Security Engineer (Penetration Testing experience)
The Security Engineer will be responsible for helping to build and support the company's Product Security Program. This cross‑functional position will work directly with product development teams by consulting on and testing security strategies.
As a Security Engineer, You Will :
- Perform product security testing and reporting, including but not limited to :
Black box reverse engineering of hardware and firmware
Vulnerability researchConduct manual penetration testing, including but not limited to :Mobile Applications (iOS & Android)
Web ApplicationsNetwork SystemsFacilitate threat modeling with company application, infrastructure, and product teams.Perform security training and outreach to internal development teams.Perform security analysis & evaluation of OT environments related to product manufacturing.Perform security analysis & evaluation of both hardware and software supply chains.Maintain documentation and metrics for the product security program’s services.Department Summary
The Product Security department is focused on ensuring that our products are secure and that we are protecting our clients from relevant cyber threats by proactively identifying, addressing, and preventing vulnerabilities that could impact the confidentiality, integrity, or availability of our products, services, or solutions. We seek individuals with experience and innovative ideas in Operational Technology (OT) / ICS SCADA / IOT security interested in integrated security operations (IT, OT, and Physical) and adversary emulation.
Who you are :
You look beyond the obvious and don’t stop at the first answers. You adjust communication content and style to meet the needs of diverse stakeholders. You maintain relationships across a variety of functions and locations. You are not afraid to disagree and are open to debate.
Minimum Qualifications
Minimum of 5 years of experience with any combination of the following : embedded systems and IoT security, red teaming, or penetration testingExperience conducting security testing of embedded hardware and the ability to identify and manipulate debug interfaces (UART, JTAG, SWD) and peripheral buses (SPI, I2C)Binary Reverse Engineering of ARM, MIPS, and PowerPC firmware using industry‑standard tools such as IDA Pro, Binary Ninja, GhidraExperienced planning and executing Red Team exercisesExperience in Fuzz Testing of industrial communication protocols like Wi‑Fi, BLE, Wireless HART, PROFINET, MODBUS, Ethernet IP, OPC UA, HART, FFUnderstanding of secure libraries (e.g., bootloader, etc.)Knowledge of embedded Linux required, knowledge of Real‑Time Operating Systems a plusUnderstanding network, web, IoT, and industrial‑related protocols (TCP / UDP, HTTPS, MQTTS, CoAP, Modbus, Ethernet / IP, DNP3, OPC‑UA, etc.)Excellent written and verbal communication skillsStrong sense of ownership, urgency, and driveSharp analytical skills with the ability to synthesize new information quicklyPreferred Qualifications
Understanding of cloud solutions and architectures supporting IoT and Edge computing environmentsExperience with programming languages such as Python, C#, C / C++, Ruby, AssemblyExperience with OT network monitoring, including serial, Ethernet, wirelessExperience with OT adversary emulationWorking knowledge of cybersecurity policies and standards related to IC / SCADASeniority level
Mid‑Senior level
Employment type
Full‑time
Job function
Information Technology
#J-18808-Ljbffr