Назад
Company hidden
9 часов назад

Staff Security Engineer (IoT Security)

167 500 - 180 500$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Security Engineer (IoT Security): Performing penetration testing and vulnerability research across IoT devices, firmware, embedded systems, and applications with an accent on reverse engineering, hardware interfaces, and embedded Linux analysis. Focus on extracting and analyzing firmware, circumventing device security mechanisms, documenting risk impacts, and driving remediation of complex IoT security issues.

Location: Tysons, Virginia, United States; office attendance required 4 days a week

Salary: $167,500–$180,500 USD base salary per year

Company

hirify.global provides an intelligently connected property platform covering security, video surveillance, access control, automation, energy management, and wellness solutions.

What you will do

  • Perform IoT penetration testing, including firmware extraction, reverse engineering, vulnerability discovery, and security mechanism analysis.
  • Conduct threat modeling, vulnerability assessments, penetration testing, and security research across applications, platforms, and systems.
  • Use manual and automated techniques to assess risks and circumvent security controls in devices and applications.
  • Manage the deployment, integration, configuration, and improvement of IoT security solutions and enterprise security documentation.
  • Document risk impacts, triage issues reported by external parties, and drive remediation.
  • Partner with infrastructure, application, product, and other stakeholders to reduce security and privacy risks.

Requirements

  • Bachelor’s or higher degree in Computer Science, Electrical Engineering, or a related engineering discipline.
  • 10+ years of information security experience focused on offensive security, penetration testing, or vulnerability research.
  • Experience testing IoT, embedded, or firmware-based environments and analyzing embedded Linux systems and firmware images.
  • Knowledge of embedded system design, ARM architectures, and hardware debugging equipment such as oscilloscopes and logic analyzers.
  • Familiarity with UART, I2C, SPI, JTAG, IDA Pro, Ghidra, and/or Binary Ninja.
  • Strong analytical, communication, documentation, collaboration, and problem-solving skills.

Nice to have

  • Development experience with embedded systems.
  • Exposure to x86, RISC-V, or other CPU architectures.
  • Information security certifications or the ability to obtain them.

Culture & Benefits

  • Collaborative, team-oriented work environment with in-person collaboration.
  • Medical plans with company subsidies and a company-contributed HSA.
  • 401(k) with employer match.
  • Paid vacation that increases with tenure, paid holidays, wellness time, and paid maternity and bonding leave.
  • Company-paid disability and life insurance.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →