NCC Group

At the heart of cyber innovation - creating a more secure digital future

Embedded Device Security Consultant

Security EngineerSecurity EngineerFull TimeRemoteTeam 1,001-5,000Since 1999H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

111 days ago

Salary

$80K - $120K / year

Bachelor Degree3 yrs expEnglishAndroidAssemblyJavaLinux

Job Description

• Perform high-end security evaluations and research for our clients, focused on a range of embedded devices • Work with other team members to deliver high-quality results to IOActive’s clients throughout the world • Investigate possible logical attack scenarios by interpreting the code review findings, orienting the attack paths, and analyzing the test results • Develop sophisticated, state-of-the-art attacks that integrate the latest attack methods against embedded products • Create tools to assist in project goals • Communicate complex vulnerabilities to both technical and non-technical client staff • Perform research on new attack vectors, discover new vulnerabilities, create new exploitation techniques • Evangelize IOActive Labs through blogs, white papers, presentations, etc. • Support business development efforts through the scoping of engagements

Job Requirements

  • 3-5 years or more of relevant work experience in a high-paced, enterprise consulting environment
  • Rapid identification of attack surfaces and entry points using implicit threat modeling techniques
  • Ability to connect and use JTAG/on-chip Debuggers
  • Low-level C code review
  • FreeRTOS, Android, Linux kernel drivers, protocol parsing
  • Sandbox policy review: SELinux/SE Android, seccomp, Linux name spaces, Minijail/Firejail
  • Crypto implementation code reviews, specifically for secure boot and code signing
  • Java, especially Android app side
  • ARM 32- and 64-bit assembly
  • Extensive Git/GitHub experience
  • Wi-Fi/Bluetooth Reverse engineering, specifically firmware
  • Hardware/embedded system hacking
  • Vulnerability assessment and penetration testing
  • Knowledge of security-related topics, such as authentication, entitlements, identity management, data protection, data leakage prevention, validation checking, encryption, hashing, principle of least privilege, software attack methodologies, secure data transfer, secure data storage
  • Ability to work independently under deadline
  • Rigorous attention to detail and strong analytic skills
  • Ability to write test plans based upon initial impressions and discussions with the team
  • Comfortable navigating large codebases with minimal guidance
  • Excellent command of written and spoken English
  • Comfortable working as part of a multinational and multidisciplinary team
  • Logical and structured approach to projects

Benefits

  • PTO
  • Holiday
  • Medical
  • Dental
  • Vision
  • 401(k) match
  • Long and Short Term Disability
  • Life Insurance
  • Employee Assistance Program (EAP)
  • Business Travel Insurance

Related Categories

Related Job Pages

More Security Engineer Jobs

GCP Security – Cloud Armor Architect

DKSH Portugal, Unipessoal, Lda.

Distributor of Specialty Chemicals and Innovative Ingredients. Market Expansion Services Provider

Security Engineer111 days ago
Full TimeRemoteTeam 11-50Since 2014

GCP Security Architect designing and managing secure cloud infrastructures

AWSAzureCloudGoogle Cloud PlatformTerraform
Ohio

Staff Security Advocate

Semgrep

Semgrep is a code scanning platform for finding first and third-party security vulnerabilities in your code base.

Security Engineer111 days ago
Full TimeRemoteTeam 51-200Since 2017H1B No Sponsor

Security Advocate educating teams on secure coding and fostering community engagement.

CloudJavaJavaScriptPythonGo
Arizona + 20 moreAll locations: Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Illinois, Nebraska, New Jersey, New York, North Carolina, Oregon, Maryland, Massachusetts, Michigan, Missouri, Tennessee, Texas, Virginia, Washington, Wisconsin
$147.5K - $199.5K / year

Capture Manager – Transportation Security

Smiths Group plc

Pioneers of progress: Engineering a better future.

Security Engineer111 days ago
Full TimeRemoteTeam 10,001+Since 1851H1B No Sponsor

Capture Manager leading TSA program business development

Maryland
$84K - $126K / year

IT Security Lead

Guidehouse

Solving big problems, building trust in society, and empowering our clients to shape the future.

Security Engineer111 days ago
Full TimeRemoteTeam 10,001+Since 2018H1B Sponsor

IT Security Lead overseeing cybersecurity strategies for healthcare technology implementations

Cyber SecurityOracle
United States
$130K - $216K / year