Wireless Security Research Engineer

Stealth

København

On-site

DKK 900,000 - 1,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Stealth is building resilient wireless infrastructure for constrained IoT and edge devices. The role spans offensive research and defensive engineering, working across low-power radio stacks like mioty and LoRa-class systems to break deployments and harden them.

You will threat-model, reverse-engineer, and build PoCs for attacks in authorized labs, then collaborate to ship mitigations that balance power, latency, and cost. Strong embedded, cryptography, and firmware skills are essential.

Qualifications

  • Experience designing secure, robust firmware architectures balancing security with constraints.
  • Hands-on analysis or attack experience on wireless/IoT protocols beyond basic pentesting.
  • Ability to read RF/protocol docs and extract findings from captures when docs are incomplete.
  • Proficiency in embedded systems including C/C++ and hardware debugging.
  • Strong cryptography foundations for constrained devices and production use.
  • Proven track record of identifying weaknesses and proposing actionable fixes.

Responsibilities

  • Threat-model IoT radio systems end-to-end from PHY to application.
  • Reverse-engineer firmware, configurations, and packet formats to uncover undocumented behaviors.
  • Build PoCs for jamming, spoofing, replay, desync, and side-channel attacks in authorized labs.
  • Assess gateways, pairing flows, and backend trust assumptions.
  • Propose and implement protocol mitigations including auth, anti-replay, and key rotation.
  • Design resilient architectures with graceful degradation and hostile RF detection.
  • Collaborate with firmware/backend teams to ship defenses respecting power, latency, and cost.
  • Mentor team on attacker mindset to improve system design and security posture.

Skills

Embedded systems
Cryptography fundamentals
C/C++
Reverse engineering
Wireless protocols
Threat modeling
Documentation

Tools

JTAG/SWD debugging
Logic analyzers
GNU Radio

Job description

About the role

We are building resilient, adversarial-ready wireless infrastructure for constrained IoT and edge devices. This role sits at the intersection of offensive research and defensive engineering. You will operate across low-power, long-range radio stacks—such as mioty, LoRa-class systems, and other proprietary LPWAN variants—to break real-world deployments and subsequently harden them. We are looking for an individual who can comfortably live on both sides of the fence: identifying vulnerabilities through authorized research and implementing concrete, shippable mitigations.

What you’ll do
  • Threat-model IoT radio systems across the entire stack, from PHY to MAC to application.
  • Reverse-engineer firmware, radio configurations, and packet formats to identify undocumented behaviors.
  • Build Proof-of-Concepts for jamming, spoofing, replay, desync, and side-channel style attacks in authorized lab environments.
  • Assess gateways, endpoints, pairing/join flows, and backend trust assumptions.
  • Propose and implement protocol-level mitigations including authentication, anti-replay, key rotation, and diversity strategies.
  • Design resilient architectures capable of graceful degradation, hostile RF detection, and multi-path fallbacks.
  • Collaborate with firmware and backend teams to ship defenses that respect real-world constraints such as power, latency, and cost.
  • Mentor the team on the attacker mindset to elevate overall system design and security posture.
What we’re looking for
Must-have
  • Experience building and designing custom communication protocols or robust firmware architectures, balancing security with functional constraints.
  • Hands‑on experience attacking or deeply analyzing wireless/IoT protocols (beyond standard web/app pentesting).
  • Ability to read RF/protocol documentation and synthesize findings from packet captures when documentation is incomplete.
  • Proficiency in embedded systems including C/C++, firmware debugging, and hardware analysis (serial/JTAG/SWD, logic analyzers).
  • Strong cryptography foundations specific to constrained devices and the realities of production implementation.
  • Proven track record of both finding security weaknesses and proposing actionable engineering fixes.
  • Clear written communication skills for documenting attack paths, risk rankings, and engineering recommendations.
Nice-to-have
  • Experience shipping production firmware or radio-enabled products.
  • Red‑team or purple‑team experience with strong ethical and scoping discipline.
  • Familiarity with SDR platforms (GNU Radio, HackRF, etc.) and PHY‑level analysis (CSS, UNB, FHSS, Doppler/jamming effects).
  • Background in gateway and network‑server security (PKI, join servers, multi‑tenant backends).
  • Hardware security expertise, including bootloaders, secure elements, and side‑channel analysis.
How we work
  • All offensive research is strictly authorized, scoped, and documented.
  • We prioritize real‑world resilience under hostile network conditions over checkbox compliance.
  • We value creative solutions for imperfect radios and legacy constraints; we bridge the gap between "this breaks" and "here is the fix."

If you have ever identified a flaw in an LPWAN join flow, sketched out the attack, and designed a survival strategy, we want to talk. Please share a summary of a wireless or embedded system you broke, what you learned, and how you would rebuild.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Wireless Security Researcher: LPWAN Resilience & Offense
Wireless Security Researcher: LPWAN Resilience & Offense

Stealth • København

On-site
DKK 900,000 - 1,200,000
Applications Engineer I Silvus
Applications Engineer I Silvus

Motorola Solutions • København

On-site
DKK 480,000 - 600,000
RF Test Engineer
RF Test Engineer

Sivers Semiconductors UK • Sverige

On-site
DKK 410,000 - 560,000
Innovative projects in cutting-edge technologies
Collaborative global team environment
Hands-on exposure to testing processes
RF Sub System Architect
RF Sub System Architect

Weibel Scientific • Allerød Kommune

On-site
DKK 900,000 - 1,200,000
Senior Network & Security Engineer
Senior Network & Security Engineer

Veo • København

On-site
DKK 600,000 - 900,000
AI Red Team Specialist – Lead Researcher in Agentic Security
AI Red Team Specialist – Lead Researcher in Agentic Security

The Tech Collective • København

Hybrid
DKK 700,000 - 1,100,000
Remote work option
Senior Electronics Engineer
Senior Electronics Engineer

Arting Green • København

On-site
DKK 750,000 - 950,000
Staff Security Engineer
Staff Security Engineer

Veo Technologies • København

On-site
DKK 900,000 - 1,200,000
System Field Engineer, Falcom
System Field Engineer, Falcom

GN Store Nord A/S • Ballerup

On-site
DKK 55,000 - 70,000
Software Engineer
Software Engineer

Motorola Solutions • Glostrup Kommune

On-site
DKK 400,000 - 600,000
Opportunity to work on side projects
Innovative work culture