Embedded Penetration Tester
Summary
An embedded/IoT security specialist at Spyrosoft who penetration tests embedded targets (via JTAG, UART, SPI, I²C), performs threat modeling and fuzz testing of communication stacks, and reviews secure boot, cryptography, and cloud-IoT architectures. Core tech includes C/C++, Rust, Python, TLS/MQTT/CoAP, hardware security (TPM, TrustZone), and standards like ISO 21434 and IEC 62443.
Tech stack:
Embedded & IoT Security
- Secure Boot, Firmware Integrity, and Code Signing
- Secure OTA (Over-the-Air) update mechanisms
- Key Management for embedded environments
- Hardware security technologies: TPM, HSM, ARM TrustZone, Secure Elements
Cryptography & Secure Communications
- Cryptographic algorithms: AES, RSA, ECC
- Lightweight cryptography for resource-constrained devices
- TLS / DTLS, MQTT(S), CoAP(S)
- Device-to-cloud and cloud-to-device encryption
- Authentication and authorization frameworks for IoT devices
Cloud & IoT Platforms
- Cloud IAM (AWS IoT Core, Azure IoT Hub, GCP IoT Core)
- Secure device provisioning and onboarding
Embedded & Industrial Protocols
- CAN, LIN, Modbus, OPC UA
- BLE, USB, Wi-Fi, NFC
- TCP/IP, UDP, IPv4, IPv6
Security Testing & Development
- Penetration testing tools and methodologies
- Fuzz testing
- Vulnerability scanning
- Secure code review (C/C++, Rust, Python)
- DevSecOps and CI/CD security
- SBOM generation and management
Project description:
We're looking for a Penetration Tester with a proven track record of successfully identifying and exploiting security weaknesses across a wide range of systems and environments. The ideal candidate will have deep expertise in advanced penetration testing methodologies, tools, and reporting, with strong analytical and problem-solving skills. Experience in embedded systems security is highly desirable and will be considered a significant advantage. This role requires excellent communication skills to translate technical findings into clear, actionable recommendations for stakeholders.
About Spyrosoft
Spyrosoft is an authentic, cutting-edge software engineering company, established in 2016. In 2021 and 2022, we were among the fastest growing technology companies in Europe, according to the Financial Times. We were founded by a group of tech experts with established backgrounds in software engineering, who created an ‘engineer-to-engineer’ workplace, powered by enthusiasm, fairness and authentic relationships. Having a unique offering, which bridge the gap between technology and business, we specialise in technology solutions for industry 4.0, automotive, geospatial, healthcare & life sciences, employee experience & education and financial services industries.
- Strong experience in embedded systems, IoT security, or product cybersecurity.
- Hands-on knowledge of secure boot, firmware protection, code signing, and secure update mechanisms.
- Deep understanding of cryptography and key management in embedded environments.
- Experience securing communication protocols and network interfaces in connected devices.
- Knowledge of IoT authentication, authorization, and cloud security architectures.
- Experience with threat modeling methodologies such as STRIDE, DREAD, and Attack Trees.
- Ability to perform security risk assessments aligned with: ISO 21434, IEC 62443, ISO 27005.
- Understanding of common embedded attack vectors: side-channel attacks, fault injection, firmware tampering, replay attacks, Man-in-the-Middle (MITM) attacks.
- Experience conducting penetration testing on embedded targets using interfaces such as JTAG, UART, SPI, and I²C.
- Experience with fuzz testing communication stacks (CAN, TCP/IP, MQTT).
- Understanding of secure SDLC principles, DevSecOps, and cybersecurity lifecycle management.
- Knowledge of vulnerability management, system hardening, and threat surface reduction strategies.
Nice to have:
- Experience in regulated industries such as Automotive, Industrial Automation, Medical Devices.
- Familiarity with: IEC 62304, ISO 27001, NIST Cybersecurity Framework, NIST 8259 (IoT Device Cybersecurity).
- Understanding of GDPR, HIPAA, and data protection requirements for cloud-connected solutions.
- Experience with incident response planning for connected and embedded systems.
- Professional security certifications such as: OSCP, GPEN, CompTIA PenTest.
- Experience working with Rust-based secure embedded applications.
- Experienced in using AI tools in day-to-day workflow.