Senior Product Security Consultant

Zappsec Inc.

Tewksbury (MA)

On-site

USD 140,000 - 200,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Zappsec Inc. seeks a Senior Product Security Consultant with 10+ years of hands-on testing across embedded devices, firmware security, and hardware interfaces (UART/JTAG/SWD/USB).

You will perform firmware extraction, reverse engineering, and validate secure boot, signing, and update mechanisms. Responsibilities include exploitability validation, attack-path analysis, and remediation guidance, working with architects to meet IEC 62443 and EU CRA controls.

Qualifications

  • Strong hands-on penetration testing and product security assessment experience across embedded systems, connected devices, and firmware security.
  • Experience with firmware extraction, unpacking, reverse engineering, binary analysis, dynamic analysis, and embedded security testing.
  • Familiarity with hardware/device attack surfaces, embedded system architectures, Linux-based systems, network protocols, and secure update mechanisms.
  • Ability to assess secure boot, firmware integrity, firmware trust chain, signing, rollback protection, secure update flows, filesystem security, bootloader security, and binary-level risks.
  • Experience testing authentication, authorization, encryption, TLS/certificates, cryptographic keys, hardware-backed key storage, device identity, secure elements, TPM, and TEE concepts.
  • Experience with exploitability validation, attack path analysis, protocol fuzzing, wireless security testing, and interface testing across UART, JTAG, SWD, USB, BLE, Wi-Fi, and proprietary protocols.

Responsibilities

  • Perform hardware and device-level penetration testing
  • Conduct firmware extraction, unpacking, and binary analysis
  • Assess secure boot, firmware integrity, rollback protection, and update mechanisms
  • Evaluate exposed interfaces (USB, network, wireless, serial/debug, administrative services)
  • Validate authentication, authorization, encryption, and secure configuration controls
  • Conduct exploitability validation, attack path analysis, and privilege escalation testing
  • Analyse attack surfaces to identify material security weaknesses across device components
  • Perform resilience testing and evaluate effectiveness of security controls
  • Test BLE, Wi-Fi, web/API, companion applications and proprietary protocols, including controlled fuzzing
  • Work with the Security architect to identify the test cases and the required open-source testing tools to perform the required IEC 62443 and EU CRA controls
  • Lead the hardware security testing, authentication, authorization, encryption, and secure configuration controls and other active tools-based testing part of the engagement

Skills

Hands-on penetration testing
Embedded systems security
Firmware extraction
Binary analysis
Reverse engineering
Secure update mechanisms
Hardware security testing
Attack surface assessment
Protocol fuzzing
BLE/Wi-Fi testing

Tools

Binwalk
Ghidra
IDA Pro
Radare2
OpenSSL
Burp Suite
Nmap
Wireshark
GDB
Frida
Firmware emulators
Logic analyzers

Job description

Senior Product Security Consultant

Role Summary

Seeking a US Person with 10+ years of hands-on product-security testing including:

  • Hands-on technical product security assessment activities across the customer product ecosystem, including hardware and device penetration testing, firmware extraction and binary analysis, exploitability validation, secure update mechanism review, and embedded security assessment.
  • The role will cover UART/JTAG/SWD/USB, firmware extraction, binary analysis, reverse engineering, secure boot, signing, updates, rollback, authentication, encryption, secure defaults, logging, deletion and residual data.
  • Testing may extend to extends to BLE, Wi-Fi, web/API, companion applications and proprietary protocols, including controlled fuzzing.
  • The consultant will work under formal safety and restoration controls, validate exploitability and compensating controls, assess blast radius and containment, eliminate false positives, produce reproducible evidence and remediation guidance, and perform retesting.

