Ready to strengthen your security posture?
Hardware Ethical Hacker
Location
Texas
Posted
8 days ago
Salary
$80K - $120K / year
Seniority
Junior
Job Description
Hardware Ethical Hacker
Packetlabs
• Plan and execute end-to-end hardware penetration tests on embedded and IoT devices, against a defined scope and rules of engagement • Identify, access, and exploit on-board debug interfaces: JTAG, SWD, UART, and similar, to gain code execution or memory access • Extract firmware via debug ports, in-circuit flash reads (SPI / I2C / NAND), or chip-off when required, and analyze it for vulnerabilities • Intercept and analyze data on common embedded buses (SPI, I2C, UART, CAN, USB) using logic analyzers and protocol decoders • Where in scope, perform side-channel analysis and fault injection (power analysis, voltage/clock glitching) to bypass secure boot, readout protection, or authentication • Reverse engineer firmware and embedded binaries (Ghidra, IDA, Binwalk, etc.) to find logic flaws, hardcoded secrets, and exploitable conditions • Assess physical attack surface, tamper resistance, and key/secret storage • Write high-quality technical reports and present findings to client stakeholders, both technical and non-technical • Advise on practical, prioritized remediation that clients can act on • Build and maintain lab tooling, test rigs, and internal methodology • Help raise the standard of hardware security work across the firm
Job Requirements
- A graduate of an Information Security, Computer Science, or Computer/Electrical Engineering degree program (or equivalent hands-on experience)
- Strong electronics fundamentals. Able to read schematics and datasheets and reason about a board from them
- Hands-on soldering ability, including surface-mount (SMD) rework and basic chip removal
- Demonstrated experience accessing debug interfaces (JTAG, SWD, UART) and extracting firmware from real devices
- Comfort with core bench instruments: logic analyzer, oscilloscope, and multimeter
- Firmware reverse-engineering skills and scripting proficiency in Python, plus enough C to read embedded code
- Familiarity with common embedded architectures (ARM/Cortex-M, MIPS, AVR, RISC-V) and RTOS/bare-metal concepts
- Clear written and verbal communication
- Nice to have (one or more would be an asset): Side-channel / fault-injection experience (e.g., ChipWhisperer)
- RF and wireless work: SDR, BLE, sub-GHz, Wi-Fi
- Knowledge of secure boot chains, TEEs, secure elements, and HSMs
- PCB design familiarity (KiCad / Altium) for understanding target boards
- Published CVEs, conference talks, CTF placements, or open-source tooling
- Relevant certifications (e.g., OSCP for breadth, or hardware-focused training)
Benefits
- Immediate and ongoing offensive security training
- Mentorship and professional development to advance your technical capabilities
- Competitive compensation and growth opportunity
- Flexible work environment that empowers employees to do their best work
- Fully remote within Canada or Texas
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Microsoft Security Engineer
GuidePoint SecurityWe help organizations make smarter cybersecurity decisions that minimize risk.
Role Description We are seeking a security first, Microsoft focused engineer to join our Microsoft Cloud Security Team. This role will be primarily delivering hands-on security engagements for clients ranging from small businesses to large enterprises. Your work centers on Microsoft Entra ID (identity and access management) and Microsoft Purview (data protection), with supporting work in Intune and Defender XDR. You'll partner with architects and principal consultants across varied industries and environments. You'll own your technical delivery independently (80% billable target), managing your time and communication within assigned engagements, and contribute to internal practice and knowledge-sharing efforts between projects. Roles and Responsibilities - Identity & Access (Entra ID / AD): - Design and implement identity architecture, hybrid sync (Entra Connect), Conditional Access, MFA/passwordless, and identity governance (PIM, RBAC, access reviews, entitlement management). - Integrate applications via SSO (SAML/OIDC), enterprise app registrations, and SCIM provisioning. - Investigate and remediate identity risks using Entra ID Protection, sign-in and audit logs; drive hybrid identity hygiene (stale object cleanup, privileged account reduction, tiered admin models). - Data Security & Compliance (Purview): - Design and implement