Enable job alerts via email!

PRINCIPAL HARDWARE SECURITY CONSULTANT

Aon Hewitt

New York (NY)

On-site

USD 130,000 - 180,000

Full time

4 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading company is seeking a Principal Hardware Security Consultant to join their Proactive Security Testing team. This role involves conducting penetration testing, mentoring junior staff, and engaging in vulnerability research. The ideal candidate will have extensive experience in hardware security and firmware analysis, contributing to a supportive work environment focused on continuous learning and diversity.

Benefits

Wellbeing Days
Professional Growth Opportunities
Comprehensive Benefits Package

Qualifications

  • At least 5 years of hands-on hardware/product security testing experience.
  • Experience with reverse engineering hardware components and firmware analysis.

Responsibilities

  • Conduct penetration testing to evaluate product security.
  • Mentor junior engineers and assist in pre-sales activities.
  • Document technical issues and provide remediation recommendations.

Skills

Hardware Security Testing
Reverse Engineering
Vulnerability Research
Mentoring
Communication

Tools

Ghidra
IDA Pro
Python
Ruby

Job description

Aon is looking for a Principal Hardware Security Consultant

The Proactive Security Testing team seeks intelligent, energetic, and motivated professionals to join its ranks. We offer a challenging and dynamic environment that balances autonomy with senior-level support. Our team engages in publishing books and blogs, delivering conference talks, contributing to open-source projects, and pursuing ongoing security research.

Aon is in the business of better decisions.

At Aon, we aim to make better decisions to protect and enrich lives worldwide. We foster a culture of trust, inclusivity, and diversity, and are dedicated to the success of our colleagues and clients.

Role Overview

As a Principal Hardware Security Consultant (also known as a “Product Security Testing Manager”), you will be a senior member of the hardware testing team. Your responsibilities will include :

  • Conducting penetration testing to evaluate product security across various sectors.
  • Performing complex security assessments involving hardware, firmware, and code reviews.
  • Creating test harnesses to identify and demonstrate security vulnerabilities.
  • Communicating vulnerabilities effectively to client development teams during and after assessments.
  • Documenting technical issues, outlining risks, and providing remediation recommendations.
  • Assisting in pre-sales activities for penetration testing engagements.
  • Mentoring junior engineers and guiding their career development.
  • Engaging in vulnerability research and sharing findings through blogs, talks, and papers.
  • Improving internal processes and tooling for security testing.
  • Participating in recruitment efforts, including resume reviews and interviews.

Note : We do not sponsor visas for this role.

Required Skills and Experience

  • At least 5 years of hands-on hardware / product security testing or bug bounty experience, especially in IoT / Mobile products.

Hardware Security Expertise

  • Experience with reverse engineering hardware components (JTAG, SPI, UART, PCB analysis).
  • Proficiency with oscilloscopes, logic analyzers, and debuggers.
  • Ability to identify and exploit embedded system vulnerabilities.
  • Deep knowledge of microcontroller architectures (ARM, RISC-V, MIPS, x86).
  • Understanding of hardware root of trust mechanisms and secure key storage.
  • Experience with scripting languages like Python or Ruby.
  • Expertise in firmware analysis, bootloaders, secure boot, and firmware vulnerabilities.
  • Familiarity with firmware extraction techniques.

Firmware Security Skills

  • Experience analyzing firmware with tools like Ghidra or IDA Pro.
  • Ability to find vulnerabilities related to memory management, encryption, and authentication.
  • Skills in firmware unpacking, bypassing secure boot, and firmware modification.
  • Knowledge of OTA update mechanisms, TEE, and related vulnerabilities.

Additional Skills / Experience

  • Experience at a consulting firm or internal security team.
  • Exploit development and reverse engineering expertise.
  • Research publications or conference presentations.
  • Experience with advanced attack techniques and supply chain security.
  • Understanding of secure hardware design principles.

Our Support for Colleagues

We promote an inclusive, flexible, and supportive work environment, emphasizing wellbeing, continuous learning, and diversity. Our benefits include Wellbeing Days, professional growth opportunities, and a comprehensive benefits package.

We are an equal opportunity employer and value diversity. We encourage applications from all qualified individuals, including those with disabilities. For accommodations, contact [emailprotected] .

This role is subject to local fair chance laws for applicants with criminal histories.

Note : Management may assign or reassign duties at any time.

Salary and Benefits

The annual salary range is $130,000 - $180,000, dependent on experience, education, location, and internal equity. Benefits include retirement plans, insurance, paid time off, and various employee programs.

J-18808-Ljbffr

Create a job alert for this search
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Principal Hardware Security Consultant

Aon

New York

On-site

USD 130.000 - 180.000

12 days ago

Principal Hardware Security Consultant

Aon Hewitt

New York

Hybrid

USD 130.000 - 180.000

15 days ago

Director of Safety

Dechra Pharmaceuticals PLC

Remote

USD 120.000 - 160.000

Today
Be an early applicant

Director of Safety

Dechra

Boston

Remote

USD 120.000 - 160.000

Yesterday
Be an early applicant

Director of Product Security Architecture/ Remote / Central OR Eastern Time zone

Motion Recruitment

Los Angeles

Remote

USD 130.000 - 160.000

2 days ago
Be an early applicant

Principal safety engineer and human

General Motors

Des Moines

Remote

USD 120.000 - 150.000

Yesterday
Be an early applicant

Security Specialist Lead- Staff (Advanced Phishing Program Manager)

AEP

Ohio

Remote

USD 112.000 - 147.000

6 days ago
Be an early applicant

Information Systems Security Manager

Potawatomi Federal Solutions

Remote

USD 90.000 - 150.000

6 days ago
Be an early applicant

Safety & Health Large Account Coordinator

Zenith Insurance Company

San Diego

Remote

USD 135.000 - 166.000

6 days ago
Be an early applicant