Point your AI agent at freehire and let it find you a job.

Get the CLI →

Spyrosoft

Embedded Penetration Tester

Posted Updated
Discussion

Tech stack:

  • Secure boot, firmware security, OTA updates.
  • Cryptography (AES, RSA, ECC) & hardware security (TPM, HSM, TrustZone).
  • Embedded interfaces & protocols: CAN, LIN, Modbus, BLE, Wi-Fi, TCP/IP.
  • Penetration testing on embedded targets: JTAG, UART, SPI, I²C.
  • Cloud IoT platforms & secure communication: AWS/Azure/GCP IoT, TLS/DTLS, MQTT(S).
  • Secure code review (C/C++, Rust, Python) & DevSecOps / CI/CD security.

Project description:

We're looking for a Penetration Tester with a proven track record of successfully identifying and exploiting security weaknesses across a wide range of systems and environments. The ideal candidate will have deep expertise in advanced penetration testing methodologies, tools, and reporting, with strong analytical and problem-solving skills. Experience in embedded systems security is highly desirable and will be considered a significant advantage. This role requires excellent communication skills to translate technical findings into clear, actionable recommendations for stakeholders.

About Spyrosoft

Spyrosoft is an authentic, cutting-edge software engineering company, established in 2016. In 2021 and 2022, we were among the fastest growing technology companies in Europe, according to the Financial Times. We were founded by a group of tech experts with established backgrounds in software engineering, who created an ‘engineer-to-engineer’ workplace, powered by enthusiasm, fairness and authentic relationships. Having a unique offering, which bridge the gap between technology and business, we specialise in technology solutions for industry 4.0, automotive, geospatial, healthcare & life sciences, employee experience & education and financial services industries.

  • Proven experience in embedded systems, IoT security, or product cybersecurity.
  • Hands-on knowledge of secure boot, firmware protection, code signing, and secure update mechanisms.
  • Good understanding of cryptography and key management in embedded environments.
  • Experience securing communication protocols and network interfaces in connected devices.
  • Knowledge of IoT authentication, authorization, and cloud security architectures.
  • Experience with threat modeling methodologies such as STRIDE, DREAD, and Attack Trees.
  • Ability to perform security risk assessments aligned with: ISO 21434, IEC 62443, ISO 27005.
  • Understanding of common embedded attack vectors: side-channel attacks, fault injection, firmware tampering, replay attacks, MITM attacks.
  • Experience conducting penetration testing on embedded targets using interfaces such as JTAG, UART, SPI, and I²C.
  • Experience with fuzz testing communication stacks (CAN, TCP/IP, MQTT).
  • Understanding of secure SDLC principles, DevSecOps, and cybersecurity lifecycle management.
  • Knowledge of vulnerability management, system hardening, and threat surface reduction strategies.
  • Understanding of GDPR, HIPAA, and data protection requirements for cloud-connected solutions.

Nice to have:

  • Experience in regulated industries such as Automotive, Industrial Automation, Medical Devices.
  • Familiarity with: IEC 62304, ISO 27001, NIST Cybersecurity Framework, NIST 8259 (IoT Device Cybersecurity).
  • Professional security certifications such as: OSCP, GPEN, CompTIA PenTest.
  • Experience in using AI tools in day-to-day workflow.

Skills

Apply

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available