Seeking a US Person with 10+ years of hands-on product-security testing including:
Hands-on technical product security assessment activities across the customer product ecosystem, including hardware and device penetration testing, firmware extraction and binary analysis, exploitability validation, secure update mechanism review, and embedded security assessment.
The role will cover UART/JTAG/SWD/USB, firmware extraction, binary analysis, reverse engineering, secure boot, signing, updates, rollback, authentication, encryption, secure defaults, logging, deletion and residual data.
Testing may extend to extends to BLE, Wi-Fi, web/API, companion applications and proprietary protocols, including controlled fuzzing.
The consultant will work under formal safety and restoration controls, validate exploitability and compensating controls, assess blast radius and containment, eliminate false positives, produce reproducible evidence and remediation guidance, and perform retesting.
Key Responsibilities
Perform hardware and device-level penetration testing
Conduct firmware extraction, unpacking, and binary analysis
Assess secure boot, firmware integrity, rollback protection, and update mechanisms
Validate authentication, authorization, encryption, and secure configuration controls
Conduct exploitability validation, attack path analysis, and privilege escalation testing
Analyse attack surfaces to identify material security weaknesses across device components
Perform resilience testing and evaluate effectiveness of security controls
Test BLE, Wi-Fi, web/API, companion applications and proprietary protocols, including controlled fuzzing
Work with the Security architect to identify the test cases and the required open-source testing tools to perform the required IEC 62443 and EU CRA controls.
Lead the hardware security testing, authentication, authorization, encryption, and secure configuration controls and other active tools-based testing part of the engagement.
Required Skills & Experience
Mandatory:
Strong hands-on penetration testing and product security assessment experience across embedded systems, connected devices, and firmware security.
Experience with firmware extraction, unpacking, reverse engineering, binary analysis, dynamic analysis, and embedded security testing.
Familiarity with hardware/device attack surfaces, embedded system architectures, Linux-based systems, network protocols, and secure update mechanisms.