Senior Security Consultant (Hardware)
NCC Group
Waterloo, ON
2d ago

We are looking for security-focused engineers and researchers to join our security consulting practice in Waterloo, Ontario, Canada.

Job duties will include code review, penetration testing, security analysis, reverse engineering, and cutting-edge research into current technologies and attacks.

Responsibilities :

A Senior Security Consultant (SSC) must have the experience, technical skill, consulting finesse, and management skills required to deliver a broad variety of technically demanding projects.

This role may be appropriate for new hires with extensive security consulting experience or those who can immediately contribute at a senior level, but generally those with this role have a long history of effectively delivering software or hardware security projects.

SSCs are expected to act as Technical Lead on most projects and to focus on developing skills needed to continue deliver high-quality projects, help colleagues at NCC through the act of mentoring, and also exhibiting technical prowess via research and tool development that extends NCC’s abilities.

We are a consultancy and so, when necessary, our work is sometimes performed on the clients’ site. That being said, we’re always working with clients to deliver remote work whenever possible.

We also proactively monitor travel so that no one spends too much time on the road. By and large, we are a company run by security consultants, and we have no interest in burning ourselves out.

Our Culture :

NCC Group has a casual culture, with people from diverse backgrounds who eat, drink and breathe security. We’re a social group and our various offices organize outings and events that are quite popular.

We also host an annual conference for our consultants (usually somewhere warm during the cold winter months), where you can catch up with your peers and see the cool research that your friends have been working on.

For the most part, we’ll want you to come into the office, but we do offer the flexibility to occasionally work from home on days when coming into the office is inconvenient (life happens!).

Research :

Research is at the foundation of NCC Group and the work that we do. We speak at top-tier security conferences all over the world.

All of our consultants receive time and resources to support their research endeavours. Research is rewarded with substantial bonuses for speaking at conferences, writing whitepapers, and creating tools.

Additionally, in your downtime between customer engagements, you can broaden your security skills by working through one of NCC Group’s numerous internal training programs.

Required Experience / Skills :

The following qualifications and experience are important for being successful in this role.

  • Bachelor’s program in Computer Science, Engineering, or equivalent.
  • Minimum of 2 years of experience working in software or hardware security.
  • Minimum of 2 years of experience in delivering technical results or solutions.
  • We expect that a Senior Security Consultant will demonstrate in-depth experience in 4+ areas of technical competency. The following technical skills and experience are important for being successful in this role.

  • Experience auditing driver code for the Windows and / or Linux operating systems.
  • Basic familiarity with firmware reverse engineering.
  • Able to read schematics.
  • Good understanding of common embedded system architectures and design patterns.
  • Able to perform security-focused code review in 2+ languages (particularly C / C++)
  • Able to guide clients through secure design methodologies such as threat modelling, and attack surface enumeration
  • Web application and web service testing
  • Network infrastructure penetration testing
  • Mobile application security testing (Android and iOS)
  • Desired Experience / Skills :

    Although the following skills are not mandatory, they will certainly help your application get our attention :

  • Familiarity with cryptography
  • Detailed knowledge of bootloaders, operating systems and drivers.
  • Ability to perform black-box reverse engineering
  • Familiarity with secure boot architectures.
  • Knowledge of ARM or x86 architectures.
  • Experience with SDR and wireless protocols (Bluetooth, ZigBee, Cellular, Wi-Fi).
  • Personal Qualities :

  • Excellent spoken and written communication skills, because being able to explain a vulnerability is just as important as being able to find it!
  • Able to act as Technical Lead on large multi-faceted projects
  • High-level of professionalism
  • Outstanding attention to detail
  • Self-motivated and a demonstrated self-starter
  • Highly dependable
  • Willingness to travel
  • Report this job

    Thank you for reporting this job!

    Your feedback will help us improve the quality of our services.

    My Email
    By clicking on "Continue", I give neuvoo consent to process my data and to send me email alerts, as detailed in neuvoo's Privacy Policy . I may withdraw my consent or unsubscribe at any time.
    Application form