Embedded Penetration Tester
120 - 150 PLN/ godz.B2B
SeniorFull-time·B2B
#429462·Dodano wczoraj·0
Źródło: nofluffjobs.comTech Stack / Keywords
Embedded systemIoTSecurityBootCryptographyProtocolsCloud securityISOIECTestingUARTSPITCPSDLCCybersecurityNISTGDPROSCPAI
Firma i stanowisko
Spyrosoft is a software engineering company founded in 2016, recognized among Europe's fastest-growing technology companies in 2021 and 2022. The company specializes in technology solutions for industry 4.0, automotive, geospatial, healthcare & life sciences, employee experience & education, and financial services industries.
Wymagania
- Strong experience in embedded systems, IoT security, or product cybersecurity.
- Hands-on knowledge of secure boot, firmware protection, code signing, and secure update mechanisms.
- Deep understanding of cryptography and key management in embedded environments.
- Experience securing communication protocols and network interfaces in connected devices.
- Knowledge of IoT authentication, authorization, and cloud security architectures.
- Experience with threat modeling methodologies such as STRIDE, DREAD, and Attack Trees.
- Ability to perform security risk assessments aligned with ISO 21434, IEC 62443, ISO 27005.
- Understanding of common embedded attack vectors: side-channel, fault injection, firmware tampering, replay, MITM attacks.
- Experience conducting penetration testing on embedded targets using JTAG, UART, SPI, and I²C.
- Experience with fuzz testing communication stacks (CAN, TCP/IP, MQTT).
- Understanding of secure SDLC principles, DevSecOps, and cybersecurity lifecycle management.
- Knowledge of vulnerability management, system hardening, and threat surface reduction strategies.
- Understanding GDPR, HIPAA, and data protection requirements for cloud-connected solutions.
Nice to have:
- Experience in regulated industries such as Automotive, Industrial Automation, Medical Devices.
- Familiarity with IEC 62304, ISO 27001, NIST Cybersecurity Framework, NIST 8259.
- Professional security certifications such as OSCP, GPEN, CompTIA PenTest.
- Experience working with Rust-based secure embedded applications.
- Experience in using AI tools in day-to-day workflow.
Obowiązki
- Design and implement security architectures for embedded and IoT solutions.
- Define and maintain secure boot, firmware integrity, code signing, and OTA update strategies.
- Establish secure device provisioning, onboarding, and lifecycle management processes.
- Conduct threat modeling, security risk assessments, and security reviews throughout the product lifecycle.
- Assess and mitigate vulnerabilities across embedded devices, cloud platforms, and communication interfaces.
- Perform penetration testing, fuzz testing, and vulnerability assessments on embedded targets and IoT ecosystems.
- Drive secure coding practices and perform security-focused code reviews.
- Collaborate with development, platform, and cloud teams to integrate security into CI/CD pipelines and development processes.
- Ensure compliance with applicable cybersecurity standards and regulatory requirements.
- Support incident response activities, vulnerability remediation, and continuous security improvement initiatives.
- Manage SBOM creation, maintenance, and software supply chain security activities.
Spyrosoft
178 aktywnych ofert