottingham Trent University
The official bitbake Git is at https://git.openembedded.org/bitbake/. Do not open issues or file pull requests here.
Role in this project:
Back-end Developer & DevOps Engineer
Contributions:254 commits in 7 years 5 months
Contributions summary:Joshua's contributions primarily focused on enhancing the BitBake fetcher. Their work involved unifying mirror support, making it independent of the fetcher implementation, and enabling parameterised checksums. They also refactored code to improve usability and included additions for a new GUI, the "Hob" program, for creating images and general enhancements. Furthermore, the user appears to have been working on the code to help automate and simplify common tasks.
The source repository for the Trusted Platform Module (TPM2.0) tools
Role in this project:
Back-end & Security Engineer
Contributions:12 releases, 299 commits, 76 PRs in 1 year
Contributions summary:Joshua's contributions primarily focused on improving the TPM2.0 tools, addressing comments, and fixing links. They removed outdated comments and TODOs, and corrected GitHub links to point to the correct organization. The user implemented new functions, particularly moving TPM capability reading into a library function, and added functionalities to various tools like tpm2_evictcontrol, tpm2_createek, and tpm2_loadexternal, enhancing their flexibility and usability through options.
tpm2signingtrustedtrusted-platform-modulesecurity
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.