2 месяца назад
Hardware Penetration Tester (Embedded/IoT)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Hardware Penetration Tester (Embedded/IoT): Performing security assessments of embedded and IoT devices with an accent on firmware analysis, board layout, and physical attack surfaces. Focus on exploiting debug interfaces, extracting firmware, and performing reverse engineering to uncover critical vulnerabilities.
Location: Fully remote within Canada
Company
Cybersecurity consulting firm specializing in rigorous, manual penetration testing for government, technology, and financial sectors.
What you will do
- Plan and execute end-to-end hardware penetration tests on embedded and IoT devices.
- Identify and exploit on-board debug interfaces such as JTAG, SWD, and UART to gain memory access or code execution.
- Extract firmware via debug ports, in-circuit flash reads (SPI/I2C/NAND), or chip-off techniques.
- Intercept and analyze data on embedded buses using logic analyzers and protocol decoders.
- Reverse engineer firmware and embedded binaries using Ghidra, IDA, and Binwalk to find logic flaws.
- Write high-quality technical reports and advise clients on prioritized remediation.
Requirements
- Degree in Information Security, Computer Science, or Electrical Engineering (or equivalent experience).
- Strong electronics fundamentals, including the ability to read schematics and datasheets.
- Hands-on soldering ability, including surface-mount (SMD) rework and chip removal.
- Experience accessing debug interfaces and extracting firmware from real-world devices.
- Proficiency with logic analyzers, oscilloscopes, and multimeters.
- Scripting skills in Python and ability to read C code.
- Must be based in Canada.
Nice to have
- Experience with side-channel analysis or fault injection (e.g., ChipWhisperer).
- RF and wireless security expertise (SDR, BLE, sub-GHz, Wi-Fi).
- Knowledge of secure boot chains, TEEs, secure elements, and HSMs.
- PCB design familiarity using KiCad or Altium.
- Published CVEs, conference talks, or relevant certifications like OSCP.
Culture & Benefits
- Access to high-stakes hardware engagements and a professional development path.
- Ongoing offensive security training and mentorship from a highly skilled team.
- Flexible, fully remote work environment.
- Culture that values technical substance and humility over ego.
- Competitive compensation and growth opportunities within an expanding hardware practice.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →