- Salary
- $80k – $150k
- Location
- Fairlawn, OH
- Department
- Engineering
- Visa
- Not sponsored
- Source
- Paylocity
Description
Description
TrustedSec is seeking a passionate information security professional to join our Software Security Team. The Hardware Security Consultant / Penetration Tester will report to the Practice Lead and be responsible for assisting clients in their hardware security needs, including conducting hardware security assessments to identify vulnerabilities, deliver clear and actionable findings, and help clients improve their overall security posture. The ideal candidate brings hardware security expertise and is equally capable in application security. Modern devices often depend on companion mobile applications and backend web infrastructure, and this role is responsible for evaluating these components as a single system. The consultant will also perform dedicated web application security assessments. At times, the consultant will work with other teams within the organization to collaborate on deliverables.
This is both a technical and client-facing role. As such, the candidate should have experience in penetration testing and embedded systems and be capable of building direct client relationships while contributing to TrustedSec’s growing body of security knowledge.
Requirements
The candidate must be legally authorized to work in the United States. TrustedSec cannot provide sponsorship or consider applicants located outside the United States.
This is a remote position, allowing employees to work from their home residence within the United States. Travel to client sites or industry-related events is required.
Duties/Responsibilities:
- Conduct high-quality hardware security assessments with limited direct supervision
- Produce clear, technically accurate reports with testing walkthroughs, findings, and actionable recommendations for both technical and executive audiences
- Conduct client meetings, serve as the primary point of contact, and interface directly with clients during engagements
- Serve as a subject matter expert for other consultants/teams and regularly collaborate and contribute to furthering the education and progression of the skills and success of everyone at TrustedSec
- Maintain and build upon cybersecurity knowledge and skills by attending educational workshops and adopting a curious, continuous learning mindset
- Review publications, write blog posts, and potentially speak at conferences or other events
Minimum Requirements:
- 2+ years' recent experience performing hardware security assessments
- 2+ years' recent experience testing web applications and APIs
- Experience identifying and interfacing with debug interfaces such as JTAG, SWD, and UART, including locating undocumented test points
- Experience with firmware extraction and firmware analysis, including extraction via debug interfaces, chip-off, or vendor update files
- Proficiency with Ghidra, Binary Ninja or equivalent for firmware reverse engineering
- Experience assessing Wi-Fi and Bluetooth communications, including traffic flows between devices and mobile applications
- Proficiency in Burp Suite, or other intercepting proxy, for intercepting and analyzing web and mobile application traffic, and familiarity with Wireshark for non-HTTP network traffic
- Experience escaping restricted environments on self-service terminals
- Knowledge of manual application security testing, penetration testing methodologies, the OWASP Top 10, and the OWASP Testing Guide
- Strong understanding of common security controls and vulnerability testing techniques
- Good time management skills and the ability to meet strict deadlines
- Demonstrated analytical and project management skills
- Excellent verbal and written communication skills including active listening and competence in presenting findings and recommendations to audiences with a range of technical understanding
- Ability to write technical documents with correct spelling, grammar, and punctuation and the ability to distill information for non-echnical readers
- Thrive in a fast-paced, collaborative environment
- Ability to take initiative and work independently
Desired Skills/Education/Experience:
- Experience assessing cellular-connected devices, including AT command interaction, SIM extraction, and IMEI spoofing
- Ability to write scripts to support testing and tooling development
- Familiarity with AI/LLMs/frontier models/agentic tools/coding assistants
- Experience in mobile application testing
- Prior consulting experience
- Industry-recognized security certification(s) such as OSCP, Burp Suite Certified Practitioner, OSWE, etc.
Physical Requirements:
- Prolonged periods of sitting at a desk and working on a computer
- Ability to lift 50 pounds occasionally, including transport of testing equipment to/from client sites
- Travel up to 25% over the course of the calendar year, including onsite client engagements
- Must reside in the United States
Salary Description:
Base compensation typically ranges from $80,000 - $150,000 and is determined by multiple factors such as geographic location, relevant experience, and demonstrated skills. In addition to base pay, we offer a generous paid time off allowance, paid holidays, and a performance pay bonus program.
Learn more about TrustedSec here!