Senior Product Security Consultant

Cloudious LLC
Tewksbury, MA, United States
2 months ago
Apply on careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$200,000.0
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Software Debugging Firmware Linux System Administration Network Protocols Software Security IoT Security

Job description

Perform hands-on technical product security assessment activities across the customer product ecosystem, including hardware and device penetration testing, firmware extraction and binary analysis, exploitability validation, secure update mechanism review, and embedded security assessment. Key Responsibilities Perform hardware and device-level penetration testing Conduct firmware extraction, unpacking, and binary analysis Assess secure boot, firmware integrity, rollback protection, and update mechanisms Evaluate exposed interfaces (USB, network, wireless, serial/debug, administrative services) Validate authentication, authorization, encryption, and secure configuration controls Conduct exploitability validation, attack path analysis, and privilege escalation testing Analyze attack surfaces to identify material security weaknesses across device components Perform resilience testing and evaluate effectiveness of security controls

Requirements

Mandatory: Strong hands-on penetration testing and product security assessment experience Experience with embedded systems, connected devices, and firmware security analysis Experience with firmware binary analysis techniques and embedded security testing tools Familiarity with hardware/device attack surfaces and embedded system architectures Familiarity with Linux-based systems, network protocols, and secure update mechanisms Good to have: Experience participating in CRA or regulated product security, or compliance-driven cybersecurity assessments Experience participating in engagement related to export-controlled environments Strong documentation skills Preferred Certifications OSCP OSEP / OSCE GPEN / GXPN Embedded or IoT security experience preferred Completed SANS training SEC556 (IoT Pen Testing) Years of Required Experience 7-10 years in product security testing including device-level penetration testing firmware extraction, unpacking, and binary analysis

About the company

MSP Hire, Inc.

  • Burlington, MA
  • $200,000 per year Daymark Solutions is an experienced technology integration and solutions provider that helps organizations effectively architect, implement, and deploy customized solutions using b…

  • 1 month ago

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:19 min

Enhancing product safety through continual red teaming operations

Rebekka Weiss Rebekka Weiss +1 · World Congress 2025

3:04 min

Supporting modern network protocols in foundational libraries

Daniel Stenberg · Coffee With Developers

3:13 min

Exposing application programming interface vulnerabilities in robotic devices

Chris Heilmann +2 · LIVE

2:19 min

Orchestrating over-the-air firmware updates for vehicle modules

Denis Grahovac · World Congress 2021

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

2:44 min

Defining foundational architectures and scaling solutions for networks

Ryan Arndt · World Congress 2023

Videos

See all

Related articles

See all