Director of Hardware Security

Aon
Seattle, Washington, US
Full-time
We are sorry. The job offer you are looking for is no longer available.

We are currently looking for a highly skilled and experienced Director to build, lead, and grow our Hardware Security service line!

Increase your chances of an interview by reading the following overview of this role before making an application.

We want technical people leading technical people. This pivotal role involves building a new service line from the ground up, structuring / shaping the client offering, developing methodologies, leading a team of penetration testers, actively collaborating with clients and internal sales teams in the pursuit of new opportunities to grow the service line, and publishing research.

The ideal candidate will possess a deep hands-on understanding of hardware and embedded system security, along with strong leadership and project management skills, with the ability to perform hands-on testing and provide detailed mentorship whenever necessary.

Do you possess extensive knowledge in hardware penetration testing, reverse engineering, low-level programming, code review, and fuzzing techniques?

What the day will look like

  • Develop and implement a strategic plan for the hardware and embedded penetration test service line, including helping to define the service offering.
  • Lead the development of internal methodologies, checklists, and marketing collateral to support the growth of the hardware penetration testing and reverse engineering service line.
  • Work closely with Business Development teams and new prospective customers to close new deals.
  • Build statement of work / proposals for clients that define scope of work, duration, deliverables, and pricing.
  • Oversee technical delivery of engagements relating to the business. Provide quality assurance and technical review of client work and internal documentation.
  • Work alongside various internal teams (e.g., operations, finance, delivery, technical) to ensure overall success of client engagement.

Form a team of hardware and embedded penetration testers through recruiting and mentorship.

Cross-train team members within the practice.

Skills and experience that will lead to success.

  • Three or more years of demonstrated ability with business development, scoping, and client / project management.
  • 10+ years of relevant professional experience performing hardware / embedded security assessments.
  • Experience leading a technical team and collaborating with clients.
  • Strong programming and code review skills in C / C++ and ASM. Experience cross compiling and working in various toolchains.
  • Proficiency in reverse engineering firmware.
  • Deep understanding of wireless protocols (e.g., Bluetooth, Zigbee).
  • Hands-on experience with JTAG, SWD, UART, I2C, and SPI protocols and expertise in using related tooling.
  • Experience soldering to remove flash chips, attaching test leads, etc. Experience extracting and analyzing firmware from hardware devices.

Experience flashing custom firmware.

  • Familiarity with QEMU, unicorn and / or other applications for emulating devices, firmware, and binaries.
  • Proficiency in writing custom tooling, as well as working with industry standard applications (e.g., IDA Pro / Ghidra and various debuggers).
  • Knowledge of modern exploitation techniques, including heap shaping and familiarity with other attacks such as side-channel, fault-injection, etc.
  • Familiarity with fuzzing, instrumenting binaries and writing fuzzing harnesses to identify vulnerabilities via custom tooling and / or AFL, libfuzzer, etc.
  • Understanding of security-related topics, such as authentication, entitlements, identity management, data protection, data leakage prevention, validation checking, encryption, hashing, principle of least privilege, software attack methodologies, secure data transfer, and secure data storage.

These skills / experiences are a plus :

  • Expertise in side-channel attacks, power analysis, clock glitching, CPLD / FPGA, and RF analysis.
  • Familiarity with embedded device architectures such as ARM, MIPS, PowerPC, x86, etc. RISC-V and microcontroller experience is a plus.
  • Sophisticated proficiency in Web Application, Mobile application, and Network penetration testing.
  • Public / published research and / or CVEs related to hardware and embedded device security testing, embedded device, and hardware / security architecture design review.
  • Industry leading certifications (e.g., OSCE / OSED, OSEE, GIAC GREM, eCRE, CREA, etc.)

How we support our colleagues

In addition to our comprehensive benefits package, we encourage a diverse workforce. Plus, our agile, inclusive environment allows you to manage your wellbeing and work / life balance, ensuring you can be your best self at Aon.

Aon values an innovative, diverse workplace where all colleagues feel empowered to be their authentic selves. Aon is proud to be an equal opportunity workplace.

J-18808-Ljbffr

6 days ago
Related jobs
Promoted
Aon
Seattle, Washington

Aon offers a comprehensive package of benefits for full-time and regular part-time colleagues, including, but not limited to: a 401(k) savings plan with employer contributions; an employee stock purchase plan; consideration for long-term incentive awards at Aon's discretion; medical, dental and visi...

Promoted
VirtualVocations
Seattle, Washington

A company is looking for a Senior Director of Information Security/CISO. ...

Promoted
MongoDB
Seattle, Washington

The MongoDB Security organization is a diverse collection of individuals working together to scale MongoDB's security, both security of the products themselves and the security features we offer to customers. Uses software architecture and coding patterns to reduce the impact of security issues. Com...

Promoted
VirtualVocations
Seattle, Washington

A company is looking for a Senior Director, Security & Compliance. ...

MongoDB
Seattle, Washington

The MongoDB Security organization is a diverse collection of individuals working together to scale MongoDB’s security, both security of the products themselves and the security features we offer to customers. Uses software architecture and coding patterns to reduce the impact of security issues. Mon...

Promoted
VirtualVocations
Seattle, Washington

A company is looking for a Director of Security in the G&A department. ...

University of Washington
Seattle, Washington

Advanced training or experience with technical elements including physical security systems; security dispatch operations; security protocols and training; and team supervision. UW Medicine’s mission is to improve the health of the public by advancing medical knowledge, providing outstanding primary...

Securitas
SeaTac, Washington

Prepares and coordinates staffing schedules for account, in collaboration with line management as necessary; acts to ensure that scheduling is handled effectively to meet client requirements while controlling labor costs; reviews Security Officer site reports to verify post orders and client directi...

JPMorgan Chase Bank, N.A.
Seattle, Washington

In addition, 5+ years of experience leading technologists to manage, anticipate and solve complex technical items within your domain of expertise * Experience running teams of engineers that deliver security solutions operations on cloud-based platforms and applications * Experie...

Marriott International
Seattle, Washington

Areas of responsibilities include protection of property assets, employees, guests and property, accident and fire prevention and response. High school diploma or GED; 4 years experience in the security/loss prevention or related professional area. Criminal Justice or related major; 2 years experien...