Hardware Security Consultant / Penetration Tester

Posted 9 Days Ago
Be an Early Applicant
Fairlawn, OH, USA
In-Office
80K-150K Annually
Junior
Information Technology • Cybersecurity
The Role
Conduct hardware, firmware, web, mobile, and API security assessments; identify vulnerabilities; reverse engineer firmware; analyze wireless communications; and produce actionable reports. The consultant will lead client meetings, build relationships, serve as a security subject matter expert, collaborate across teams, contribute to knowledge-sharing, and occasionally write or present security research. This remote U.S.-based role requires travel to client sites and industry events up to 25% annually.
Summary Generated by Built In

Description

  

TrustedSec is seeking a passionate information security professional to join our Software Security Team. The Hardware Security Consultant / Penetration Tester will report to the Practice Lead and be responsible for assisting clients in their hardware security needs, including conducting hardware security assessments to identify vulnerabilities, deliver clear and actionable findings, and help clients improve their overall security posture. The ideal candidate brings hardware security expertise and is equally capable in application security. Modern devices often depend on companion mobile applications and backend web infrastructure, and this role is responsible for evaluating these components as a single system. The consultant will also perform dedicated web application security assessments. At times, the consultant will work with other teams within the organization to collaborate on deliverables.
 

This is both a technical and client-facing role. As such, the candidate should have experience in penetration testing and embedded systems and be capable of building direct client relationships while contributing to TrustedSec’s growing body of security knowledge.

Requirements

The candidate must be legally authorized to work in the United States. TrustedSec cannot provide sponsorship or consider applicants located outside the United States. 

This is a remote position, allowing employees to work from their home residence within the United States. Travel to client sites or industry-related events is required.

Duties/Responsibilities:  

  • Conduct high-quality hardware security assessments with limited direct supervision
  • Produce clear, technically accurate reports with testing walkthroughs, findings, and actionable recommendations for both technical and executive audiences
  • Conduct client meetings, serve as the primary point of contact, and interface directly with clients during engagements
  • Serve as a subject matter expert for other consultants/teams and regularly collaborate and contribute to furthering the education and progression of the skills and success of everyone at TrustedSec
  • Maintain and build upon cybersecurity knowledge and skills by attending educational workshops and adopting a curious, continuous learning mindset
  • Review publications, write blog posts, and potentially speak at conferences or other events

Minimum Requirements:

  • 2+ years' recent experience performing hardware security assessments
  • 2+ years' recent experience testing web applications and APIs
  • Experience identifying and interfacing with debug interfaces such as JTAG, SWD, and UART, including locating undocumented test points
  • Experience with firmware extraction and firmware analysis, including extraction via debug interfaces, chip-off, or vendor update files
  • Proficiency with Ghidra, Binary Ninja or equivalent for firmware reverse engineering
  • Experience assessing Wi-Fi and Bluetooth communications, including traffic flows between devices and mobile applications 
  • Proficiency in Burp Suite, or other intercepting proxy, for intercepting and analyzing web and mobile application traffic, and familiarity with Wireshark for non-HTTP network traffic
  • Experience escaping restricted environments on self-service terminals
  • Knowledge of manual application security testing, penetration testing methodologies, the OWASP Top 10, and the OWASP Testing Guide 
  • Strong understanding of common security controls and vulnerability testing techniques
  • Good time management skills and the ability to meet strict deadlines
  • Demonstrated analytical and project management skills
  • Excellent verbal and written communication skills including active listening and competence in presenting findings and recommendations to audiences with a range of technical understanding
  • Ability to write technical documents with correct spelling, grammar, and punctuation and the ability to distill information for non-echnical readers
  • Thrive in a fast-paced, collaborative environment
  • Ability to take initiative and work independently

Desired Skills/Education/Experience:

  • Experience assessing cellular-connected devices, including AT command interaction, SIM extraction, and IMEI spoofing
  • Ability to write scripts to support testing and tooling development
  • Familiarity with AI/LLMs/frontier models/agentic tools/coding assistants
  • Experience in mobile application testing
  • Prior consulting experience
  • Industry-recognized security certification(s) such as OSCP, Burp Suite Certified Practitioner, OSWE, etc.

Physical Requirements:

  • Prolonged periods of sitting at a desk and working on a computer
  • Ability to lift 50 pounds occasionally, including transport of testing equipment to/from client sites
  • Travel up to 25% over the course of the calendar year, including onsite client engagements
  • Must reside in the United States

Salary Description:

Base compensation typically ranges from $80,000 - $150,000 and is determined by multiple factors such as geographic location, relevant experience, and demonstrated skills. In addition to base pay, we offer a generous paid time off allowance, paid holidays, and a performance pay bonus program.

Learn more about TrustedSec here!

Skills Required

  • Legally authorized to work in the United States
  • Must reside in the United States
  • At least 2 years of recent experience performing hardware security assessments
  • At least 2 years of recent experience testing web applications and APIs
  • Experience identifying and interfacing with JTAG, SWD, UART, and undocumented test points
  • Experience with firmware extraction and firmware analysis through debug interfaces, chip-off, or vendor update files
  • Proficiency with Ghidra, Binary Ninja, or an equivalent firmware reverse-engineering tool
  • Experience assessing Wi-Fi and Bluetooth communications and device-to-mobile-application traffic
  • Proficiency with Burp Suite or another intercepting proxy
  • Familiarity with Wireshark for non-HTTP network traffic
  • Experience escaping restricted environments on self-service terminals
  • Knowledge of manual application security testing, penetration testing methodologies, the OWASP Top 10, and the OWASP Testing Guide
  • Strong understanding of common security controls and vulnerability testing techniques
  • Good time management and ability to meet strict deadlines
  • Demonstrated analytical and project management skills
  • Excellent verbal and written communication skills, including presenting findings to audiences with varied technical understanding
  • Ability to write technically accurate documents and explain findings to nontechnical readers
  • Ability to work collaboratively in a fast-paced environment
  • Ability to take initiative and work independently
  • Ability to lift 50 pounds occasionally
  • Experience assessing cellular-connected devices, including AT commands, SIM extraction, and IMEI spoofing
  • Ability to write scripts for testing and tooling development
  • Familiarity with AI, LLMs, frontier models, agentic tools, or coding assistants
  • Experience in mobile application testing
  • Prior consulting experience
  • Industry-recognized security certifications such as OSCP, Burp Suite Certified Practitioner, or OSWE
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Fairlawn, OH
107 Employees
Year Founded: 2012

What We Do

TrustedSec is an information security consulting team at the forefront of attack simulations with a focus on strategic risk-management. Our goal is to help organizations defend against threats of all kinds and change the security industry for the better. With a team handpicked not only for expertise and technical skill, but for ethical character and dedication, TrustedSec is committed to increasing the security posture of organizations around the world. TrustedSec is an ally to any organization working to develop and improve their security program.

Similar Jobs

Hybrid
Columbus, OH, USA
289097 Employees

PNC Bank Logo PNC Bank

Security Specialist - Workforce Identity Governance and Administration (IGA)

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees

Federal Reserve Bank of Boston Logo Federal Reserve Bank of Boston

Solutions Engineer

Fintech • Information Technology • Payments • Sharing Economy • Financial Services • Cryptocurrency
In-Office
11 Locations
1200 Employees
95K-154K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Underwriting Internship Program - Commercial Lines - Summer 2027

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Hybrid
8 Locations
40000 Employees
25K-27K Hourly

Similar Companies Hiring

Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account