Summary
TrustedSec is seeking an information security professional to join its Software Security Team. The Hardware Security Consultant / Penetration Tester will conduct hardware, web application, API, mobile application, and embedded systems security assessments, produce actionable reports, manage client engagements, and collaborate with internal teams. The role also contributes to security education, publications, and industry events.
Responsibilities
- Conduct high-quality hardware security assessments with limited direct supervision
- Produce clear, technically accurate reports with testing walkthroughs, findings, and actionable recommendations for both technical and executive audiences
- Conduct client meetings, serve as the primary point of contact, and interface directly with clients during engagements
- Serve as a subject matter expert for other consultants/teams and regularly collaborate and contribute to furthering the education and progression of the skills and success of everyone at TrustedSec
- Maintain and build upon cybersecurity knowledge and skills by attending educational workshops and adopting a curious, continuous learning mindset
- Review publications, write blog posts, and potentially speak at conferences or other events
Skills
- The candidate must be legally authorized to work in the United States
- 2+ years' recent experience performing hardware security assessments
- 2+ years' recent experience testing web applications and APIs
- Experience identifying and interfacing with debug interfaces such as JTAG, SWD, and UART, including locating undocumented test points
- Experience with firmware extraction and firmware analysis, including extraction via debug interfaces, chip-off, or vendor update files
- Proficiency with Ghidra, Binary Ninja or equivalent for firmware reverse engineering
- Experience assessing Wi-Fi and Bluetooth communications, including traffic flows between devices and mobile applications
- Proficiency in Burp Suite, or other intercepting proxy, for intercepting and analyzing web and mobile application traffic, and familiarity with Wireshark for non-HTTP network traffic
- Experience escaping restricted environments on self-service terminals
- Knowledge of manual application security testing, penetration testing methodologies, the OWASP Top 10, and the OWASP Testing Guide
- Strong understanding of common security controls and vulnerability testing techniques
- Good time management skills and the ability to meet strict deadlines
- Demonstrated analytical and project management skills
- Excellent verbal and written communication skills including active listening and competence in presenting findings and recommendations to audiences with a range of technical understanding
- Ability to write technical documents with correct spelling, grammar, and punctuation and the ability to distill information for non-echnical readers
- Thrive in a fast-paced, collaborative environment
- Ability to take initiative and work independently
- Experience assessing cellular-connected devices, including AT command interaction, SIM extraction, and IMEI spoofing
- Ability to write scripts to support testing and tooling development
- Familiarity with AI/LLMs/frontier models/agentic tools/coding assistants
- Experience in mobile application testing
- Prior consulting experience
- Industry-recognized security certification(s) such as OSCP, Burp Suite Certified Practitioner, OSWE, etc
Qualifications
Must Haves
- The candidate must be legally authorized to work in the United States
- 2+ years' recent experience performing hardware security assessments
- 2+ years' recent experience testing web applications and APIs
- Experience identifying and interfacing with debug interfaces such as JTAG, SWD, and UART, including locating undocumented test points
- Experience with firmware extraction and firmware analysis, including extraction via debug interfaces, chip-off, or vendor update files
- Proficiency with Ghidra, Binary Ninja or equivalent for firmware reverse engineering
- Experience assessing Wi-Fi and Bluetooth communications, including traffic flows between devices and mobile applications
- Proficiency in Burp Suite, or other intercepting proxy, for intercepting and analyzing web and mobile application traffic, and familiarity with Wireshark for non-HTTP network traffic
- Experience escaping restricted environments on self-service terminals
- Knowledge of manual application security testing, penetration testing methodologies, the OWASP Top 10, and the OWASP Testing Guide
- Strong understanding of common security controls and vulnerability testing techniques
- Good time management skills and the ability to meet strict deadlines
- Demonstrated analytical and project management skills
- Excellent verbal and written communication skills including active listening and competence in presenting findings and recommendations to audiences with a range of technical understanding
- Ability to write technical documents with correct spelling, grammar, and punctuation and the ability to distill information for non-echnical readers
- Thrive in a fast-paced, collaborative environment
- Ability to take initiative and work independently
Nice to Haves
- Experience assessing cellular-connected devices, including AT command interaction, SIM extraction, and IMEI spoofing
- Ability to write scripts to support testing and tooling development
- Familiarity with AI/LLMs/frontier models/agentic tools/coding assistants
- Experience in mobile application testing
- Prior consulting experience
- Industry-recognized security certification(s) such as OSCP, Burp Suite Certified Practitioner, OSWE, etc
Benefits
- This is a remote position, allowing employees to work from their home residence within the United States.
- Generous paid time off allowance
- Paid holidays
- A performance pay bonus program