Hardware Security and Vulnerability Analyst (Reverse Engineer) - Remote

Remote • Posted 60+ days ago • Updated 4 hours ago
Full Time
Occasional Travel Required
Remote
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

👾 Reticulating splines...

Job Details

Skills

  • C/C++
  • Python
  • Assembly
  • IDA Pro
  • Ghidra
  • FPGA
  • Cryptography
  • Hardware
  • Embedded Software
  • Hardware Security
  • Reverse Engineering
  • Side Channel Attacks
  • Fault Injection

Summary

The EndoSec Hardware Security and Vulnerability Analyst is responsible for extracting and analyzing firmware and data at rest, identifying vulnerabilities in software, firmware, and hardware, as well as developing proof of concept exploits. The candidate will collaborate with other engineers and security experts to find and exploit security flaws and vulnerabilities within devices and designs as well as to build secure and efficient systems, contributing to our products and services ongoing security and privacy. This is a remote position.

Key Responsibilities

  1. System Analysis: Analyze systems to understand functionality, failure points, and consequences of failure.
  2. Security Measure Circumvention: Bypass implemented security measures to gain access to sensitive data, including enabling debugging, forging or bypassing signatures, gaining elevated privileges, and simulating environmental and working conditions.
  3. Binary Code Extraction and Analysis: Extract firmware, executables, and other sensitive data from embedded systems and analyze the extracted code for possible vulnerabilities and sensitive data, e.g. passwords, cryptographic keys, etc.
  4. Side-Channel Analysis and Fault Injection: Setup and perform side-channel analysis to recover sensitive data, e.g. cryptographic keys, sensitive plaintext, etc. Setup and perform fault injection attacks to bypass security measures and/or recover sensitive data.
  5. Exploit Development: Develop custom and novel exploits to bypass security measures, recover sensitive data, or gain elevated privileges in embedded systems.
  6. Documentation: Prepare detailed documentation, including physical setups, testing procedures, and user guides, for reproducibility of found results and maintenance.
  7. Continuous Learning: Stay current with the latest advancements in reverse engineering and hardware security to continually refine and enhance skills.

Position Requirements

  1. Ability to obtain and maintain a US government security clearance.
  2. Bachelor''s degree in Electrical Engineering, Computer Engineering, or a related field.
  3. Experience reverse engineering embedded systems including using standard tools such as IDA Pro, Ghidra, etc.
  4. Experience working with FPGAs, hardware description languages (VHDL, Verilog), microcontrollers, SoCs, and related hardware (Flash, SRAM, DRAM, etc.).
  5. Strong programming skills in scripting languages (Python, JavaScript, bash) and C/C++ for hardware/software integration.
  6. Experience standard interfaces (AXI, SPI, UART, JTAG).
  7. Strong analytical and problem-solving skills, with the ability to understand complex software and hardware designs.
  8. Strong documentation skills and the ability to convey complex information clearly and effectively.
  9. Collaborative mindset and excellent communication skills to work effectively with cross-functional teams.
  10. Experience in hardware security and reverse engineering techniques.

Preferred Qualifications

  • Advanced degree (M.S. or Ph.D.) in Electrical Engineering, Computer Engineering, or a related field.
  • Knowledge of cryptographic algorithms and experience implementing mathematical algorithms in hardware or software.
  • Experience in tamper detection and anti-reverse engineering techniques.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91140791
  • Position Id: 8866969
  • Posted 30+ days ago

Company Info

About EndoSec LLC

EndoSec is a leading cryptography and embedded security company focused on developing leading edge technology. Our mission is to be the most innovative, reliable, and cost effective security software, firmware, and services solutions for government agencies, prime contractors, and enterprise; meet customer's future needs and requirements; continue on-going research; and do rapid deployment of updated technology.

To build the best encryption and embedded security product we need the absolute best people on our team. At EndoSec you will be surrounded by a team of smart, dedicated and self motivated engineers.  If you want to join us in making an impact on securing critical technology we look forward to having you as part of the team.

EndoSec Knows Security
EndoSec specializes in products for hardware/software security and cryptography. EndoSec also offers services for security design and AT planning.

EndoSec is Experienced
EndoSec was founded by security professionals with over 100 years of combined experience supplying products and services to the Aerospace and Defense industry.

EndoSec is All American
EndoSec LLC has offices in Washington DC, Virginia, Indiana and North Carolina. We are a 100% US owned and operated company and are a Veteran Owned Small Business. Our employees are US Citizens.

A Message from our President
“As a Veteran, I am well aware of the critical importance of protecting US technologies and systems. Our team’s primary mission is to develop and provide the best cryptographic technologies to keep these products and systems secure.”
— Robert Moriarty

Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

Today

Easy Apply

Full-time

Depends on Experience

Remote

Today

Easy Apply

Full-time

Depends on Experience

Search all similar jobs