> Markdown version of [/jobs/ext/1189364-penetration-tester-iot-embedded-devices](https://www.wearedevelopers.com/jobs/ext/1189364-penetration-tester-iot-embedded-devices). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester - IoT & Embedded Devices - **Company:** Enphase Energy - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Software System Penetration Testing, ARM Architecture, Booting (BIOS), Burp Suite, C++ (Programming Language), Software Debugging, Linux on Embedded Systems, Firmware, Fuzz Testing, Joint Test Action (IEEE Standards), Python (Programming Language), Open Web Application Security, Quick EMUlator (QEMU), Real-Time Operating Systems, Reverse Engineering, Universal Asynchronous Receiver/Transmitter, Wi-Fi Technology, Information Technology, IDA Pro, EMMC - **Published:** July 5, 2026 - **Apply:** http://app.jobvite.com/CompanyJobs/Careers.aspx?c=qu49Vfwm&j=ob5nAfwX&k=Apply ## About the Role * BE/BTech/MS/MTech in Computer Science, Electrical Engineering, or a related field. * A minimum of 6+ years of experience in IoT/embedded penetration testing * Strong expertise in hardware and bus-level analysis (UART, SPI, I²C, JTAG/SWD), logic analyzers, and an understanding of fault-injection/glitching and side-channel techniques * Hands-on firmware reverse engineering and binary analysis across ARM and MIPS, including bootloader and RTOS internals * Proficiency with Ghidra/IDA Pro, Binwalk, QEMU, Burp Suite, and SDR/logic-analyzer hardware tools * Experience in RF/wireless fuzzing and API exploitation * Strong understanding of embedded Linux systems and ARM architectures * Knowledge of CVE disclosure processes and OWASP IoT Top 10 * Familiarity with standards such as IEC 62443 and EU Cyber Resilience Act * Excellent analytical, problem-solving, and communication skills * Familiarity with Wi-Fi/cellular networking and bidirectional powerline (PLC) communication security * Experience with cloud-managed OTA update pipelines and full-stack red-team engagements spanning device, network, and cloud layers * Proficiency in Python and C/C++ for automation, tooling, and exploit development Nice to have: * Published CVEs, security advisories, or competitive Capture-the-Flag (CTF) experience * Exploit development and custom tooling for embedded and ARM targets * Relevant certifications such as OSCP, OSCE, GXPN, or GIAC GPEN ## Description As a Senior Penetration Tester - IoT & Embedded Devices, you will be part of a cutting-edge cybersecurity team focused on securing our connected energy ecosystem, including IQ Gateway, IQ Microinverters, IQ Batteries, and EV Chargers deployed across 4M+ homes in 150+ countries. These devices rely on bidirectional powerline communication, Wi-Fi and cellular networking, and cloud-managed over-the-air (OTA) firmware updates. You will lead offensive security testing across hardware, firmware, and software layers, while partnering closely with the CISO's office to drive vulnerability lifecycle management from discovery to remediation. What you will be doing: * Perform hardware security testing: PCB teardown, component identification, bus sniffing and injection on UART/SPI/I²C, and logic-analyzer/oscilloscope signal capture * Reverse-engineer firmware - dump SPI/eMMC flash, unpack with Binwalk, perform static analysis in Ghidra/IDA, and emulate with QEMU to surface logic flaws and hardcoded secrets * Capture, analyze, and fuzz RF/wireless traffic with SDR tooling (HackRF/RTL-SDR) across BLE, Wi-Fi, sub-GHz, and cellular protocols * Test cloud APIs and backend services (REST, gRPC, MQTT) for authentication bypass, IDOR, injection, and broken access control * Lead end-to-end red-team exercises that chain device, network, and cloud footholds - lateral movement, privilege escalation, and persistence on embedded Linux/ARM platforms * Document findings with reproducible PoCs, CVSS scoring, and remediation guidance, and retest fixes through closure * Collaborate with internal security and engineering teams to strengthen product security * Ensure compliance with industry security standards and best practices * Perform JTAG/SWD debug-port attacks to extract, analyze, and modify device firmware * Assess the security of Wi-Fi, cellular, and bidirectional powerline (PLC) communication interfaces * Evaluate cloud-managed OTA firmware update mechanisms for integrity, authentication, and rollback protection ## Related Videos - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [When Agents Meet Legacy: Never Change a Running System](https://www.wearedevelopers.com/videos/100320-when-agents-meet-legacy-never-change-a-running-system) - [A Hitchhikers Guide to Container Security - Automotive Edition 2024](https://www.wearedevelopers.com/videos/1119-a-hitchhikers-guide-to-container-security-automotive-edition-2024) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 182: GPT5 Prompts, MCP Vulnerabilities, Code Traps](https://www.wearedevelopers.com/magazine/622-dev-digest-182-gpt5-prompts-mcp-vulnerabilities-code-traps)