Key Responsibilities

  • Perform hardware and device-level penetration testing
  • Conduct firmware extraction, unpacking, and binary analysis
  • Assess secure boot, firmware integrity, rollback protection, and update mechanisms
  • Evaluate exposed interfaces (USB, network, wireless, serial/debug, administrative services)
  • Validate authentication, authorization, encryption, and secure configuration controls
  • Conduct exploitability validation, attack path analysis, and privilege escalation testing
  • Analyse attack surfaces to identify material security weaknesses across device components
  • Perform resilience testing and evaluate effectiveness of security controls
  • Test BLE, Wi-Fi, web/API, companion applications and proprietary protocols, including controlled fuzzing
  • Work with the Security architect to identify the test cases and the required open-source testing tools to perform the required IEC 62443 and EU CRA controls.
  • Lead the hardware security testing, authentication, authorization, encryption, and secure configuration controls and other active tools-based testing part of the engagement.

Required Skills & Experience

Mandatory:

  • Strong hands-on penetration testing and product security assessment experience across embedded systems, connected devices, and firmware security.
  • Experience with firmware extraction, unpacking, reverse engineering, binary analysis, dynamic analysis, and embedded security testing.
  • Familiarity with hardware/device attack surfaces, embedded system architectures, Linux-based systems, network protocols, and secure update mechanisms.
  • Ability to assess secure boot, firmware integrity, firmware trust chain, signing, rollback protection, secure update flows, filesystem security, bootloader security, and binary-level risks.
  • Experience testing authentication, authorization, encryption, TLS/certificates, cryptographic keys, hardware-backed key storage, device identity, secure elements, TPM, and TEE concepts.
  • Experience with exploitability validation, attack path analysis, protocol fuzzing, wireless security testing, and interface testing across UART, JTAG, SWD, USB, BLE, Wi-Fi, and proprietary protocols.
  • Hands-on experience using security testing and analysis tools such as Binwalk, Ghidra, IDA Pro, Radare2, OpenSSL, Burp Suite, Nmap, Wireshark, testssl.sh, Trivy, GDB, Frida, firmware emulators, protocol fuzzers, logic analyzers, and approved debug-interface tooling.

Good to have:

  • Experience participating in CRA or regulated product security, or compliance-driven cybersecurity assessments
  • Experience participating in engagement related to export-controlled environments
  • Embedded or IoT security experience preferred

Preferred Certifications

  • GXPN (Top Choice)
  • OSEP
  • Completed SANS training SEC556 (IoT Pen Testing)

Years of Required Experience

  • 7-10 years in product security testing including device-level penetration testing
  • 10+ years in Product Security Testing firmware extraction, unpacking, and binary analysis

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Product Security Consultant
Senior Product Security Consultant

Zappsec • Tewksbury (MA), Northern (KY)

Hybrid
USD 150,000 - 190,000
Principal Product Security Architect & Engagement Lead
Principal Product Security Architect & Engagement Lead

Zappsec • Tewksbury (MA), Northern (KY)

Hybrid
USD 190,000 - 230,000
Product Security Engineer
Product Security Engineer

Cypress HCM • Irvine (CA)

On-site
USD 130,000 - 180,000
Principal Product Security Architect & Engagement Lead
Principal Product Security Architect & Engagement Lead

Zappsec Inc. • Tewksbury (MA)

On-site
USD 130,000 - 170,000
Penetration Tester
Penetration Tester

Darkwolfsolutions • Colorado Springs (CO)

On-site
USD 130,000 - 145,000
Penetration Tester
Penetration Tester

Dark Wolf Solutions • Colorado Springs (CO)

Hybrid
USD 130,000 - 145,000
Penetration Tester
Penetration Tester

Dark Wolf • Colorado Springs (CO)

Hybrid
USD 130,000 - 145,000
Senior Embedded Product Security Tester
Senior Embedded Product Security Tester

Zappsec Inc. • Tewksbury (MA)

On-site
USD 140,000 - 200,000
Principal Security Consultant (Hardware/Embedded Penetration Tester)
Principal Security Consultant (Hardware/Embedded Penetration Tester)

NetSPI Inc. • Minneapolis (MN)

On-site
USD 100,000 - 130,000
Principal Security Consultant (Hardware/Embedded Penetration Tester)
Principal Security Consultant (Hardware/Embedded Penetration Tester)

NetSPI • Minneapolis (MN)

On-site
USD 100,000 - 130,000