Product Security Consultant
Blueprint School Network, Inc.
Tewksbury, MA, United States
1 day ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on zappsec.applytojob.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours
Job source
Tech stack
Application Programming Interfaces (APIs)
Software System Penetration Testing
User Authentication
Automation of Tests
Burp Suite
Software Debugging
Dynamic Program Analysis
Firmware
Fuzz Testing
Hardware Security Module
Joint Test Action (IEEE Standards)
Linux System Administration
+15 more
Wireless Security
Network Protocols
Nmap
Open Source Technology
OpenSSL
Reverse Engineering
Tripwire
Wireshark
Universal Asynchronous Receiver/Transmitter
Wi-Fi Technology
Data Logging
Software Security
IDA Pro
U-Boot
IoT Security
Job description
- Hands-on technical product security assessment activities across the customer product ecosystem, including hardware and device penetration testing, firmware extraction and binary analysis, exploitability validation, secure update mechanism review, and embedded security assessment.
- The role will cover UART/JTAG/SWD/USB, firmware extraction, binary analysis, reverse engineering, secure boot, signing, updates, rollback, authentication, encryption, secure defaults, logging, deletion and residual data.
- Testing may extend to extends to BLE, Wi-Fi, web/API, companion applications and proprietary protocols, including controlled fuzzing.
- The consultant will work under formal safety and restoration controls, validate exploitability and compensating controls, assess blast radius and containment, eliminate false positives, produce reproducible evidence and remediation guidance, and perform retesting.
Key Responsibilities
- Perform hardware and device-level penetration testing
- Conduct firmware extraction, unpacking, and binary analysis
- Assess secure boot, firmware integrity, rollback protection, and update mechanisms
- Evaluate exposed interfaces (USB, network, wireless, serial/debug, administrative services)
- Validate authentication, authorization, encryption, and secure configuration controls
- Conduct exploitability validation, attack path analysis, and privilege escalation testing
- Analyse attack surfaces to identify material security weaknesses across device components
- Perform resilience testing and evaluate effectiveness of security controls
- Test BLE, Wi-Fi, web/API, companion applications and proprietary protocols, including controlled fuzzing
- Work with the Security architect to identify the test cases and the required open-source testing tools to perform the required IEC 62443 and EU CRA controls.
- Lead the hardware security testing, authentication, authorization, encryption, and secure configuration controls and other active tools-based testing part of the engagement.
Requirements
Mandatory:
- Strong hands-on penetration testing and product security assessment experience across embedded systems, connected devices, and firmware security.
- Experience with firmware extraction, unpacking, reverse engineering, binary analysis, dynamic analysis, and embedded security testing.
- Familiarity with hardware/device attack surfaces, embedded system architectures, Linux-based systems, network protocols, and secure update mechanisms.
- Ability to assess secure boot, firmware integrity, firmware trust chain, signing, rollback protection, secure update flows, filesystem security, bootloader security, and binary-level risks.
- Experience testing authentication, authorization, encryption, TLS/certificates, cryptographic keys, hardware-backed key storage, device identity, secure elements, TPM, and TEE concepts.
- Experience with exploitability validation, attack path analysis, protocol fuzzing, wireless security testing, and interface testing across UART, JTAG, SWD, USB, BLE, Wi-Fi, and proprietary protocols.
- Hands-on experience using security testing and analysis tools such as Binwalk, Ghidra, IDA Pro, Radare2, OpenSSL, Burp Suite, Nmap, Wireshark, testssl.sh, Trivy, GDB, Frida, firmware emulators, protocol fuzzers, logic analyzers, and approved debug-interface tooling.
Good to have:
- Experience participating in CRA or regulated product security, or compliance-driven cybersecurity assessments
- Experience participating in engagement related to export-controlled environments
- Embedded or IoT security experience preferred
Preferred Certifications
- GXPN (Top Choice)
- OSEP
- Completed SANS training SEC556 (IoT Pen Testing)
Years of Required Experience
- 7-10 years in product security testing including device-level penetration testing
- 10+ years in Product Security Testing firmware extraction, unpacking, and binary analysis
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on zappsec.applytojob.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
CH
Chris Heilmann
almost 2 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
7 months ago
LM
Luis Minvielle
The 8 Best Code Testing Tools
over 2 years ago
IK
Igor Khokhriakov
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
24 days ago
DC
Daniel Cranney
The Overflow: Security and Privacy
6 months ago