Hardware Security and Vulnerability Analyst - Hybrid (Office/Remote)

EndoSec LLC
Lafayette, IN, United States
5 days ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

C++ (Programming Language) Software Debugging Embedded Software Firmware Field-Programmable Gate Array (FPGA) Hardware Security Module Systems Analysis Python (Programming Language) Microsoft Office Reverse Engineering IDA Pro

Job description

The EndoSec Hardware Security and Vulnerability Analyst is responsible for extracting and analyzing firmware and data at rest, identifying vulnerabilities in software, firmware, and hardware, as well as developing proof of concept exploits. The candidate will collaborate with other engineers and security experts to find and exploit security flaws and vulnerabilities within devices and designs as well as to build secure and efficient systems, contributing to our products and services’ ongoing security and privacy. This is a remote position., 1. System Analysis: Analyze systems to understand functionality, failure points, and consequences of failure.

  1. Security Measure Circumvention: Bypass implemented security measures to gain access to sensitive data, including enabling debugging, forging or bypassing signatures, gaining elevated privileges, and simulating environmental and working conditions.
  2. Binary Code Extraction and Analysis: Extract firmware, executables, and other sensitive data from embedded systems and analyze the extracted code for possible vulnerabilities and sensitive data, e.g. passwords, cryptographic keys, etc.
  3. Side-Channel Analysis and Fault Injection: Setup and perform side-channel analysis to recover sensitive data, e.g. cryptographic keys, sensitive plaintext, etc. Setup and perform fault injection attacks to bypass security measures and/or recover sensitive data.
  4. Exploit Development: Develop custom and novel exploits to bypass security measures, recover sensitive data, or gain elevated privileges in embedded systems.
  5. Documentation: Prepare detailed documentation, including physical setups, testing procedures, and user guides, for reproducibility of found results and maintenance.
  6. Continuous Learning: Stay current with the latest advancements in reverse engineering and hardware security to continually refine and enhance skills.

Requirements

  • Preferred Skills: C/C++, Python, assembly, IDA Pro, Ghidra, FPGA, cryptography, hardware, embedded software, hardware security, reverse engineering, side channel attacks, fault injection
  • Travel required up to 20%.

Full Time

Must be able to apply for and maintain a U.S. Government Security Clearance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:19 min

Orchestrating over-the-air firmware updates for vehicle modules

Denis Grahovac · World Congress 2021

3:06 min

System thinking and the necessity of architectural synthesis

Mourjo Sen Mourjo Sen · World Congress 2026 Europe

1:57 min

Following security research and continuous developer education

Martin Schmiedecker · LIVE

2:20 min

Utilizing custom firmware for variable torque manipulation

Daniel Meilak Daniel Meilak +1 · World Congress 2026 Europe

2:10 min

Analyzing logic and performance metrics via developer profiling tools

Paul Graham Paul Graham · LIVE

Videos

See all

Related articles

See all