Embedded IoT Security Penetration Specialist

Spyro Soft

United States

Remote

USD 110,000 - 170,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Spyro Soft is looking for a Penetration Tester with deep expertise in embedded systems and IoT security to identify and exploit weaknesses across diverse environments. The role demands strong analytical skills and the ability to translate findings into actionable guidance for stakeholders.

You will design secure architectures for embedded and cloud-connected devices, conduct threat modeling, perform penetration and fuzz testing on interfaces like JTAG, UART, SPI and I²C, and help integrate

Qualifications

  • Proven experience in embedded systems, IoT security, or product cybersecurity.
  • Hands-on knowledge of secure boot, firmware protection, code signing, and secure update mechanisms.
  • Good understanding of cryptography and key management in embedded environments.
  • Experience securing communication protocols and network interfaces in connected devices.
  • Knowledge of IoT authentication, authorization, and cloud security architectures.
  • Experience with threat modeling methodologies such as STRIDE, DREAD, and Attack Trees.
  • Ability to perform security risk assessments aligned with: ISO 21434, IEC 62443, ISO 27005.
  • Understanding of common embedded attack vectors: side-channel attacks, fault injection, firmware tampering, replay attacks, MITM attacks.
  • Experience conducting penetration testing on embedded targets using interfaces such as JTAG, UART, SPI, and I²C.
  • Experience with fuzz testing communication stacks (CAN, TCP/IP, MQTT).
  • Understanding of secure SDLC principles, DevSecOps, and cybersecurity lifecycle management.
  • Knowledge of vulnerability management, system hardening, and threat surface reduction strategies.
  • Understanding of GDPR, HIPAA, and data protection requirements for cloud-connected solutions.

Responsibilities

  • Design and implement security architectures for embedded and IoT solutions.
  • Define and maintain secure boot, firmware integrity, code signing, and OTA update strategies.
  • Establish secure device provisioning, onboarding, and lifecycle management processes.
  • Conduct threat modeling, security risk assessments, and security reviews throughout the product lifecycle.
  • Assess and mitigate vulnerabilities across embedded devices, cloud platforms, and communication interfaces.
  • Perform penetration testing, fuzz testing, and vulnerability assessments on embedded targets and IoT ecosystems.
  • Drive secure coding practices and perform security-focused code reviews.
  • Collaborate with development, platform, and cloud teams to integrate security into CI/CD pipelines and development processes.
  • Ensure compliance with applicable cybersecurity standards and regulatory requirements.
  • Support incident response activities, vulnerability remediation, and continuous security improvement initiatives.
  • Manage SBOM creation, maintenance, and software supply chain security activities.

Skills

Embedded security
IoT security
Threat modeling
Penetration testing
Secure coding
Code signing
CI/CD security
Data protection
Vulnerability assessment

Tools

JTAG
UART
SPI
I2C

Job description

Spyro Soft is looking for a Penetration Tester with deep expertise in embedded systems and IoT security to identify and exploit weaknesses across diverse environments. The role demands strong analytical skills and the ability to translate findings into actionable guidance for stakeholders.

You will design secure architectures for embedded and cloud-connected devices, conduct threat modeling, perform penetration and fuzz testing on interfaces like JTAG, UART, SPI and I²C, and help integrate

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Embedded Penetration Tester — Secure IoT Devices
Embedded Penetration Tester — Secure IoT Devices

TP-Link • Irvine (CA)

On-site
USD 80,000 - 132,000
Medical, dental, and vision insurance
401k contributions
Paid vacation and holidays
Senior Hardware & Embedded Security Penetration Tester
Senior Hardware & Embedded Security Penetration Tester

NetSPI LLC • United States

On-site
USD 180,000 - 230,000
Remote Hardware Security Tester — Embedded & IoT
Remote Hardware Security Tester — Embedded & IoT

Cybersecurity Jobs • Miami (FL)

Remote
USD 80,000 - 120,000
Flexible work environment
Remote within TX/FL
Education reimbursement
+2
Remote Hardware Pen Tester — Embedded & IoT
Remote Hardware Pen Tester — Embedded & IoT

Cybersecurity Jobs • Town of Texas (WI), Town of Florida (NY)

Remote
USD 80,000 - 120,000
Security training
Mentorship
Development reimbursement
+4
Security Consultant II (Mobile Application Penetration Tester)
Security Consultant II (Mobile Application Penetration Tester)

NetSPI • Minneapolis (MN)

On-site
USD 90,000 - 130,000
Security Consultant II (Mobile Application Penetration Tester)
Security Consultant II (Mobile Application Penetration Tester)

NetSPI • United States

On-site
USD 80,000 - 110,000
Principal Security Consultant (Hardware/Embedded Penetration Tester)
Principal Security Consultant (Hardware/Embedded Penetration Tester)

NetSPI • Minneapolis (MN)

On-site
USD 100,000 - 130,000
Hybrid Penetration Tester - Hardware & IoT Security Expert
Hybrid Penetration Tester - Hardware & IoT Security Expert

Dark Wolf • Colorado Springs (CO)

Hybrid
USD 130,000 - 145,000
IoT Software Security Engineer — SDLC & PenTest
IoT Software Security Engineer — SDLC & PenTest

Itron • United States

Hybrid
USD 44,000 - 67,000
R&D center in Budapest
Security Consultant II (Mobile Application Penetration Tester)
Security Consultant II (Mobile Application Penetration Tester)

NetSPI • United States

On-site
USD 85,000 - 110,000