sensitivity labels, DLP, and retention policies across M365; support data classification, information protection rollouts, and data security posture assessments. - Support eDiscovery, Insider Risk Management, communication compliance, and AI data security readiness (DSPM for AI) as engagements require. - Intune & Defender XDR: - Configure device compliance, configuration profiles, and app deployments across platforms; support Defender for Endpoint, Office 365, Identity, and Cloud Apps in cloud and hybrid environments. - Other duties as assigned. - Adhere to GuidePoint Security Core Values. Qualifications - Bachelor’s degree preferred. - 2–5 years in IT administration, identity management, or security operations. - Hands-on production experience with Microsoft Entra ID and on-premises Active Directory, including Conditional Access, MFA, RBAC, and hybrid identity (Entra Connect). - Knowledge of core authentication protocols: SAML, OAuth 2.0/OIDC, Kerberos, LDAP. - Experience implementing Microsoft Purview (sensitivity labels, DLP, retention, or eDiscovery) and comfort supporting Intune and Defender XDR. - Basic PowerShell scripting for automation and reporting (e.g., Microsoft Graph PowerShell). - Strong troubleshooting skills, attention to detail, and clear written and verbal communication. - Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes. Preferred Experience - Advanced AD work: multi-domain/forest design, migrations, tiered administration, legacy auth cleanup. - Microsoft Sentinel: log onboarding, detection development, or broader SIEM/SOAR experience. - Azure infrastructure and security (Azure Policy, network security, landing zones, RBAC). - SharePoint Online governance, Teams Voice, Power BI/Fabric, or Copilot Studio/Azure AI Foundry experience. Travel Requirements - This role is 100% remote requiring less than 10% travel for corporate events. Physical Requirements - Sedentary work. - Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day. - Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day. Benefits - Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions). - Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans). - Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans. - 12 corporate holidays and a Flexible Time Off (FTO) program. - Healthy mobile phone and home internet allowance. - Eligibility for retirement plan after 2 months at open enrollment. - Pet Benefit Option.
• Lead and perform AI-assisted red team engagements across web applications, APIs, cloud workloads and infrastructure, and deliver prioritized technical reports and executive summaries. • Manage and develop two direct reports, run regular 1:1s, performance reviews, and development plans; contribute to hiring and team growth. • Provide clear remediation guidance and validate fixes, prioritizing critical and high findings. • Configure, tune and maintain offensive tooling and develop automation playbooks that reduce manual triage and false positives. • Integrate recurring security checks into CI/CD pipelines and platform processes to enable continuous testing and attack-surface reduction. • Lead remediation workshops and knowledge transfers, and produce reusable runbooks for product and platform teams. • Coordinate triage and handoff with SOC, IT Ops, product teams and central IT Security, and support governance and compliance mapping (OWASP, API Security Top 10, CVSS).
Senior Manager, Corporate Security
Keurig Dr PepperKeurig Dr Pepper (Nasdaq: KDP) is a leading beverage company with more than 150 owned, licensed and partner brands that meet a wide range of needs and occasions. Our North American refreshment beverage business holds leadership positions across carbonated soft drinks, water, juice and mixers with a portfolio of iconic brands such as Dr Pepper®, Canada Dry®, Mott’s®, A&W®, Peñafiel®, GHOST®, 7UP®, Snapple®, Clamato® and Core Hydration®. Our global coffee business spans more than 100 markets and includes the leading Keurig® single‑serve brewing system in the U.S. and Canada, along with powerhouse brands such as Peet’s, L’OR and Jacobs, and other regional coffee leaders. Our more than 50,000 employees aim to enhance the experience of every beverage and coffee occasion while making a positive impact for people, communities and the planet. We strive to be an employer of choice, providing a culture and opportunities that empower our team to grow and develop. We offer robust benefits to support your health and wellness as well as your personal and financial well-being.
