Embedded Penetration Tester
Tech stack:
Embedded & IoT Security
Secure Boot, Firmware Integrity, and Code Signing
Secure OTA (Over-the-Air) update mechanisms
Key Management for embedded environments
Hardware security technologies: TPM, HSM, ARM TrustZone, Secure Elements
Cryptography & Secure Communications
Cryptographic algorithms: AES, RSA, ECC
Lightweight cryptography for resource-constrained devices
TLS / DTLS, MQTT(S), CoAP(S)
Device-to-cloud and cloud-to-device encryption
Authentication and authorization frameworks for IoT devices
Cloud & IoT Platforms
Cloud IAM (AWS IoT Core, Azure IoT Hub, GCP IoT Core)
Secure device provisioning and onboarding
Embedded & Industrial Protocols
CAN, LIN, Modbus, OPC UA
BLE, USB, Wi-Fi, NFC
TCP/IP, UDP, IPv4, IPv6
Security Testing & Development
Penetration testing tools and methodologies
Fuzz testing
Vulnerability scanning
Secure code review (C/C++, Rust, Python)
DevSecOps and CI/CD security
SBOM generation and management
Requirements:
Strong experience in embedded systems, IoT security, or product cybersecurity.
Hands-on knowledge of secure boot, firmware protection, code signing, and secure update mechanisms.
Deep understanding of cryptography and key management in embedded environments.
Experience securing communication protocols and network interfaces in connected devices.
Knowledge of IoT authentication, authorization, and cloud security architectures.
Experience with threat modeling methodologies such as STRIDE, DREAD, and Attack Trees.
Ability to perform security risk assessments aligned with: ISO 21434, IEC 62443, ISO 27005.
Understanding of common embedded attack vectors: side-channel attacks, fault injection, firmware tampering, replay attacks, Man-in-the-Middle (MITM) attacks.
Experience conducting penetration testing on embedded targets using interfaces such as JTAG, UART, SPI, and I²C.
Experience with fuzz testing communication stacks (CAN, TCP/IP, MQTT).
Understanding of secure SDLC principles, DevSecOps, and cybersecurity lifecycle management.
Knowledge of vulnerability management, system hardening, and threat surface reduction strategies.
Nice to have:
Experience in regulated industries such as Automotive, Industrial Automation, Medical Devices.
Familiarity with: IEC 62304, ISO 27001, NIST Cybersecurity Framework, NIST 8259 (IoT Device Cybersecurity).
Understanding of GDPR, HIPAA, and data protection requirements for cloud-connected solutions.
Experience with incident response planning for connected and embedded systems.
Professional security certifications such as: OSCP, GPEN, CompTIA PenTest.
Experience working with Rust-based secure embedded applications.
Experienced in using AI tools in day-to-day workflow.
Project description:
We're looking for a Penetration Tester with a proven track record of successfully identifying and exploiting security weaknesses across a wide range of systems and environments. The ideal candidate will have deep expertise in advanced penetration testing methodologies, tools, and reporting, with strong analytical and problem-solving skills. Experience in embedded systems security is highly desirable and will be considered a significant advantage. This role requires excellent communication skills to translate technical findings into clear, actionable recommendations for stakeholders.
Main responsibilities:
Design and implement security architectures for embedded and IoT solutions.
Define and maintain secure boot, firmware integrity, code signing, and OTA update strategies.
Establish secure device provisioning, onboarding, and lifecycle management processes.
Conduct threat modeling, security risk assessments, and security reviews throughout the product lifecycle.
Assess and mitigate vulnerabilities across embedded devices, cloud platforms, and communication interfaces.
Perform penetration testing, fuzz testing, and vulnerability assessments on embedded targets and IoT ecosystems.
Drive secure coding practices and perform security-focused code reviews.
Collaborate with development, platform, and cloud teams to integrate security into CI/CD pipelines and development processes.
Ensure compliance with applicable cybersecurity standards and regulatory requirements.
Support incident response activities, vulnerability remediation, and continuous security improvement initiatives.
Manage SBOM creation, maintenance, and software supply chain security activities.
- Department
- Software Delivery
- Role
- Security Engineer
- Locations
- Wroclaw (PL), Poland (PL)
- Remote status
- Hybrid
- Hourly salary
- PLN120 - PLN150
- Experience
- Regular, Senior
- Area
- Embedded, QA, Defence & Security
About Spyrosoft
Spyrosoft is an authentic, cutting-edge software engineering company, established in 2016. In 2021 and 2022, we were among the fastest growing technology companies in Europe, according to the Financial Times. We were founded by a group of tech experts with established backgrounds in software engineering, who created an ‘engineer-to-engineer’ workplace, powered by enthusiasm, fairness and authentic relationships. Having a unique offering, which bridge the gap between technology and business, we specialise in technology solutions for industry 4.0, automotive, geospatial, healthcare & life sciences, employee experience & education and financial services industries.