Embedded Product Security Engineer

Fulcrum 

📍 United States, United States 🇺🇸

contract
mid-level
Posted —

Key Skills

firmwarepenetrationreverseBluetoothZigbee

Industry

Consumer ElectronicsSecurity & Surveillance

Job Description

Fulcrum Technology Solutions are supporting a client to hunt for an Embedded Product Security Engineer. This is a contract to start.


We are seeking a highly technical security engineer focused on embedded systems security, firmware analysis, and offensive security research across IoT and hardware-based products. This role involves deep technical testing of embedded devices, wireless protocols, and firmware to identify vulnerabilities and develop exploit paths.

The ideal candidate has strong hands-on experience breaking embedded systems, reverse engineering firmware, and performing advanced penetration testing on hardware and wireless-enabled devices.


Key Responsibilities

Embedded Security & Offensive Research

  • Perform penetration testing and vulnerability research across embedded systems, firmware, and IoT devices
  • Reverse engineer firmware and binaries to identify security vulnerabilities and exploit paths
  • Develop proof-of-concept exploits targeting embedded architectures (ARM and/or x86)
  • Conduct fuzz testing against firmware, kernels, and embedded software components
  • Analyze wireless protocols including Bluetooth, Zigbee, Z-Wave, Wi-Fi, and proprietary RF systems
  • Perform hardware-assisted security testing where applicable (debug interfaces, embedded access points, etc.)


Firmware & Reverse Engineering

  • Conduct deep firmware analysis using reverse engineering tools and methodologies
  • Identify vulnerability classes in embedded systems and validate exploitability
  • Build or extend tooling for embedded security testing and automation
  • Collaborate with engineering teams to validate and reproduce vulnerabilities


Threat Modeling & Secure Design

  • Perform Threat Analysis and Risk Assessments (TARA) across embedded product lines
  • Participate in secure architecture reviews and secure-by-design initiatives
  • Identify design-level security gaps early in product development lifecycles
  • Translate technical findings into actionable remediation guidance for engineering teams


Security Communication & Enablement

  • Document vulnerabilities with clear reproduction steps, severity ratings, and remediation guidance
  • Present findings to engineering teams, product stakeholders, and security leadership
  • Support PSIRT-style workflows for vulnerability triage and resolution
  • Provide guidance on secure development practices and emerging threat trends


Required Qualifications

  • 4–6+ years of hands-on experience in embedded security, firmware security, or hardware penetration testing
  • Strong experience in reverse engineering (Ghidra, IDA Pro, Binwalk, or similar tools)
  • Experience with embedded systems programming (C/C++) and scripting (Python preferred)
  • Hands-on experience with wireless protocols such as Bluetooth, Zigbee, Z-Wave, or Wi-Fi
  • Experience performing fuzz testing or vulnerability discovery in embedded environments
  • Understanding of embedded hardware interfaces (UART, JTAG, SPI, I2C, etc.)
  • Ability to analyze and exploit vulnerabilities in firmware or embedded systems
  • Strong communication skills for documenting and presenting technical findings


Preferred Qualifications

  • Experience with hardware security tooling (logic analyzers, oscilloscopes, JTAG/SWD tools)
  • Experience in exploit development for embedded or IoT systems
  • Experience contributing to PSIRT or product security programs
  • Familiarity with embedded security standards (IEC 62443, NIST 800-193, etc.)
  • Experience in industrial, automotive, medical device, or telecom security environments
  • Prior consulting or offensive security research background
  • Experience working in lab environments or hardware testing setups


Work Environment

This is a highly technical offensive security role focused on breaking and analyzing embedded systems. The environment is research-driven, engineering-focused, and requires strong autonomy and deep technical curiosity.