Senior Penetration Tester
Senior
Application Security
Binary Analysis
Cloud Platforms
Embedded Iot Security
Fuzzing
Identity and Access Management
Information Security
Information Technology (IT)
InfoSec
Offensive Security
Owasp
Owasp Top Ten
Penetration Testing
Security Compliance
Security Standards
Security Testing
Vulnerability Assessment
Job Description
Senior Penetration Tester to lead security assessment work across embedded, cloud, web, and mobile environments in a hybrid setup from Northbrook, IL.
Responsibilities
- Lead end-to-end security assessment engagements covering embedded products, IoT Medical & Industrial devices, Web/Mobile applications, and Cloud infrastructures.
- Run comprehensive evaluations including vulnerability discovery, exploitation, code review, fuzzing, binary analysis, and validation of security controls across target environments.
- Interpret and apply cybersecurity compliance standards including EN18031, CRA, UK PSTI, and UL Standards for diverse product types; translate requirements into effective test plans.
- Partner with clients to understand security objectives; provide technical guidance and deliver professional reports with findings, risk ratings, and remediation recommendations.
- Provide high-level technical support for test planning, methodology development, procedure updates, staff training, and resolution of complex quality or testing issues.
- Maintain and improve technical knowledge through workshops, professional publications, applicable certifications, professional societies, and cross-departmental task forces.
- Track and incorporate latest developments in physical attacks to contribute to internal R&D for both hardware (analog and digital electronics) and software (C, C++, Assembly, and others) to enhance attack capabilities and explore new attack forms.
- Implement sophisticated multi-technique attacks using approaches such as vulnerability analysis, signal processing, FPGA, optical, and others.
- Conduct security evaluation attacks on smart cards and embedded systems, with emphasis on analyzing real products to identify strengths and weaknesses.
- Specialize in innovative physical attacks using laser or EM techniques, applying an in-depth understanding of how products work to stress them with complex hardware techniques.
- Perform web application penetration testing covering OWASP Top 10, API security, authentication/authorization flaws, business logic vulnerabilities, and modern web frameworks.
- Execute mobile application security assessments for iOS and Android, including static analysis, dynamic analysis, reverse engineering, and platform-specific vulnerability testing.
- Conduct cloud security testing and configuration reviews across AWS, Azure, GCP, or multi-cloud environments, focusing on IAM, network security, container/Kubernetes security, serverless architectures, storage security, and cloud misconfigurations.
Requirements
- University Degree (equivalent to a Bachelor’s) in Electronic/Computer Science/Computer Engineering/Electrical Engineering or related discipline, plus 3–5 years of related experience.
- Good skills in Cloud security testing preferred.
- Strong low-level programming capabilities in C, C++, and Assembly, plus scripting experience.
- Experience with FPGA, signal processing, or hardware debugging tools is a strong plus.
- Comfort using test equipment and working in a multi-skills environment mixing electronic, optical, security, mechanical, and IT.
- Excellent written and verbal communication skills, including the ability to explain complex technical concepts to technical and non-technical stakeholders.
- Self-motivated team player who can work independently and is interested in bringing new ideas for technical development.
Technologies
- C, C++, Assembly
- FPGA
- OWASP Top 10
- iOS, Android
- AWS, Azure, GCP
- IAM, Kubernetes
- Serverless architectures
Benefits
- Annual bonus compensation with a target payout of 10% of base salary.
- Health benefits: medical, dental, and vision.
- Wellness benefits: mental and financial health.
- Retirement savings: 401K commensurate with standard rewards offered in each location/country.
- Paid time off including vacation (15 days), holiday and personal days (totaling 12 days), and sick time off (72 hours).
Location: Northbrook, IL (hybrid)
Estimated Salary: USD 110,000–140,000 per year
Similar Jobs
J
S
J