Hardware Ethical Hacker positions focus on delivering results in their domain. This page aggregates open Hardware Ethical Hacker roles and what employers typically expect.
Packetlabs is a cybersecurity consulting firm specializing in advanced Penetration Testing. We exist to eliminate the false sense of security that comes from shallow testing and checkbox-driven assessments. Our slogan, "Ready for more than a VA scan?", reflects a simple standard: real security work should be rigorous, manual, and built to uncover what automated approaches miss. Our clients span government, technology, law enforcement, retail, healthcare, and financial services, and they rely on us because credibility matters when the stakes are high. Packetlabs is looking for an Ethical Hacker - Hardware to lead security assessments of embedded and IoT devices, the physical products where a vulnerability lives in silicon, firmware, and board layout, rather than in a web request. The Ethical Hacker - Hardware is a specialized technical role focused on assessing embedded systems across all industries, from consumer IoT to industrial and connected devices. This role involves getting hands-on with a device, opening it up, and proving what an attacker with physical or local access can really do. This role requires the rare combination of offensive security instinct and genuine hardware fundamentals. You will work directly with clients to understand their devices and deliver findings that improve security posture. **Who we are looking for** - No egos, ever. Egos don't belong at Packetlabs. The more you learn, the less you know. You stay humble, ask questions, and work to help clients improve their security. - Customer-first mentality. You are an excellent communicator with clients, project managers, and teammates. You are responsive, reliable, and professional throughout every engagement. - You deliver work that you take pride in. Your work is an autograph of your excellence. You hold yourself to a high standard, and it shows in what you produce. - Digs deeper into every finding. You don't stop until impact is proven, while understanding that restraint is the right call in sensitive OT environments where high-risk activity is not appropriate. - Comfortable being uncomfortable. You move toward obstacles, not away from them. Consulting is not a typical job and requires adapting to rapidly changing environments. - Always learning. Cybersecurity changes every day, and you keep up because you want to. You are deeply aware of your skillset and committed to improving it. - Self-motivated and dependable. You take ownership of your work and your outcomes without needing to be managed into them. **What you’ll be doing** - **Hardware Penetration Testing** - - Plan and execute end-to-end hardware penetration tests on embedded and IoT devices, against a defined scope and rules of engagement - Identify, access, and exploit on-board debug interfaces: JTAG, SWD, UART, and similar, to gain code execution or memory access - Extract firmware via debug ports, in-circuit flash reads (SPI / I2C / NAND), or chip-off when required, and analyze it for vulnerabilities - Intercept and analyze data on common embedded buses (SPI, I2C, UART, CAN, USB) using logic analyzers and protocol decoders - Where in scope, perform side-channel analysis and fault injection (power analysis, voltage/clock glitching) to bypass secure boot, readout protection, or authentication - **Firmware Analysis & Reverse Engineering** - - Reverse engineer firmware and embedded binaries (Ghidra, IDA, Binwalk, etc.) to find logic flaws, hardcoded secrets, and exploitable conditions - Assess physical attack surface, tamper resistance, and key/secret storage - Distinguish between theoretical and operationally relevant risk to keep findings actionable - **Client Advisory & Remediation** - - Write high-quality technical reports and present findings to client stakeholders, both technical and non-technical - Advise on practical, prioritized remediation that clients can act on - Build client confidence through credibility, clear communication, and proven impact - **Methodology, Research & Continuo…