Director of Hardware Security

at  Aon Corporation

New York, NY 10006, USA -

Start DateExpiry DateSalaryPosted OnExperienceSkillsTelecommuteSponsor Visa
Immediate10 Sep, 2024USD 180000 Annual10 Jun, 202410 year(s) or aboveAuthentication,Fuzzing,Zigbee,Wireless Protocols,Penetration Testing,Design Review,Qemu,Data Transfer,Encryption,Powerpc,Security Testing,I2C,Power Analysis,X86,EntitlementsNoNo
Add to Wishlist Apply All Jobs
Required Visa Status:
CitizenGC
US CitizenStudent Visa
H1BCPT
OPTH4 Spouse of H1B
GC Green Card
Employment Type:
Full TimePart Time
PermanentIndependent - 1099
Contract – W2C2H Independent
C2H W2Contract – Corp 2 Corp
Contract to Hire – Corp 2 Corp

Description:

Posting Description:
We are currently looking for a highly skilled and experienced Director to build, lead, and grow our Hardware Security service line!
We want technical people leading technical people. This pivotal role involves building a new service line from the ground up, structuring / shaping the client offering, developing methodologies, leading a team of penetration testers, actively collaborating with clients and internal sales teams in the pursuit of new opportunities to grow the service line, and publishing research. The ideal candidate will possess a deep hands-on understanding of hardware and embedded system security, along with strong leadership and project management skills, with the ability to perform hands-on testing and provide detailed mentorship whenever necessary.
Do you possess extensive knowledge in hardware penetration testing, reverse engineering, low-level programming, code review, and fuzzing techniques?

SKILLS AND EXPERIENCE THAT WILL LEAD TO SUCCESS.

  • Three or more years of demonstrated ability with business development, scoping, and client/project management.
  • 10+ years of relevant professional experience performing hardware/embedded security assessments.
  • Experience leading a technical team and collaborating with clients.
  • Strong programming and code review skills in C/C++ and ASM. Experience cross compiling and working in various toolchains.
  • Proficiency reverse engineering firmware
  • Deep understanding of wireless protocols (e.g., Bluetooth, Zigbee)
  • Hands-on experience with JTAG, SWD, UART, I2C, and SPI protocols and expertise in using related tooling.
  • Experience soldering to remove flash chips, attaching test leads, etc. Experience extracting and analyzing firmware from hardware devices. Experience flashing custom firmware.
  • Familiarity with QEMU, unicorn and/or other applications for emulating devices, firmware, and binaries. Experience with methods of tamper-proofing and potential circumvention methods
  • Proficiency in writing custom tooling, as well as working with industry standard applications (e.g., IDA Pro/Ghidra and various debuggers)
  • Knowledge of modern exploitation techniques, including heap shaping and familiarity with other attacks such as side-channel, fault-injection, etc.
  • Familiarity with fuzzing, instrumenting binaries and writing fuzzing harnesses to identify vulnerabilities via custom tooling and/or AFL, libfuzzer, etc.
  • Understanding of security-related topics, such as authentication, entitlements, identity management, data protection, data leakage prevention, validation checking, encryption, hashing, principle of least privilege, software attack methodologies, secure data transfer, and secure data storage

THESE SKILLS/EXPERIENCES ARE A PLUS:

Expertise in side-channel attacks, power analysis, clock glitching, CPLD/FPGA, and RF analysis.
Familiarity with embedded device architectures such as ARM, MIPS, PowerPC, x86, etc. RISC-V and microcontroller experience is a plus.
Sophisticated proficiency in Web Application, Mobile application, and Network penetration testing
Public / published research and/or CVEs related to hardware and embedded device security testing, embedded device, and hardware / security architecture design review.
Industry leading certifications (e.g., OSCE/OSED, OSEE, GIAC GREM, eCRE, CREA, etc.)

HOW WE SUPPORT OUR COLLEAGUES

In addition to our comprehensive benefits package, we encourage a diverse workforce. Plus, our agile, inclusive environment allows you to manage your wellbeing and work/life balance, ensuring you can be your best self at Aon. Furthermore, all colleagues enjoy two “Global Wellbeing Days” each year, encouraging you to take time to focus on yourself. We offer a variety of working style solutions, but we also recognize that flexibility goes beyond just the place of work… and we are all for it. We call this Smart Working!
Our continuous learning culture inspires and equips you to learn, share and grow, helping you achieve your fullest potential. As a result, at Aon, you are more connected, more relevant, and more valued.
Aon values an innovative, diverse workplace where all colleagues feel empowered to be their authentic selves. Aon is proud to be an equal opportunity workplace.
Aon provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, creed, sex, sexual orientation, gender identity, national origin, age, disability, veteran, marital, domestic partner status, or other legally protected status. People with criminal histories are encouraged to apply.
We welcome applications from all and provide individuals with disabilities with reasonable adjustments to participate in the job application, interview process and to perform essential job functions once onboard. If you would like to learn more about the reasonable accommodations we provide, email ReasonableAccommodations@Aon.com
For positions in San Francisco and Los Angeles, we will consider for employment qualified applicants with arrest and conviction record in accordance with local Fair Chance ordinances.
Nothing in this job description restricts management’s right to assign or reassign duties and responsibilities to this job at any time.

Responsibilities:

Please refer the Job description for details


REQUIREMENT SUMMARY

Min:10.0Max:15.0 year(s)

Information Technology/IT

IT Software - Other

Software Engineering

Graduate

Proficient

1

New York, NY 10006, USA