Role Description
Festo is establishing a Product Security Testing team in India, and we are looking for highly motivated Product Security Engineers with experience in security testing, particularly in the domain of Embedded and IoT products.
We seek enthusiastic, young, and talented Product Security Specialist who are passionate about working with industrial devices, identifying security vulnerabilities, and helping the team validate fixes. As a Product Security Engineer, you will collaborate with your teammates in the product security testing team on various products across the organization to ensure that all Festo products are cyber security compliant and free from vulnerabilities.
Your Responsibilities
- Perform hardware and firmware security testing, including Hardware VAPT, TARA analysis, and penetration testing for embedded and IoT products
- Conduct reverse engineering of firmware, binaries, and hardware components to identify vulnerabilities and weaknesses
- Execute fuzzing tests (black-box, white-box, and grey-box) on device protocols, firmware, and communication interfaces
- Perform vulnerability assessments using tools such as Nessus, OpenVAS, Nmap, and Wireshark
- Document findings, prepare detailed test reports, and collaborate closely with development teams to validate and resolve vulnerabilities
- Support test automation within CI / CD environments to streamline security testing workflows
Our Requirements
Bachelor’s degree in Engineering, Computer Science, Cyber Security, or a related technical fieldMinimum of two years of experience in device or embedded security testing, preferably within the Industrial Automation or Automotive sectorsHands-on expertise in hardware penetration testing, firmware analysis, reverse engineering, and fuzzing methodologiesExperience in Hardware and Thick Client pentesting methodologiesStrong understanding of embedded systems, Linux environments, and communication protocols (industrial and automotive)Knowledge of Secure Development Lifecycle and familiarity with IEC 62443-4 or equivalent standardsProficiency with tools such as Nessus, OpenVAS, Nmap, Wireshark, Burp Suite, Ghidra, IDA Pro, and other security testing utilitiesProgramming experience in C / C++, Python, or Shell scripting, with exposure to CI / CD tools and automation frameworksProficient in using security testing tools and frameworks for embedded systems, firmware, and network protocolsAnalytical, detail-oriented, collaborative, and proactive in identifying and addressing vulnerabilitiesOSCP, CRTP, CRTO, eWPTX, CPENT, LPT, PNPT, or equivalent industry-recognized credentialsExcellent written and spoken English communication skillsJob Location : Bengaluru, India
Job Type : Full-time | Hybrid
Experience : 2 years