Penetration Tester - Hardware
Cybersecurity Tools
Data Security
Embedded Firmware
Embedded Systems
Embedded Systems Security
Embedded Testing
Engineer
Engineering
Ethical Hacking
Firmware Analysis
Hardware Engineering
Hardware Software Co Design
Hardware Testing
Information Security
InfoSec
Offensive Security
Security
Security Testing
Security Testing Tools
Software Engineering
Job Description
Packetlabs is building out its hardware security practice and is hiring a Penetration Tester - Hardware for remote work across Texas/Florida. In this role, you will lead end-to-end security assessments for embedded and IoT devices, combining bench testing with firmware reverse engineering to surface vulnerabilities clients can fix.
What you’ll do
- Plan and execute end-to-end hardware penetration tests on embedded and IoT devices within a defined scope and rules of engagement
- Identify, access, and exploit on-board debug interfaces such as JTAG, SWD, UART, and similar paths to reach code execution or memory access
- Extract firmware through debug ports, in-circuit flash reads (SPI/I2C/NAND), or chip-off when needed, then analyze for vulnerabilities
- Intercept and analyze data on embedded buses including SPI, I2C, UART, CAN, and USB using logic analyzers and protocol decoders
- When in scope, perform side-channel analysis and fault injection such as power analysis and voltage/clock glitching to bypass secure boot, readout protection, or authentication
- Reverse engineer firmware and embedded binaries using tools like Ghidra, IDA, and Binwalk to uncover logic flaws, hardcoded secrets, and exploitable conditions
- Assess physical attack surface, tamper resistance, and key or secret storage
- Separate theoretical risk from operationally relevant findings to keep results actionable
- Produce clear technical reports and present findings to client stakeholders, supporting both technical and non-technical audiences
- Advise on practical, prioritized remediation clients can implement
- Build and maintain lab tooling, test rigs, and internal methodology
- Contribute to research, responsible disclosure, and internal knowledge-sharing
- Stay current on hardware attack techniques, embedded architectures, and defensive controls
- Help raise the standard of hardware security work across the firm
Skills and experience
- Graduate of an Information Security, Computer Science, or Computer/Electrical Engineering degree program (or equivalent hands-on experience)
- Strong electronics fundamentals, including the ability to read schematics and datasheets and reason about boards
- Hands-on soldering skills, including SMD rework and basic chip removal
- Demonstrated experience accessing debug interfaces (JTAG, SWD, UART) and extracting firmware from real devices
- Comfort with core bench instruments: logic analyzer, oscilloscope, and multimeter
- Firmware reverse engineering with scripting in Python, plus enough C to understand embedded code
- Familiarity with embedded architectures including ARM/Cortex-M, MIPS, AVR, and RISC-V, along with RTOS and bare-metal concepts
- Clear written and verbal communication
- Must be located in Texas or Florida
Tools and technologies
- Debug and interfaces: JTAG, SWD, UART, SPI, I2C, NAND, CAN, USB
- Bench instruments and analysis: logic analyzer, oscilloscope, multimeter, protocol decoders
- Reverse engineering and scripting: Ghidra, IDA, Binwalk, Python, C
- Embedded platforms and concepts: ARM/Cortex-M, MIPS, AVR, RISC-V, RTOS, bare-metal
- Security and research tooling: ChipWhisperer, secure boot chains
- Additional platforms noted: TEEs, secure elements, HSMs, SDR, BLE, Wi-Fi, KiCad, Altium
- Certs and related areas: OSCP
Nice to have
- Side-channel and fault-injection experience such as ChipWhisperer
- RF and wireless work including SDR, BLE, sub-GHz, and Wi-Fi
- Knowledge of secure boot chains, TEEs, secure elements, and HSMs
- PCB design familiarity with KiCad or Altium
- Published CVEs, conference talks, CTF placements, or open-source tooling
- Relevant certifications, for example OSCP or hardware-focused training
Compensation and benefits
The salary range for this role is USD 80,000 - 120,000 per year (remote within Texas or Florida). Packetlabs also provides offensive security training, mentorship, and professional development reimbursement, along with a flexible work environment, a paid volunteer day, paid Birthday day off, and paid U.S. public holidays.
Additional expectations
- No ego culture and a focus on continuous learning and humility
- A customer-first mindset with responsive, professional communication
- Work quality that demonstrates credibility and proven impact
- Depth in validating findings, with appropriate restraint in sensitive OT environments
- Adaptability to changing consulting environments and comfort tackling difficult technical obstacles
- Self-motivation and ownership of outcomes
- Location requirement: Texas or Florida
What success looks like
- Clients receive a clear, accurate understanding of hardware risk backed by proven, reproducible impact
- Findings are credible, actionable, and relevant for both technical and leadership audiences
- Engagements are delivered to a consistently high standard with strong client confidence
- Scope and rules of engagement are managed well as engagements evolve, with risk surfaced early and clearly
- Packetlabs hardware testing methodology and lab capability continue to mature through your contribution
- Clients trust Packetlabs as the partner that can break their hardware before someone else does