Embedded Penetration Tester

Spyro Soft

Wrocław

On-site

PLN 180,000 - 240,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Spyro Soft in Wrocław is seeking a Penetration Tester with proven track record in embedded systems security and IoT. You will design security architectures, perform threat modeling, run penetration tests on embedded devices, and collaborate with cloud teams to secure CI/CD.

Strong communication skills are essential to translate findings into actionable recommendations for stakeholders, with experience in standards such as ISO 21434, IEC 62443, and GDPR compliance.

Qualifications

  • Strong experience in embedded systems, IoT security, or product cybersecurity.
  • Hands-on knowledge of secure boot, firmware protection, code signing, and secure update mechanisms.
  • Deep understanding of cryptography and key management in embedded environments.
  • Experience securing communication protocols and network interfaces in connected devices.
  • Knowledge of IoT authentication, authorization, and cloud security architectures.
  • Experience with threat modeling methodologies such as STRIDE, DREAD, and Attack Trees.
  • Ability to perform security risk assessments aligned with ISO 21434, IEC 62443, ISO 2705.
  • Understanding of common embedded attack vectors: side-channel attacks, fault injection, firmware tampering, replay attacks, MITM attacks.
  • Experience conducting penetration testing on embedded targets using interfaces such as JTAG, UART, SPI, and I²C.
  • Experience with fuzz testing communication stacks (CAN, TCP/IP, MQTT).
  • Understanding of secure SDLC principles, DevSecOps, and cybersecurity lifecycle management.
  • Knowledge of vulnerability management, system hardening, and threat surface reduction strategies.
  • Understanding of GDPR, HIPAA, and data protection requirements for cloud-connected solutions.

Responsibilities

  • Design and implement security architectures for embedded and IoT solutions.
  • Define and maintain secure boot, firmware integrity, code signing, and OTA update strategies.
  • Establish secure device provisioning, onboarding, and lifecycle management processes.
  • Conduct threat modeling, security risk assessments, and security reviews throughout the product lifecycle.
  • Assess and mitigate vulnerabilities across embedded devices, cloud platforms, and communication interfaces.
  • Perform penetration testing, fuzz testing, and vulnerability assessments on embedded targets and IoT ecosystems.
  • Drive secure coding practices and perform security-focused code reviews.
  • Collaborate with development, platform, and cloud teams to integrate security into CI/CD pipelines and development processes.
  • Ensure compliance with applicable cybersecurity standards and regulatory requirements.
  • Support incident response activities, vulnerability remediation, and continuous security improvement initiatives.
  • Manage SBOM creation, maintenance, and software supply chain security activities.

Skills

Embedded systems security
IoT security
Threat modeling
Secure coding & DevSecOps
Penetration testing
Code signing & OTA updates
Cloud security architectures
ISO 21434 / IEC 62443 knowledge

Tools

JTAG
UART
SPI
I²C
CAN
Fuzz testing
TLS/DTLS
MQTT

Job description

Tech stack:
  • Secure boot, firmware security, OTA updates.
  • Cryptography (AES, RSA, ECC) & hardware security (TPM, HSM, TrustZone).
  • Embedded interfaces & protocols: CAN, LIN, Modbus, BLE, Wi-Fi, TCP/IP.
  • Penetration testing on embedded targets: JTAG, UART, SPI, I²C.
  • Cloud IoT platforms & secure communication: AWS/Azure/GCP IoT, TLS/DTLS, MQTT(S).
  • Secure code review (C/C++, Rust, Python) & DevSecOps / CI/CD security.
Requirements:
  • Strong experience in embedded systems, IoT security, or product cybersecurity.
  • Hands-on knowledge of secure boot, firmware protection, code signing, and secure update mechanisms.
  • Deep understanding of cryptography and key management in embedded environments.
  • Experience securing communication protocols and network interfaces in connected devices.
  • Knowledge of IoT authentication, authorization, and cloud security architectures.
  • Experience with threat modeling methodologies such as STRIDE, DREAD, and Attack Trees.
  • Ability to perform security risk assessments aligned with: ISO 21434, IEC 62443, ISO 2705.
  • Understanding of common embedded attack vectors: side-channel attacks, fault injection, firmware tampering, replay attacks, MITM attacks.
  • Experience conducting penetration testing on embedded targets using interfaces such as JTAG, UART, SPI, and I²C.
  • Experience with fuzz testing communication stacks (CAN, TCP/IP, MQTT).
  • Understanding of secure SDLC principles, DevSecOps, and cybersecurity lifecycle management.
  • Knowledge of vulnerability management, system hardening, and threat surface reduction strategies.
  • Understanding of GDPR, HIPAA, and data protection requirements for cloud-connected solutions.
Nice to have:
  • Experience in regulated industries such as Automotive, Industrial Automation, Medical Devices.
  • Familiarity with: IEC 62304, ISO 27001, NIST Cybersecurity Framework, NIST 8259 (IoT Device Cybersecurity).
  • Professional security certifications such as: OSCP, GPEN, CompTIA PenTest.
  • Experience working with Rust-based secure embedded applications.
  • Experience in using AI tools in day-to-day workflow.
Project description:

