Embedded Security Testing

Cyient

Bengaluru

On-site

INR 3,500,000 - 6,500,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Cyient seeks an experienced Penetration Tester - Leader to perform offensive security testing on embedded devices, network IT/OT infrastructure, and backend/cloud apps. The role emphasizes manual and automated testing, reverse engineering, and industry-standard cybersecurity practices.

The candidate will conduct threat analysis, test on embedded/IoT and cloud platforms, and document findings with clear remediation guidance, collaborating with cross-functional teams to validate fixes.

Qualifications

  • Strong hands-on experience in penetration testing methodologies.
  • Reverse engineering of embedded firmware (ARM, PowerPC, TriCore, etc.).
  • Familiarity with secure boot, bootloaders and firmware update mechanisms.
  • Ability to identify, document, and remediate vulnerabilities with clear guidance.
  • Knowledge of secure coding flaws and best practices.

Responsibilities

  • Perform threat analysis and risk assessment for embedded devices and IT/OT networks.
  • Conduct security assessments on embedded/IoT devices, cloud/web apps, and IT/OT infrastructure.
  • Perform firmware extraction, analysis, and reverse engineering.
  • Document vulnerabilities with risk ratings and remediation steps.
  • Collaborate with development teams to validate fixes and retest.
  • Prepare penetration test reports for customers and internal stakeholders.

Skills

Penetration testing
Threat analysis
Reverse engineering
Security testing
Documentation
Attacker mindset
Problem solving

Tools

Burp Suite
Metasploit
Nmap
Wireshark
Ghidra
IDA Pro

Job description

Embedded + Security:
Job Description:

We are seeking an experienced Penetration Tester - Leader to perform offensive security testing on embedded devices (automotive or medical device or Iot) , network devices, network IT/OT infrastructure & backend/cloud applications. The role involves identifying security vulnerabilities through manual and automated penetration testing, reverse engineering in compliance with industry-specific cybersecurity standards (Automotive, Healthcare, OT, IT) and project requirements.

Key Responsibilities:
  1. Perform Threat analysis and risk assessment
  2. Conduct security assessments on:
    1. Embedded/ IOT devices
    2. Cloud/Web apps
    3. IT/OT infrastructure
    4. Android & iOS apps
  3. Perform firmware extraction, analysis, and reverse engineering
  4. Identify, exploit, and document vulnerabilities with clear risk and remediation guidance
  5. Collaborate with development and system teams to validate fixes and retest vulnerabilities
  6. Prepare penetration test reports for customers and internal stakeholders
  7. Knowledge of secure coding flaws
Technical Skills:
  1. Strong hands-on experience in penetration testing methodologies
  2. Proficiency with Kali Linux and Linux-based testing environments
  3. Hands-on usage of tools such as:
    1. Burp Suite
    2. Metasploit
    3. Nmap
    4. Wireshark
    5. Ghidra / IDA Pro
  4. Experience in reverse engineering of embedded firmware (ARM, PowerPC, TriCore, etc.)
  5. Familiarity with bootloaders, secure boot, and firmware update mechanisms
  6. Understanding of hardware attack surfaces and mitigation techniques
Tools & Platforms:
  1. Kali Linux, Ubuntu, embedded Linux
  2. Burp Suite, Wireshark, Nmap, Metasploit
  3. Ghidra, IDA Pro, Binwalk
  4. Python / Bash scripting for automation (preferred)
Certifications (Preferred):

Demonstrate strong offensive security capabilities supported by industryrecognized certifications and verifiable achievements, including:

  1. Proven presence in leading Security Hall of Fame / Acknowledgment Lists from global technology vendors (e.g. Bugcrowd, HackerOne).
  2. Preferred certifications are
    1. CREST Certified Tester (CCT / CRT / CCT-INF)
    2. OSCP / OSWE / GWAPT
    3. Offensive Security or INE/eLearnSecurity certifications, such as: OSEP, ejpt, eCPPT, eWPT/eWPTX, eCPTX
  3. Documented contribution to the cybersecurity community through published CVEs listed under the candidates name. Participation in responsible disclosure programs with publicly available acknowledgements or awards.
  4. Demonstrated excellence through participation in national and international cybersecurity hackathons and completion of advanced CTF challenges. Achieved toptier rankings on offensivetraining platforms such as Hack The Box, TryHackMe, and other similar competitive environments.
  5. Strong portfolio of security research, exploit development, vulnerability analysis, or open-source security tool contributions.
Standards & Framework Awareness:
  1. OWASP Testing Methodology
  2. Familiarity with Threat Analysis and Risk Assessment and threat-based testing
Behavioral & Professional Skills:
  1. Strong analytical and problem-solving skills
  2. Ability to think like an attacker and communicate risk clearly
  3. Excellent technical documentation and reporting skills
  4. Comfortable with customer-facing discussions and technical reviews
  5. Ability to work independently and in cross-functional teams Under direct supervision, performs maintenance on existing software products for customers. Assists in coding, testing, and debugging new software or making enhancements to existing software for customers. Writes programs according to specifications from higher level staff or business analysts. May use CASE tools. Makes suggestions for problem solutions or software enhancements. May assist in development of user manuals. Works with technical staff to learn and understand problems with software. Note: If the incumbent is responsible for the development of software for internal use, please match to a position in the Application Development sub-family grouping.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Test Engineer
Security Test Engineer

Cyient • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Application and Product Security I Analyst III (Pen Tester)
Application and Product Security I Analyst III (Pen Tester)

Vertiv Co • Pune District

On-site
INR 2,500,000 - 4,200,000
Automotive/Embedded Penetration Tester (Cybersecurity V&V)
Automotive/Embedded Penetration Tester (Cybersecurity V&V)

Acesoft Labs • Bengaluru

Hybrid
INR 1,500,000 - 2,300,000
Software Engineer
Software Engineer

Cloudxtreme • Bengaluru, Hyderabad

On-site
INR 900,000 - 1,500,000
Application and Product Security I Analyst I
Application and Product Security I Analyst I

Vertiv Co • Pune District

On-site
INR 1,000,000 - 1,800,000
Senior Security Engineer - IOT
Senior Security Engineer - IOT

Arrow Electronics • Ahmedabad District

On-site
INR 1,200,000 - 1,800,000
Competitive salary
Career growth opportunities
Work-life balance
Embedded system enginner / ECU Testing
Embedded system enginner / ECU Testing

Acesoft Labs • Bengaluru

On-site
INR 2,500,000 - 4,200,000
Penetration Tester (ME)
Penetration Tester (ME)

BreachLock, Inc. • Dadri

On-site
INR 1,200,000 - 2,400,000
Private Health Insurance
Penetration Tester ME
Penetration Tester ME

BreachLock, Inc. • Dadri

On-site
INR 900,000 - 1,500,000
Private Health Insurance
Application Security Consultant
Application Security Consultant

Securityboat • Mumbai

On-site
INR 1,200,000 - 2,000,000
Flexible engagements
Competitive compensation
Collaborative cybersecurity team
+1