Senior Product Security Consultant
Tewksbury, MA - USA
Job Summary
Role: Senior Product Security Consultant
Work Location: Tewksbury MA 01876 (Hybrid)
Type: C2C
Role Summary
Perform hands-on technical product security assessment activities across the customer product ecosystem including hardware and device penetration testing firmware extraction and binary analysis exploitability validation secure update mechanism review and embedded security assessment.
Key Responsibilities
-
Perform hardware and device-level penetration testing
-
Conduct firmware extraction unpacking and binary analysis
-
Assess secure boot firmware integrity rollback protection and update mechanisms
-
Evaluate exposed interfaces (USB network wireless serial/debug administrative services)
-
Validate authentication authorization encryption and secure configuration controls
-
Conduct exploitability validation attack path analysis and privilege escalation testing
-
Analyze attack surfaces to identify material security weaknesses across device components
-
Perform resilience testing and evaluate effectiveness of security controls
Required Skills & Experience
Mandatory:
-
Strong hands-on penetration testing and product security assessment experience
-
Experience with embedded systems connected devices and firmware security analysis
-
Experience with firmware binary analysis techniques and embedded security testing tools
-
Familiarity with hardware/device attack surfaces and embedded system architectures
-
Familiarity with Linux-based systems network protocols and secure update mechanisms
Good to have:
-
Experience participating in CRA or regulated product security or compliance-driven cybersecurity assessments
-
Experience participating in engagement related to export-controlled environments
-
Strong documentation skills
Preferred Certifications
-
OSCP
-
OSEP / OSCE
-
GPEN / GXPN
-
Embedded or IoT security experience preferred
-
Completed SANS training SEC556 (IoT Pen Testing)
Years of Required Experience
-
7-10 years in product security testing including device-level penetration testing
-
firmware extraction unpacking and binary analysis