We're looking for a Penetration Tester with a proven track record of successfully identifying and exploiting security weaknesses across a wide range of systems and environments. The ideal candidate will have deep expertise in advanced penetration testing methodologies, tools, and reporting, with strong analytical and problem-solving skills. Experience in embedded systems security is highly desirable and will be considered a significant advantage. This role requires excellent communication skills to translate technical findings into clear, actionable recommendations for stakeholders.

Main responsibilities:
  • Design and implement security architectures for embedded and IoT solutions.
  • Define and maintain secure boot, firmware integrity, code signing, and OTA update strategies.
  • Establish secure device provisioning, onboarding, and lifecycle management processes.
  • Conduct threat modeling, security risk assessments, and security reviews throughout the product lifecycle.
  • Assess and mitigate vulnerabilities across embedded devices, cloud platforms, and communication interfaces.
  • Perform penetration testing, fuzz testing, and vulnerability assessments on embedded targets and IoT ecosystems.
  • Drive secure coding practices and perform security-focused code reviews.
  • Collaborate with development, platform, and cloud teams to integrate security into CI/CD pipelines and development processes.
  • Ensure compliance with applicable cybersecurity standards and regulatory requirements.
  • Support incident response activities, vulnerability remediation, and continuous security improvement initiatives.
  • Manage SBOM creation, maintenance, and software supply chain security activities.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Embedded Penetration Tester
Embedded Penetration Tester

Talanto • Wrocław

Hybrid
PLN 232,000 - 290,000
Embedded Penetration Tester — IoT & Firmware Security
Embedded Penetration Tester — IoT & Firmware Security

Talanto • Wrocław

Hybrid
PLN 232,000 - 290,000
Senior Pentester (Security Engineer)
Senior Pentester (Security Engineer)

DEVTALENTS Sp. z o.o. • Województwo mazowieckie

On-site
PLN 80,000 - 100,000
Influence over security architecture
Supportive culture for professional growth
Senior Embedded IoT Security Penetration Tester
Senior Embedded IoT Security Penetration Tester

Spyro Soft • Wrocław

On-site
PLN 180,000 - 240,000
Penetration Tester Team Lead
Penetration Tester Team Lead

Terra Security • Poland

On-site
PLN 297,000 - 384,000
Penetration Tester
Penetration Tester

Atos • Bydgoszcz

Hybrid
PLN 120,000 - 170,000
Hybrid work model
Private medical care
Benefits platform
+4
Principal Penetration Tester - Mobile Application (f/m/x)
Principal Penetration Tester - Mobile Application (f/m/x)

Sii Polska • Poland

Hybrid
PLN 240,000 - 420,000
Product Principal Penetration Tester
Product Principal Penetration Tester

Hitachi Energy • Kraków

On-site
PLN 120,000 - 180,000
Product Security Test Engineer
Product Security Test Engineer

Seargin • Katowice

On-site
PLN 120,000 - 180,000
MultiSport
Private Medical Care
Staff Product Security Engineer
Staff Product Security Engineer

Renesas Electronics • Poland

On-site
PLN 297,000 - 383,000
Diversity & Inclusion Statement