Unlock Full Resume Report

New offer - be the first one to apply!

September 8, 2026

Embedded Penetration Tester

Senior • Remote

120 - 150 PLN/yr

Wrocław, DS, Poland

Tech stack

  • Secure boot, firmware security, OTA updates
  • Cryptography (AES, RSA, ECC) and hardware security (TPM, HSM, TrustZone)
  • Embedded interfaces and protocols: CAN, LIN, Modbus, BLE, Wi-Fi, TCP/IP
  • Penetration testing on embedded targets: JTAG, UART, SPI, I²C
  • Cloud IoT platforms and secure communication: AWS/Azure/GCP IoT, TLS/DTLS, MQTT(S)
  • Secure code review (C/C++, Rust, Python) and DevSecOps / CI/CD security

Requirements

  • Strong experience in embedded systems, IoT security, or product cybersecurity
  • Hands-on knowledge of secure boot, firmware protection, code signing, and secure update mechanisms
  • Deep understanding of cryptography and key management in embedded environments
  • Experience securing communication protocols and network interfaces in connected devices
  • Knowledge of IoT authentication, authorization, and cloud security architectures
  • Experience with threat modeling methodologies such as STRIDE, DREAD, and Attack Trees
  • Ability to perform security risk assessments aligned with ISO 21434, IEC 62443, and ISO 27005
  • Understanding of common embedded attack vectors: side-channel attacks, fault injection, firmware tampering, replay attacks, and MITM attacks
  • Experience conducting penetration testing on embedded targets using JTAG, UART, SPI, and I²C
  • Experience with fuzz testing communication stacks including CAN, TCP/IP, and MQTT
  • Understanding of secure SDLC principles, DevSecOps, and cybersecurity lifecycle management
  • Knowledge of vulnerability management, system hardening, and threat-surface reduction strategies
  • Understanding of GDPR, HIPAA, and data-protection requirements for cloud-connected solutions

Nice to have

  • Experience in regulated industries such as Automotive, Industrial Automation, or Medical Devices
  • Familiarity with IEC 62304, ISO 27001, NIST Cybersecurity Framework, and NIST 8259 (IoT Device Cybersecurity)
  • Professional security certifications such as OSCP, GPEN, or CompTIA PenTest
  • Experience working with Rust-based secure embedded applications
  • Experience using AI tools in day-to-day workflow

Project description

The role seeks a Penetration Tester with a proven track record of identifying and exploiting security weaknesses across a wide range of systems and environments. Deep expertise in advanced penetration-testing methodologies, tools, and reporting is expected, along with strong analytical and problem-solving skills. Embedded systems security experience is highly desirable. Excellent communication skills are needed to translate technical findings into clear, actionable recommendations for stakeholders.

Main responsibilities

  • Design and implement security architectures for embedded and IoT solutions
  • Define and maintain secure boot, firmware integrity, code signing, and OTA update strategies
  • Establish secure device provisioning, onboarding, and lifecycle-management processes
  • Conduct threat modeling, security risk assessments, and security reviews throughout the product lifecycle
  • Assess and mitigate vulnerabilities across embedded devices, cloud platforms, and communication interfaces
  • Perform penetration testing, fuzz testing, and vulnerability assessments on embedded targets and IoT ecosystems
  • Drive secure coding practices and perform security-focused code reviews
  • Collaborate with development, platform, and cloud teams to integrate security into CI/CD pipelines and development processes
  • Ensure compliance with applicable cybersecurity standards and regulatory requirements
  • Support incident response, vulnerability remediation, and continuous security-improvement initiatives
  • Manage SBOM creation, maintenance, and software supply-chain security activities

Similar jobs you might like