Hardware Security Consultant

Pen Test Partners

United Kingdom

Hybrid

GBP 50,000 - 70,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

24 development days per year
Paid training & exams
Private Medical Insurance
Access to internal workshops
25 days holiday + 8 bank holidays
Opportunity to buy and sell holiday
4 x salary life insurance

Job summary

A global cyber security consultancy is seeking a hardware security consultant to deliver diverse services, including hardware and pen testing. The role involves collaborating with experts and requires penetration testing skills, strong analytical abilities in network protocols, knowledge in reverse engineering, and scripting proficiency. Employees enjoy 25 days of holiday, private medical insurance, and professional development support, alongside flexible home-working arrangements. This position is based in the UK and involves onsite travel when necessary.

Qualifications

  • Ability to learn and adapt to new technologies.
  • Strong communication and collaboration skills are essential.
  • Experience in a relevant field, including embedded systems or hardware security.

Responsibilities

  • Deliver hardware security and pen testing services.
  • Contribute to research and internal tool development.
  • Upskill team members with your knowledge.

Skills

Pen testing skills in web application, API and mobile applications
Excellent ability to learn new technologies, systems, and languages
Keen interest in embedded systems, IoT and hardware
Demonstrated hardware security skills
Strong network protocol analysis
Understanding of reverse engineering
Ability to script in appropriate languages
Knowledge of ICS/OT architectures
Understanding of cryptography
Experience in analysing RF protocols
Threat modelling knowledge
Experience working in industrial or maritime environments

Tools

Wireshark
Ghidra

Job description

PTP works with clients globally providing cyber security consultancy and testing services. We work with the most cutting-edge industries, including consumer IoT, aerospace, maritime and autonomous vehicles.

We are seeking a hardware security consultant, who is eager to learn, to join our team. Working alongside some of the best hacking minds in the country you’ll be delivering a mixture of hardware and pen testing services to clients across all sectors.

You will need:

  • Pen testing skills in web application, API and mobile applications
  • Excellent ability to learn new technologies, systems, and languages
  • A keen interest in embedded systems, IoT and hardware
  • Demonstrated hardware security skills either in professional or hobbyist sphere
  • Strong network protocol analysis using tools such as Wireshark
  • An understanding of reverse engineering, experience using tools such as Ghidra, with particular focus on ARM and x86 architectures
  • Ability to script in appropriate languages to facilitate testing
  • Awareness of typical Industrial Control Systems (ICS)/Operational Technology (OT) architectures, components and protocols
  • An understanding of cryptography and common mistakes made
  • Experience in analysing RF protocols such as BLE, Zigbee, LoRa, Wi-Fi, and proprietary ISM band protocols.
  • Threat modelling knowledge, being able to determine which attacks and assets are highest risk for different classes of system.
  • Experience working in industrial or maritime environments, either as a pen tester, IT, or other role

We recognise that the tasks carried out by members of the hardware team are varied and challenging and we do not expect any member of the team to know everything. We operate as a team, providing advice, guidance and mentoring to each other.

You’ll be:

  • Reporting into the Head of Hardware delivering hardware, ICS/OT and pen testing services, from presales through to delivery and debrief
  • Contributing towards research and our development of internal tools and processes
  • Helping to upskill others into the hardware team

Here are some examples of the services you may provide to clients:

  • Penetration testing of a cloud-connected consumer IoT system including the device, messaging platforms, infrastructure, and mobile application
  • Producing a threat model for a complex system such as a crypto wallet, aiming to uncover inherent outstanding risks in the design and implementation
  • Reviewing custom cryptographic systems to identify common issues such as hardcoded keys, use of insecure block modes, unauthenticated encryption, and use of deprecated algorithms
  • Testing routers and other networking equipment before they are deployed across Critical National Infrastructure, to ensure that they are suitably protected from physical attack and contain no secrets that can impact the wider system
  • Performing lab-based testing of complex control systems used in Critical National Infrastructure, allowing more aggressive and invasive techniques to be used than in traditional ICS environments
  • Reverse engineering the protocol used in a legacy specialised machine tool to allow it to be serviceable long into the future
  • Attempting to bypass a custom digital rights management system to provide assurance that their product is adequately secure
  • Testing network segmentation and infrastructure on a variety of ships, including cruise ships and oil rigs
  • Working in ICS environments using a risk-averse methodology using document review, visual survey and low-risk techniques to find security issues

Knowledge development is part of our culture. We take professional development seriously and as member of the team you will receive:

  • 24 development days per year
  • Time to go to conferences
  • Access to Internal workshops, HTB, TryHackMe and many more resources
  • Paid training & exams
  • Access to our blog bounty programme

Although you’ll mostly work from home, we may ask you into the lab to work on pieces of hardware such as vehicles. Onsite travel to client sites (including international) will also be required for maritime, ICS and aerospace work. PTP are mindful that people have a life outside of work and onsite work is distributed across the team appropriately. Around 25% of your days will be onsite over a year.

Although we are a remote working company, our teams meet regularly throughout the year holding local and company meet ups.

As an employee you’ll also have access to:

  • 25 days holiday+ 8 bank holidays
  • An opportunity to buy and sell holiday each year
  • Private Medical Insurance and Healthcare Benefit
  • 4 x salary life insurance
  • Financing for training and conference attendance
  • An environment where you can flourish, learn, and grow, as a person not just as an employee

This is a UK role, so you must live and be eligible to work in the UK.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hardware & OT Security Consultant
Hardware & OT Security Consultant

Pen Test Partners • United Kingdom

Hybrid
GBP 55,000 - 90,000
24 development days per year
Conference attendance
Paid training and exams
+2
IT/OT Penetration Tester
IT/OT Penetration Tester

PA Consulting • City of Westminster

Hybrid
GBP 45,000 - 65,000
Health and lifestyle perks
25 days annual leave
Generous company pension scheme
+2
Hardware Security Engineer - Consultant
Hardware Security Engineer - Consultant

Awerian Ltd • Cambridge

On-site
GBP 70,000 - 100,000
Profit-related bonus
Private medical insurance
25 days holiday
+3
Hybrid IT & OT Security Penetration Tester
Hybrid IT & OT Security Penetration Tester

PA Consulting • City of Westminster

Hybrid
GBP 45,000 - 65,000
Health and lifestyle perks
25 days annual leave
Generous company pension scheme
+2
Pen Tester
Pen Tester

Pen Test Partners LLP • United Kingdom

On-site
GBP 40,000 - 60,000
Life insurance (4 x salary)
Buying & selling holiday
Working abroad opportunities
+2
Penetration Tester
Penetration Tester

Oscar • Bristol

On-site
GBP 60,000 - 80,000
Funded certifications
Access to modern tooling
Performance-based incentives
Penetration Tester (Web App)
Penetration Tester (Web App)

Bulletproof incorporated • United Kingdom

On-site
GBP 45,000 - 75,000
25 days annual holiday
Additional holiday for birthday
Company Pension contribution
+7
IT/OT Penetration Tester
IT/OT Penetration Tester

PA Consulting • Greater London

On-site
GBP 60,000 - 80,000
Health and lifestyle perks with private healthcare
25 days annual leave with the option to buy 5 additional days
Generous company pension scheme
+2
Penetration Tester
Penetration Tester

Hamilton Barnes ? • North East

Hybrid
GBP 55,000 - 75,000
25 days annual leave
Pension scheme
Death in service insurance
+1
Hardware Security Engineer - Consultant
Hardware Security Engineer - Consultant

Camwebdir • United Kingdom

Remote
GBP 65,000 - 90,000
Annual profit-related bonus
Virtual shares
Employer pension contribution
+6