Hardware Penetration Tester

Packetlabs Ltd.
Remote

About The Position

Packetlabs is seeking a specialized Penetration Tester - Hardware to lead security assessments of embedded and IoT devices. This role focuses on vulnerabilities residing in silicon, firmware, and board layout, rather than in web requests. The Ethical Hacker - Hardware will assess embedded systems across various industries, requiring hands-on interaction with devices to identify and exploit physical or local access vulnerabilities. This position demands a blend of offensive security instincts and hardware fundamentals, working directly with clients to understand their devices and deliver actionable security findings.

Requirements

  • A graduate of an Information Security, Computer Science, or Computer/Electrical Engineering degree program (or equivalent hands-on experience).
  • Strong electronics fundamentals. Able to read schematics and datasheets and reason about a board from them.
  • Hands-on soldering ability, including surface-mount (SMD) rework and basic chip removal.
  • Demonstrated experience accessing debug interfaces (JTAG, SWD, UART) and extracting firmware from real devices.
  • Comfort with core bench instruments: logic analyzer, oscilloscope, and multimeter.
  • Firmware reverse-engineering skills and scripting proficiency in Python, plus enough C to read embedded code.
  • Familiarity with common embedded architectures (ARM/Cortex-M, MIPS, AVR, RISC-V) and RTOS/bare-metal concepts.
  • Clear written and verbal communication.
  • No egos, ever.
  • Customer-first mentality.
  • Deliver work that you take pride in.
  • Digs deeper into every finding.
  • Comfortable being uncomfortable.
  • Always learning.
  • Self-motivated and dependable.

Nice To Haves

  • Side-channel / fault-injection experience (e.g., ChipWhisperer)
  • RF and wireless work: SDR, BLE, sub-GHz, Wi-Fi
  • Knowledge of secure boot chains, TEEs, secure elements, and HSMs
  • PCB design familiarity (KiCad / Altium) for understanding target boards
  • Published CVEs, conference talks, CTF placements, or open-source tooling
  • Relevant certifications (e.g., OSCP for breadth, or hardware-focused training)

Responsibilities

  • Plan and execute end-to-end hardware penetration tests on embedded and IoT devices, against a defined scope and rules of engagement.
  • Identify, access, and exploit on-board debug interfaces: JTAG, SWD, UART, and similar, to gain code execution or memory access.
  • Extract firmware via debug ports, in-circuit flash reads (SPI / I2C / NAND), or chip-off when required, and analyze it for vulnerabilities.
  • Intercept and analyze data on common embedded buses (SPI, I2C, UART, CAN, USB) using logic analyzers and protocol decoders.
  • Perform side-channel analysis and fault injection (power analysis, voltage/clock glitching) to bypass secure boot, readout protection, or authentication, where in scope.
  • Reverse engineer firmware and embedded binaries (Ghidra, IDA, Binwalk, etc.) to find logic flaws, hardcoded secrets, and exploitable conditions.
  • Assess physical attack surface, tamper resistance, and key/secret storage.
  • Distinguish between theoretical and operationally relevant risk to keep findings actionable.
  • Write high-quality technical reports and present findings to client stakeholders, both technical and non-technical.
  • Advise on practical, prioritized remediation that clients can act on.
  • Build client confidence through credibility, clear communication, and proven impact.
  • Build and maintain lab tooling, test rigs, and internal methodology.
  • Contribute to research, responsible disclosure, and internal knowledge-sharing.
  • Stay current on hardware attack techniques, embedded architectures, and defensive controls.
  • Help raise the standard of hardware security work across the firm.

Benefits

  • Competitive compensation and growth opportunity
  • Flexible work environment that empowers employees to do their best work
  • Immediate and ongoing offensive security training, mentorship, and professional development
  • Opportunity to work on high-stakes hardware engagements
  • Play a key role in shaping the growth, direction, and methodology of Packetlabs' expanding hardware practice
  • Collaboration with a highly skilled team of security professionals
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service