> Markdown version of [/jobs/ext/600549-senior-product-security-consultant](https://www.wearedevelopers.com/jobs/ext/600549-senior-product-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Product Security Consultant - **Company:** Cloudious LLC - **Location:** Tewksbury, MA, United States - **Experience:** Expert - **Salary:** $200,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Software Debugging, Firmware, Linux System Administration, Network Protocols, Software Security, IoT Security - **Published:** June 23, 2026 - **Apply:** https://www.careerjet.com/jobad/us0126e85a5952df784c479cf4ce93edc4 ## About the Role Mandatory: Strong hands-on penetration testing and product security assessment experience Experience with embedded systems, connected devices, and firmware security analysis Experience with firmware binary analysis techniques and embedded security testing tools Familiarity with hardware/device attack surfaces and embedded system architectures Familiarity with Linux-based systems, network protocols, and secure update mechanisms Good to have: Experience participating in CRA or regulated product security, or compliance-driven cybersecurity assessments Experience participating in engagement related to export-controlled environments Strong documentation skills Preferred Certifications OSCP OSEP / OSCE GPEN / GXPN Embedded or IoT security experience preferred Completed SANS training SEC556 (IoT Pen Testing) Years of Required Experience 7-10 years in product security testing including device-level penetration testing firmware extraction, unpacking, and binary analysis ## Description Perform hands-on technical product security assessment activities across the customer product ecosystem, including hardware and device penetration testing, firmware extraction and binary analysis, exploitability validation, secure update mechanism review, and embedded security assessment. Key Responsibilities Perform hardware and device-level penetration testing Conduct firmware extraction, unpacking, and binary analysis Assess secure boot, firmware integrity, rollback protection, and update mechanisms Evaluate exposed interfaces (USB, network, wireless, serial/debug, administrative services) Validate authentication, authorization, encryption, and secure configuration controls Conduct exploitability validation, attack path analysis, and privilege escalation testing Analyze attack surfaces to identify material security weaknesses across device components Perform resilience testing and evaluate effectiveness of security controls ## Related Videos - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [MySQL Protocol Features You Should Be Aware Of](https://www.wearedevelopers.com/videos/100267-mysql-protocol-features-you-should-be-aware-of) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)