> Markdown version of [/jobs/ext/575080-penetration-tester-embedded-devices](https://www.wearedevelopers.com/jobs/ext/575080-penetration-tester-embedded-devices). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Penetration Tester, Embedded Devices - **Company:** TP-Link North America, Inc. - **Location:** Irvine, CA, United States - **Experience:** Starter - **Salary:** $80,000.0 - $132,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Automation of Tests, Bash Shell, C++ (Programming Language), Cyber Security, Fuzz Testing, Python (Programming Language), Kali Linux, Nmap, Windows PowerShell, Systems Development Life Cycle, Reverse Engineering, Software Vulnerability Management, Information Technology, Metasploit, Nessus, Burpsuite, Static Application Security Testing - **Published:** June 21, 2026 - **Apply:** https://www.juju.com/job/00000000g9nf2i ## About the Role + Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent work experience). + Proven 1-3 years' experience as a Security Engineer (Embedded devices) or in a similar role. + Strong knowledge of protocol security design, cryptography, security frameworks and common vulnerabilities. + Experience with security tools such as Burpsuite, Nmap, Kali, Nessus, Metasploit, IDA, Ghidra, etc. + Capability to optimize penetration testing tools and Fuzzing strategies. + Ability to analyze SAST results, conduct basic reverse engineering. + Proficient in at least one programming language (e.g., C/C++, Python, Bash, or PowerShell). + Relevant advanced security certifications (e.g., OSWP, etc.) are highly preferred. + Published CVEs are highly preferred. Soft Skills: + Strong communication and interpersonal skills. Ability to work independently as well as collaborate with cross-functional teams. + Strong willingness to learn, able to work under guidance and take constructive feedback. + Team-oriented mindset, with the ability to follow technical direction and contribute constructively to group tasks. ## Description TP-Link Systems Inc. is seeking a skilled and proactive Penetration Testing Engineer, Embedded Devices to support our embedded product projects under the guidance of senior team members. This role is designed for candidates with a foundational technical background in cybersecurity, particularly in embedded devices. Under the mentorship of senior engineers, the successful candidate will be involved in a range of security activities for a single product category, including penetration testing, threat modeling and security assessment for specific modules, contributing to investigation, risk assessment and verification for incident response. The ideal candidate is eager to learn, capable of working within defined boundaries, and driven to enhance the security of TP-Link's embedded devices. Key Responsibilities: + Penetration Testing: Perform penetration testing on embedded products to identify vulnerabilities. Provide remediation recommendations and write detailed penetration test reports. + Threat Modelling and security assessment: Perform threat modeling to identify and evaluate potential risks for specific modules. + Incident Response and Vulnerability Management: Responsible for specific area's incident response, including investigation, containment, remediation, and post-incident analysis. Coordinate with cross-functional teams to ensure effective resolution. + Product cybersecurity certification: Analyze specific product security certification requirements and collaborate with cross-functional teams to achieve product security certification. + Develop security tools: Assist in developing various pen-testing tools, automated testing platforms, and scripts to enhance testing efficiency and accuracy. + SDLC Integration: Participate in the development and improvement of the company's SDLC processes, ensuring security considerations are embedded during development. + Interpret global cybersecurity standards and regulatory requirements, supporting implementation of security requirements. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [It's a (testing) trap! - Common testing pitfalls and how to solve them](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)