Назад
Company hidden
3 часа назад

PSC Engineer (Product Security Concierge)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
PSC Engineer (Product Security Concierge) (Embedded Product Security): Analyzing firmware and embedded devices, assessing product risk, and building customer-specific integrations and AI-driven workflows on a product security platform with an accent on vulnerability research, penetration testing, and secure product development. Focus on reverse engineering real-world devices, designing threat models, hardening Linux and embedded systems, and translating regulatory requirements into actionable engineering solutions.

Location: Remote in the United States or Canada

Company

hirify.global provides a product security platform for analyzing firmware and software supply chains, identifying vulnerabilities, and helping organizations secure connected devices and embedded systems.

What you will do

  • Own the technical relationship and outcomes for a portfolio of customer accounts.
  • Analyze firmware and binaries, investigate SBOMs and software supply chains, triage vulnerabilities, and provide remediation guidance.
  • Perform penetration tests and hands-on security assessments of embedded hardware and software.
  • Run threat modeling and product risk assessments for connected products and embedded environments.
  • Build integrations, data feeds, automation, SDK extensions, and AI-driven workflows on the hirify.global platform.
  • Guide customers through product security regulations and communicate findings to engineers, security leaders, executives, and boards.

Requirements

  • 5+ years of experience in customer engineering, solutions engineering, technical account management, security consulting, field engineering, or a similar customer-facing technical role.
  • Hands-on product security expertise across embedded software and hardware security, firmware analysis, penetration testing, and threat and risk assessment.
  • Experience building integrations, SDKs, automation, APIs, or platform extensions.
  • Experience building and deploying production-ready Linux and embedded systems.
  • Proficiency in one or more relevant programming languages, including C/C++, Python, Go, Rust, or TypeScript.
  • Strong written and verbal communication skills, customer ownership, technical judgment, and ability to manage multiple priorities.

Nice to have

  • Advanced certifications such as CISSP, CSSLP, OSCP, or OSWE, or experience in exploit development and vulnerability research.
  • Familiarity with the EU Cyber Resilience Act, RED EN 18031, FDA cybersecurity requirements, IEC 62443, or related standards.
  • Knowledge of RTOS, embedded Linux internals, JTAG, UART, SPI, and wireless communication protocols.
  • Experience securing aerospace, medical, automotive, smart energy, smart city, or other mission-critical cyber-physical systems.
  • Experience with programmable logic devices or U.S. government cyber methodologies.

Culture & Benefits

  • Fully remote work with a high degree of autonomy and ownership.
  • Distributed, transparent, inclusive, and collaborative working environment.
  • Learning stipends for professional development.
  • Equity participation and comprehensive benefits.
  • Opportunity to work on connected-device cybersecurity and critical infrastructure challenges.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →