Fulcrum Technology Solutions are supporting a client to hunt for an Embedded Product Security Engineer. This is a contract to start.
We are seeking a highly technical security engineer focused on embedded systems security, firmware analysis, and offensive security research across IoT and hardware-based products. This role involves deep technical testing of embedded devices, wireless protocols, and firmware to identify vulnerabilities and develop exploit paths.
The ideal candidate has strong hands-on experience breaking embedded systems, reverse engineering firmware, and performing advanced penetration testing on hardware and wireless-enabled devices.
Key Responsibilities
Embedded Security & Offensive Research
-
Perform penetration testing and vulnerability research across embedded systems, firmware, and IoT devices
-
Reverse engineer firmware and binaries to identify security vulnerabilities and exploit paths
-
Develop proof-of-concept exploits targeting embedded architectures (ARM and/or x86)
-
Conduct fuzz testing against firmware, kernels, and embedded software components
-
Analyze wireless protocols including Bluetooth, Zigbee, Z-Wave, Wi-Fi, and proprietary RF systems
-
Perform hardware-assisted security testing where applicable (debug interfaces, embedded access points, etc.)
Firmware & Reverse Engineering
-
Conduct deep firmware analysis using reverse engineering tools and methodologies
-
Identify vulnerability classes in embedded systems and validate exploitability
-
Build or extend tooling for embedded security testing and automation
-
Collaborate with engineering teams to validate and reproduce vulnerabilities
Threat Modeling & Secure Design
-
Perform Threat Analysis and Risk Assessments (TARA) across embedded product lines
-
Participate in secure architecture reviews and secure-by-design initiatives
-
Identify design-level security gaps early in product development lifecycles
-
Translate technical findings into actionable remediation guidance for engineering teams
Security Communication & Enablement
-
Document vulnerabilities with clear reproduction steps, severity ratings, and remediation guidance
-
Present findings to engineering teams, product stakeholders, and security leadership
-
Support PSIRT-style workflows for vulnerability triage and resolution
-
Provide guidance on secure development practices and emerging threat trends
Required Qualifications
-
4–6+ years of hands-on experience in embedded security, firmware security, or hardware penetration testing
-
Strong experience in reverse engineering (Ghidra, IDA Pro, Binwalk, or similar tools)
-
Experience with embedded systems programming (C/C++) and scripting (Python preferred)
-
Hands-on experience with wireless protocols such as Bluetooth, Zigbee, Z-Wave, or Wi-Fi
-
Experience performing fuzz testing or vulnerability discovery in embedded environments
-
Understanding of embedded hardware interfaces (UART, JTAG, SPI, I2C, etc.)
-
Ability to analyze and exploit vulnerabilities in firmware or embedded systems
-
Strong communication skills for documenting and presenting technical findings
Preferred Qualifications
-
Experience with hardware security tooling (logic analyzers, oscilloscopes, JTAG/SWD tools)
-
Experience in exploit development for embedded or IoT systems
-
Experience contributing to PSIRT or product security programs
-
Familiarity with embedded security standards (IEC 62443, NIST 800-193, etc.)
-
Experience in industrial, automotive, medical device, or telecom security environments
-
Prior consulting or offensive security research background
-
Experience working in lab environments or hardware testing setups
Work Environment
This is a highly technical offensive security role focused on breaking and analyzing embedded systems. The environment is research-driven, engineering-focused, and requires strong autonomy and deep technical curiosity.