Back to search
Stealth Linkedin · Posted 5d ago

Wireless Security Research Engineer

Copenhagen

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

About the role

We are building resilient, adversarial-ready wireless infrastructure for constrained IoT and edge devices. This role sits at the intersection of offensive research and defensive engineering. You will operate across low-power, long-range radio stacks—such as mioty, LoRa-class systems, and other proprietary LPWAN variants—to break real-world deployments and subsequently harden them. We are looking for an individual who can comfortably live on both sides of the fence: identifying vulnerabilities through authorized research and implementing concrete, shippable mitigations.


What you’ll do
  • Threat-model IoT radio systems across the entire stack, from PHY to MAC to application.
  • Reverse-engineer firmware, radio configurations, and packet formats to identify undocumented behaviors.
  • Build Proof-of-Concepts for jamming, spoofing, replay, desync, and side-channel style attacks in authorized lab environments.
  • Assess gateways, endpoints, pairing/join flows, and backend trust assumptions.
  • Propose and implement protocol-level mitigations including authentication, anti-replay, key rotation, and diversity strategies.
  • Design resilient architectures capable of graceful degradation, hostile RF detection, and multi-path fallbacks.
  • Collaborate with firmware and backend teams to ship defenses that respect real-world constraints such as power, latency, and cost.
  • Mentor the team on the attacker mindset to elevate overall system design and security posture.


What we’re looking for

Must-have

  • Experience building and designing custom communication protocols or robust firmware architectures, balancing security with functional constraints.
  • Hands-on experience attacking or deeply analyzing wireless/IoT protocols (beyond standard web/app pentesting).
  • Ability to read RF/protocol documentation and synthesize findings from packet captures when documentation is incomplete.
  • Proficiency in embedded systems including C/C++, firmware debugging, and hardware analysis (serial/JTAG/SWD, logic analyzers).
  • Strong cryptography foundations specific to constrained devices and the realities of production implementation.
  • Proven track record of both finding security weaknesses and proposing actionable engineering fixes.
  • Clear written communication skills for documenting attack paths, risk rankings, and engineering recommendations.


Nice-to-have

  • Experience shipping production firmware or radio-enabled products.
  • Red-team or purple-team experience with strong ethical and scoping discipline.
  • Familiarity with SDR platforms (GNU Radio, HackRF, etc.) and PHY-level analysis (CSS, UNB, FHSS, Doppler/jamming effects).
  • Background in gateway and network-server security (PKI, join servers, multi-tenant backends).
  • Hardware security expertise, including bootloaders, secure elements, and side-channel analysis.


How we work
  • All offensive research is strictly authorized, scoped, and documented.
  • We prioritize real-world resilience under hostile network conditions over checkbox compliance.
  • We value creative solutions for imperfect radios and legacy constraints; we bridge the gap between "this breaks" and "here is the fix."


If you have ever identified a flaw in an LPWAN join flow, sketched out the attack, and designed a survival strategy, we want to talk. Please share a summary of a wireless or embedded system you broke, what you learned, and how you would rebuild.

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search