Role Description The Senior Manager, Corporate Security is responsible for supporting and managing all Corporate Security programs for an assigned territory within the U.S. portfolio. This includes overseeing all investigations, facility security assessment, capital projects, and awareness training in a manner consistent with KDP policies, procedures, quality standards, customer needs, and applicable local, state, and federal regulations. This position requires a solid hands-on candidate who will be directly involved with all members of management and field personnel. This is a remote-based position; however, candidates must be located in California and willing to travel quarterly or as needed. Position Responsibilities - Physical Security: Supports implementation and gap analysis on electronic security systems, closed circuit television (CCTV), access controls, fire/burglar alarms, outdoor perimeter controls. Assists in the project design of physical security systems at applicable locations. Ensures proper evaluation of the physical security system at all facilities. - Risk Assessment: Responsible to conduct site vulnerability assessments and liaise with appropriate site leadership on risk mitigation plans and physical security capital design projects. - Threat Management: Responsible for investigating, assessing, and responding to incidents of internal and external workplace violence to include physical violence, criminal activity, and communicated threats. Ensures locations susceptible to labor strikes implement proper protection programs. - Risk Advisor & Business Partner: Works directly with all KDP management in Legal, Human Resources, Finance, Operations, Compliance and Environmental Health & Safety for purposes of security training, coordination of investigative activities, and advisory consultations. - Security Training: Responsible for various aspects related to training leadership and workforce on security related training activities, including security awareness, workplace violence, active shooter, crisis management, and business continuity. - Law Enforcement Liaison: Serves as liaison between KDP and all federal, state, and local law enforcement personnel. Qualifications - Bachelor's degree in related field - 7 years of experience in Federal, State or Local law enforcement, military service, or private/corporate security companies. - Experience working in a corporate environment preferred - Demonstrated leadership skills, ability to inspire confidence, and experience in working with individuals from diverse backgrounds, and levels within corporate structure - Knowledge of physical security, alarm, access control and CCTV surveillance systems preferred. - Security training and written/verbal communications skills required - Must be PC literate including MS Word, Excel, PowerPoint, and Internet - Strong communication and interpersonal skills - Ability to work effectively in complex and often ambiguous situations under tight deadlines and competing demands - Proven record of accomplishment and experience in change management preferred - Ability to function independently and exercise sound judgment. - Professional accreditation desirable (Certified Protection Professional, Physical Security Professional, etc.) Requirements - Must be available to work in 24/7 environment as required - Must be available for primary travel to sites throughout United States and on occasion global deployment as well (up to 40%) - Must be based in California Benefits - Salary Range: $116,100 - $160,000 - Actual placement within the compensation range may vary depending on experience, skills, and other factors - Benefits, subject to election and eligibility: Medical, Dental, Vision, Disability, Paid Time Off (including paid parental leave, vacation, and sick time), 401k with company match, Tuition Reimbursement, and Mileage Reimbursement - Annual bonus based on performance and eligibility
Cyber-Security Engineer
VOLENTUM Deutschland GmbHVOLENTUM ist eine deutschlandweit tätige Personalberatung, die sich auf die Vermittlung von Fach- und Führungskräften sowie die Besetzung von C-Level Positionen (Geschäftsführer, Vorstände) spezialisiert hat.
Role Description Du entwickelst und implementierst technische Sicherheitskonzepte für IT-, Cloud- und Hybrid-Infrastrukturen und bist offen für spannende Karrierechancen, die nicht nur irgendein Job sind? Wir von VOLENTUM sprechen regelmäßig mit Unternehmen, die kompetente und motivierte IT-Security-Spezialisten suchen. Wenn Du in diesem Bereich Erfahrung mitbringst und offen für eine neue Herausforderung bist, freuen wir uns darauf, Dich kennenzulernen. Aufgaben - Bewertung von IT-Sicherheitsrisiken und Koordination geeigneter Maßnahmen. - Weiterentwicklung und Sicherstellung von Netzwerk- und Security-Standards. - Mitwirkung bei der Umsetzung von regulatorischen Anforderungen wie ISO 27001, NIS2 und BSI IT-Grundschutz. - Betreuung und kontinuierliche Optimierung von SIEM-, EDR- und XDR-Lösungen. - Entwicklung von Detection Rules, Use Cases, Alerts und automatisierten Reaktionsmaßnahmen. - Durchführung von Security Reviews und Unterstützung bei internen und externen Audits. - Beobachtung aktueller Bedrohungslagen und Bewertung neuer Sicherheitstechnologien und Angriffsmethoden. Qualifications - Abgeschlossenes Studium der Informatik, IT-Sicherheit oder einer vergleichbaren Fachrichtung beziehungsweise eine gleichwertige Ausbildung mit relevanter Berufserfahrung. - Mehrjährige praktische Erfahrung in der IT-Sicherheit, beispielsweise als Cyber-Security Engineer, Security Analyst, SOC Analyst oder Security Administrator. - Fundierte Kenntnisse in mindestens drei der folgenden Bereiche: SIEM und Security Monitoring, Endpoint Detection and Response, Netzwerk- und Firewall-Security, Cloud Security, Identity and Access Management, Schwachstellenmanagement, Incident Response. - Sicheres Verständnis von Netzwerkprotokollen und Technologien wie TCP/IP, DNS, HTTP/S, VPN, VLAN und TLS. - Erfahrung mit Microsoft-, Linux- oder hybriden Infrastrukturumgebungen. - Fundierte Kenntnisse typischer Angriffsmethoden sowie gängiger Schutz- und Erkennungsmaßnahmen. Benefits - Unbefristete Festanstellung direkt bei unserem Kunden. - Ein an Deinen Kenntnissen und Erfahrungen orientiertes, attraktives Gehalt. - Individuelle Festlegung Deiner präferierten Technologien und Einsatzbereiche. - 100% remote oder hybrid an einem der deutschlandweiten Standorte. - Karriere-Begleitung während Deiner Einarbeitung und auch darüber hinaus.


