Security Test Engineer
⚲ Katowice
23 520 - 27 720 PLN netto (B2B)
Wymagania
- Python
- Security
- Embedded Systems
Opis stanowiska
Our client is a global technology leader specializing in industrial automation, digital transformation, and smart manufacturing solutions.
We are looking for a Security Test Engineer to join a team responsible for strengthening the security of industrial automation products and systems. In this role, you will contribute to the development and execution of a comprehensive product security validation program, helping ensure the resilience of products against evolving cybersecurity threats.
This position is ideal for a security-focused engineer who enjoys analyzing complex systems, uncovering vulnerabilities, and developing innovative testing approaches for embedded and industrial environments.
Key responsibilities
• Execute white-box and black-box security testing as part of a structured product security validation program.
• Perform security assessments of industrial products and systems, including firmware, communication protocols, and device interfaces.
• Conduct protocol-level testing and validate industrial communication mechanisms.
• Analyze firmware and software binaries to identify security weaknesses, including reverse engineering activities when required.
• Design and execute fuzz testing and negative testing scenarios targeting device interfaces and communication protocols.
• Identify, validate, and document security vulnerabilities, including the creation of proof-of-concept (PoC) exploits when appropriate.
• Perform basic hardware-level security validation, including analysis of debug interfaces and physical access scenarios.
• Analyze test results, triage findings, and support root cause analysis together with development teams.
• Contribute to the development and maintenance of automated security testing frameworks and scripts, primarily in Python.
• Research emerging vulnerabilities, attack techniques, and threat trends relevant to industrial products and environments.
Ideal candidate profile
• Bachelor’s degree in Computer Science or a related field.
• Hands-on experience with programming or scripting languages, preferably Python.
• Solid understanding of computer networking, including configuration and troubleshooting.
• Familiarity with software security testing methodologies, including fuzz testing, negative testing, and white-box/black-box testing.
• English communication skills min. B2
Nice to Have
• Experience with reverse engineering tools such as IDA Pro, Ghidra, or Radare2.
• Knowledge of industrial communication protocols, including Ethernet/IP and CIP.
• Experience testing embedded systems, firmware, or hardware devices.
• Knowledge of security testing tools such as Burp Suite and Wireshark.
Conditions
• Contract type: B2B
• Rate: 140–165 PLN net/hour
• Work model: Hybrid (3 days per week from the office in Katowice)
• Benefits: private medical care, life insurance, Multisport card
Recruitment steps
• Phone call with a Recruiter
• Client interview (may require 2 rounds)
• Feedback and decision
We are looking for a Security Test Engineer to join a team responsible for strengthening the security of industrial automation products and systems. In this role, you will contribute to the development and execution of a comprehensive product security validation program, helping ensure the resilience of products against evolving cybersecurity threats.
This position is ideal for a security-focused engineer who enjoys analyzing complex systems, uncovering vulnerabilities, and developing innovative testing approaches for embedded and industrial environments.
Key responsibilities
• Execute white-box and black-box security testing as part of a structured product security validation program.
• Perform security assessments of industrial products and systems, including firmware, communication protocols, and device interfaces.
• Conduct protocol-level testing and validate industrial communication mechanisms.
• Analyze firmware and software binaries to identify security weaknesses, including reverse engineering activities when required.
• Design and execute fuzz testing and negative testing scenarios targeting device interfaces and communication protocols.
• Identify, validate, and document security vulnerabilities, including the creation of proof-of-concept (PoC) exploits when appropriate.
• Perform basic hardware-level security validation, including analysis of debug interfaces and physical access scenarios.
• Analyze test results, triage findings, and support root cause analysis together with development teams.
• Contribute to the development and maintenance of automated security testing frameworks and scripts, primarily in Python.
• Research emerging vulnerabilities, attack techniques, and threat trends relevant to industrial products and environments.
Ideal candidate profile
• Bachelor’s degree in Computer Science or a related field.
• Hands-on experience with programming or scripting languages, preferably Python.
• Solid understanding of computer networking, including configuration and troubleshooting.
• Familiarity with software security testing methodologies, including fuzz testing, negative testing, and white-box/black-box testing.
• English communication skills min. B2
Nice to Have
• Experience with reverse engineering tools such as IDA Pro, Ghidra, or Radare2.
• Knowledge of industrial communication protocols, including Ethernet/IP and CIP.
• Experience testing embedded systems, firmware, or hardware devices.
• Knowledge of security testing tools such as Burp Suite and Wireshark.
Conditions
• Contract type: B2B
• Rate: 140–165 PLN net/hour
• Work model: Hybrid (3 days per week from the office in Katowice)
• Benefits: private medical care, life insurance, Multisport card
Recruitment steps
• Phone call with a Recruiter
• Client interview (may require 2 rounds)
• Feedback and decision
🔍 Dekoder Ogłoszenia
🔴
developing innovative testing approaches for embedded and industrial environments
Może oznaczać potrzebę tworzenia niestandardowych narzędzi i metodologii, ponieważ standardowe rozwiązania mogą być niewystarczające dla specyfiki systemów przemysłowych.
🔴
reverse engineering activities when required
Oznacza, że będziesz musiał analizować kod bez dostępu do jego źródła, co wymaga specyficznych umiejętności i może być czasochłonne.
🔴
basic hardware-level security validation
Sugeruje, że zakres testów sprzętowych może być ograniczony i nie obejmować zaawansowanych analiz fizycznych czy ataków sprzętowych.