Embedded Penetration Tester

Talanto

Wrocław

Hybrid

PLN 232,000 - 290,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Talanto is seeking a skilled Penetration Tester with a focus on embedded and IoT security. You will design secure architectures, enforce secure boot and OTA updates, and perform threat modeling and vulnerability assessments across devices and cloud interfaces.

You will collaborate with cross‑functional teams to integrate security into CI/CD, ensure regulatory compliance, and drive lifecycle security improvements across the product stack.

Qualifications

  • Strong experience in embedded systems, IoT security, or product cybersecurity.
  • Hands‑on knowledge of secure boot, firmware protection, code signing, and OTA updates.
  • Deep understanding of cryptography and key management in embedded environments.
  • Experience securing communication protocols and network interfaces in connected devices.
  • Knowledge of IoT authentication, authorization, and cloud security architectures.
  • Experience with threat modeling methodologies such as STRIDE, DREAD, and Attack Trees.

Responsibilities

  • Design and implement security architectures for embedded and IoT solutions.
  • Define and maintain secure boot, firmware integrity, code signing, and OTA update strategies.
  • Establish secure device provisioning, onboarding, and lifecycle management processes.
  • Conduct threat modeling, security risk assessments and security reviews throughout the product lifecycle.
  • Assess and mitigate vulnerabilities across embedded devices, cloud platforms, and communication interfaces.
  • Perform penetration testing, fuzz testing, and vulnerability assessments on embedded targets and IoT ecosystems.
  • Drive secure coding practices and perform security‑focused code reviews.
  • Collaborate with development, platform, and cloud teams to integrate security into CI/CD pipelines and development processes.
  • Ensure compliance with applicable cybersecurity standards and regulatory requirements.
  • Support incident response activities, vulnerability remediation, and continuous security improvement initiatives.
  • Manage SBOM creation, maintenance, and software supply chain security activities.

Skills

Embedded security
IoT security
Penetration testing
Threat modeling
Secure coding

Tools

JTAG
UART
SPI
I2C

Job description

20,800 – 26,000 PLN

Important: if an employer asks you to log into their system via iCloud or Google, send a code, an SMS or Telegram password, run some code, or install software — refuse. These are signs of fraud.

Secure boot, firmware security, OTA updates.

Cryptography (AES, RSA, ECC) & hardware security (TPM, HSM, TrustZone).

Embedded interfaces & protocols: CAN, LIN, Modbus, BLE, Wi-Fi, TCP/IP.

Penetration testing on embedded targets: JTAG, UART, SPI, I²C.

Secure code review (C/C++, Rust, Python) & DevSecOps / CI/CD security.

Requirements:

Strong experience in embedded systems, IoT security, or product cybersecurity.

Hands‑on knowledge of secure boot, firmware protection, code signing, and secure update mechanisms.

Deep understanding of cryptography and key management in embedded environments.

Experience securing communication protocols and network interfaces in connected devices.

Knowledge of IoT authentication, authorization, and cloud security architectures.

Experience with threat modeling methodologies such as STRIDE, DREAD, and Attack Trees.

Ability to perform security risk assessments aligned with: ISO 21434, IEC 62443, ISO 27005.

Understanding of common embedded attack vectors: side‑channel attacks, fault injection, firmware tampering, replay attacks, MITM attacks.

Experience conducting penetration testing on embedded targets using interfaces such as JTAG, UART, SPI, and I²C.

Experience with fuzz testing communication stacks (CAN, TCP/IP, MQTT).

Understanding of secure SDLC principles, DevSecOps, and cybersecurity lifecycle management.

Knowledge of vulnerability management, system hardening, and threat surface reduction strategies.

Understanding of GDPR, HIPAA, and data protection requirements for cloud‑connected solutions.

Nice to have:

Experience in regulated industries such as Automotive, Industrial Automation, Medical Devices.

Familiarity with: IEC 62304, ISO 27001, NIST Cybersecurity Framework, NIST 8259 (IoT Device Cybersecurity).

Professional security certifications such as: OSCP, GPEN, CompTIA PenTest.

Experience working with Rust‑based secure embedded applications.

Experience in using AI tools in day‑to‑day workflow.

We're looking for a Penetration Tester with a proven track record of successfully identifying and exploiting security weaknesses across a wide range of systems and environments. The ideal candidate will have deep expertise in advanced penetration testing methodologies, tools, and reporting, with strong analytical and problem‑solving skills. Experience in embedded systems security is highly desirable and will be considered a significant advantage. This role requires excellent communication skills to translate technical findings into clear, actionable recommendations for stakeholders.

Main responsibilities:

Design and implement security architectures for embedded and IoT solutions.

Define and maintain secure boot, firmware integrity, code signing, and OTA update strategies.

Establish secure device provisioning, onboarding, and lifecycle management processes.

Conduct threat modeling, security risk assessments and security reviews throughout the product lifecycle.

Assess and mitigate vulnerabilities across embedded devices, cloud platforms, and communication interfaces.

Perform penetration testing, fuzz testing, and vulnerability assessments on embedded targets and IoT ecosystems.

Drive secure coding practices and perform security‑focused code reviews.

Collaborate with development, platform, and cloud teams to integrate security into CI/CD pipelines and development processes.

Ensure compliance with applicable cybersecurity standards and regulatory requirements.

Support incident response activities, vulnerability remediation, and continuous security improvement initiatives.

Manage SBOM creation, maintenance, and software supply chain security activities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Embedded Penetration Tester
Embedded Penetration Tester

Spyro Soft • Wrocław

On-site
PLN 180,000 - 240,000
Senior Embedded IoT Security Penetration Tester
Senior Embedded IoT Security Penetration Tester

Spyro Soft • Wrocław

On-site
PLN 180,000 - 240,000
Embedded Penetration Tester — IoT & Firmware Security
Embedded Penetration Tester — IoT & Firmware Security

Talanto • Wrocław

Hybrid
PLN 232,000 - 290,000
Senior Pentester (Security Engineer)
Senior Pentester (Security Engineer)

DEVTALENTS Sp. z o.o. • Województwo mazowieckie

On-site
PLN 80,000 - 100,000
Influence over security architecture
Supportive culture for professional growth
Principal Penetration Tester - Mobile Application (f/m/x)
Principal Penetration Tester - Mobile Application (f/m/x)

Sii Polska • Poland

Hybrid
PLN 240,000 - 420,000
Lead Security Testing Engineer
Lead Security Testing Engineer

EPAM Systems • Łódź

Hybrid
PLN 180,000 - 280,000
Hybrid work model
Relocation opportunities
Employee stock purchase plan
+5
Ethical Hacker/Pentester
Ethical Hacker/Pentester

your Jared • Kraków

Hybrid
PLN 120,000 - 180,000
Private medical care package
MultiSport card
Flexible working hours
Product Security Test Engineer – Firmware & Protocols
Product Security Test Engineer – Firmware & Protocols

Seargin • Katowice

On-site
PLN 120,000 - 180,000
MultiSport
Private Medical Care
С & C++ Embedded Engineer
С & C++ Embedded Engineer

SQUAD Ukraine Limited • Wrocław

On-site
PLN 70,000 - 100,000
Competitive salary packages
Performance and Loyalty Bonuses
Paid vacation and medical leaves
+2
Cybersecurity Senior Consultant - Senior Pentester
Cybersecurity Senior Consultant - Senior Pentester

EY • Katowice

Hybrid
PLN 180,000 - 280,000