Hardware penetration tester assessing embedded and IoT devices for Packetlabs, a Canadian cybersecurity consultancy.
Reverse engineering firmware, exploiting hardware interfaces, and advising clients on practical remediation.
Responsibilities
Plan and execute end-to-end hardware penetration tests on embedded and IoT devices against defined scope and rules of engagement
Identify, access, and exploit on-board debug interfaces such as JTAG, SWD, and UART
Extract firmware through debug ports, in-circuit flash reads, or chip-off and analyze it for vulnerabilities
Intercept and analyze embedded buses including SPI, I2C, UART, CAN, and USB
Perform side-channel analysis and fault injection where in scope
Reverse engineer firmware and embedded binaries to identify logic flaws, hardcoded secrets, and exploitable conditions
Assess physical attack surfaces, tamper resistance, and key/secret storage
Distinguish theoretical from operationally relevant risk
Write technical reports and present findings to technical and non-technical client stakeholders
Advise clients on practical, prioritized remediation
Build and maintain lab tooling, test rigs, and internal methodology
Contribute to research, responsible disclosure, and internal knowledge-sharing
Stay current on hardware attack techniques, embedded architectures, and defensive controls
Help raise the standard of hardware security work across the firm
Requirements
Graduate of an Information Security, Computer Science, or Computer/Electrical Engineering degree program, or equivalent hands-on experience
Strong electronics fundamentals, including ability to read schematics and datasheets
Hands-on soldering ability, including surface-mount rework and basic chip removal
Demonstrated experience accessing JTAG, SWD, UART, and similar debug interfaces
Experience extracting firmware from real devices
Comfort using logic analyzers, oscilloscopes, and multimeters
Firmware reverse-engineering skills
Scripting proficiency in Python and enough C to read embedded code
Familiarity with ARM/Cortex-M, MIPS, AVR, and RISC-V architectures
Familiarity with RTOS and bare-metal concepts
Clear written and verbal communication
Ability to work with clients, project managers, and teammates
Side-channel or fault-injection experience, RF/wireless work, secure boot/TEE/secure element/HSM knowledge, PCB design familiarity, published CVEs, conference talks, CTF placements, open-source tooling, and relevant certifications are assets
Benefits
Immediate and ongoing offensive security training, mentorship, and professional development
Competitive compensation and growth opportunity
Flexible work environment
Opportunity to shape the growth, direction, and methodology of Packetlabs' expanding hardware practice
Collaboration with a highly skilled team of security professionals
Quality Assurance Analyst reviewing Canadian mortgage files for nesto, a mortgage technology and financing company. Detecting fraud, supporting audits, and advising underwriting teams on credit and property risks.
Quality Assurance Analyst reviewing Canadian mortgage applications for compliance, fraud, and underwriting risks. Supporting audits and advising nesto’s mortgage technology and financing business.
Senior QA Analyst testing payment APIs, distributed systems, and Kafka event flows for Expleo, a global engineering and consulting organization. Designing automation and validating end - to - end transaction quality in a hybrid Montreal role.
Développeur QA Salesforce automatisant les tests pour nesto, entreprise canadienne de financement hypothécaire. Concevant des scripts Playwright, administrant les environnements Salesforce et soutenant les processus QA et CI/CD.
Quality Assurance Technician supporting Hydro Tech’s hydro - electric projects and quality management system. Performing dimensional inspections, QA/QC testing, documentation, and quality control in the field.
QA Engineer testing Computrition’s web and desktop foodservice and nutrition applications remotely in Canada. Building manual and automated quality processes across Agile development and cloud deployment pipelines.
Senior QA Engineer building iOS and Android automation for Trust Wallet, a non - custodial cryptocurrency wallet. Owning TypeScript frameworks, GitHub Actions quality gates, and mobile test reliability.