Role & responsibilities
- Conduct security assessments and risk analysis of embedded medical devices
- Develop and implement security protocols and solutions for medical devices
- Design and execute penetration testing and vulnerability assessments
- Research and stay updated on emerging threats, vulnerabilities, and security trends in IoT and embedded systems.
- Collaborate with cross-functional teams to integrate security measures into the development lifecycle of products.
- Provide technical guidance and support to internal teams on security best practices.
- Participate in the design and architecture of secure IoT and embedded systems.
Preferred candidate profile
Mandatory Skills:
- Proven experience (5 years) in IoT and embedded systems security. Strong knowledge of IoT protocols (e.g., UART, I2C, JTAG, MQTT, CoAP, HTTP) and embedded system architecture
- Experience with reverse engineering ARM/MIPS/x86 code architecture
- Hands on with hardware attacks such as PCB reversing, Component identification,Side channel attacks,memory extraction methods
- Knowledge of radio frequency (RF) protocols and related security implications such as BLE, WIFI, LoRa,DSP, SDR, etc
- Understanding of industrial IoT (IIoT) security considerations. Experience with various hardware security assessment tools/frameworks.
- Familiarity with hardware security concepts such as secure boot, encryption, and secure firmware updates.
- Proficiency in programming languages commonly used in embedded systems (C/C++, Python).
- Proactive, problem-solver and the ability to work independently and within a team
Good to Have:
- Understanding of cryptographic algorithms and protocols
- Knowledge of exploit development techniques, buffer overflows, and other memory corruption vulnerabilities applicable to embedded systems
- Knowledge of secure coding practices and principles specific to embedded systems, including memory management and input validation
- Familiarity with regulatory compliance and standards in IoT security
- Any certification in IoT security, Embedded device security or similar, is a plus.