About this role
<p><strong>Your job:</strong></p> <ul> <li>Perform hardware and firmware security testing, including Hardware VAPT, TARA analysis, and penetration testing for embedded and IoT products</li> <li>Conduct reverse engineering of firmware, binaries, and hardware components to identify vulnerabilities and weaknesses</li> <li>Execute fuzzing tests (black-box, white-box, and grey-box) on device protocols, firmware, and communication interfaces</li> <li>Perform vulnerability assessments using tools such as Nessus, OpenVAS, Nmap, and Wireshark</li> <li>Develop and maintain test plans, test cases, and security checklists aligned with IEC 62443-4 and secure development lifecycle principles</li> <li>Document findings, prepare detailed test reports, and collaborate closely with development teams to validate and resolve vulnerabilities</li> <li>Support test automation within CI/CD environments to streamline security testing workflows </li> </ul> <p> </p> <p><strong>Your qualification: </strong></p> <ul> <li>Bachelor’s degree in Engineering, Computer Science, Cyber Security with a minimum of 2 years of experience in device or embedded security testing, preferably within the Industrial Automation or Automotive sectors</li> <li>Hands-on expertise in hardware penetration testing, firmware analysis, reverse engineering, fuzzing methodologies, hardware and Thick Client pentesting methodologies</li> <li>Strong understanding of embedded systems, Linux environments, communication protocols (industrial and automotive), frameworks for embedded systems, firmware, and network protocols</li> <li>Knowledge of Secure Development Lifecycle and familiarity with IEC 62443-4 or equivalent standards</li> <li>Proficiency with tools such as Nessus, OpenVAS, Nmap, Wireshark, Burp Suite, Ghidra, IDA Pro, and other security testing utilities</li> <li>Programming experience in C/C++, Python, or Shell scripting, with exposure to CI/CD tools and automation frameworks</li> <li>OSCP, CRTP, CRTO, eWPTX, CPENT, LPT, PNPT, or equivalent industry-recognized credentials is an advantage </li> </ul>