Ethical Hacker - Hardware (Embedded/IoT)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Ethical Hacker - Hardware (Embedded/IoT): Leading security assessments of embedded and IoT devices with an accent on physical attack surfaces, firmware analysis, and hardware-level exploitation. Focus on proving vulnerabilities in silicon, firmware, and board layouts through hands-on bench work and rigorous manual testing.
Location: Must be based in Canada or Texas, USA
Company
is a cybersecurity consulting firm specializing in advanced, manual penetration testing to uncover vulnerabilities that automated tools miss.
What you will do
- Plan and execute end-to-end hardware penetration tests on embedded and IoT devices.
- Exploit on-board debug interfaces (JTAG, SWD, UART) to gain code execution or memory access.
- Perform firmware extraction and reverse engineering using tools like Ghidra, IDA, and Binwalk.
- Analyze physical attack surfaces, including side-channel analysis and fault injection.
- Write high-quality technical reports and present actionable remediation advice to clients.
- Contribute to internal lab tooling, methodology development, and knowledge-sharing.
Requirements
- Must be based in Canada or Texas, USA.
- Strong electronics fundamentals with the ability to read schematics and datasheets.
- Hands-on soldering experience, including SMD rework and chip removal.
- Demonstrated experience with debug interfaces and firmware extraction from real devices.
- Proficiency in Python and basic C for embedded code analysis.
- Familiarity with core bench instruments like logic analyzers, oscilloscopes, and multimeters.
Nice to have
- Experience with side-channel analysis or fault-injection (e.g., ChipWhisperer).
- Knowledge of RF/wireless protocols (BLE, SDR, Wi-Fi).
- Familiarity with secure boot chains, TEEs, and HSMs.
- PCB design experience (KiCad/Altium).
- Relevant certifications (OSCP) or published security research.
Culture & Benefits
- Opportunity to work on high-stakes hardware engagements.
- Ongoing offensive security training and professional mentorship.
- Competitive compensation with growth opportunities.
- Corporate benefit plans and GRRSP with matching (Canada).
- Flexible work environment focused on technical excellence.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →