Wireless Security Research Engineer
Indexed description
We are building resilient, adversarial-ready wireless infrastructure for constrained IoT and edge devices. This role sits at the intersection of offensive research and defensive engineering. You will operate across low-power, long-range radio stacks—such as mioty, LoRa-class systems, and other proprietary LPWAN variants—to break real-world deployments and subsequently harden them. We are looking for an individual who can comfortably live on both sides of the fence: identifying vulnerabilities through authorized research and implementing concrete, shippable mitigations.
- Threat-model IoT radio systems across the entire stack, from PHY to MAC to application.
- Reverse-engineer firmware, radio configurations, and packet formats to identify undocumented behaviors.
- Build Proof-of-Concepts for jamming, spoofing, replay, desync, and side-channel style attacks in authorized lab environments.
- Assess gateways, endpoints, pairing/join flows, and backend trust assumptions.
- Propose and implement protocol-level mitigations including authentication, anti-replay, key rotation, and diversity strategies.
- Design resilient architectures capable of graceful degradation, hostile RF detection, and multi-path fallbacks.
- Collaborate with firmware and backend teams to ship defenses that respect real-world constraints such as power, latency, and cost.
- Mentor the team on the attacker mindset to elevate overall system design and security posture.
Must-have
- Experience building and designing custom communication protocols or robust firmware architectures, balancing security with functional constraints.
- Hands-on experience attacking or deeply analyzing wireless/IoT protocols (beyond standard web/app pentesting).
- Ability to read RF/protocol documentation and synthesize findings from packet captures when documentation is incomplete.
- Proficiency in embedded systems including C/C++, firmware debugging, and hardware analysis (serial/JTAG/SWD, logic analyzers).
- Strong cryptography foundations specific to constrained devices and the realities of production implementation.
- Proven track record of both finding security weaknesses and proposing actionable engineering fixes.
- Clear written communication skills for documenting attack paths, risk rankings, and engineering recommendations.
Nice-to-have
- Experience shipping production firmware or radio-enabled products.
- Red-team or purple-team experience with strong ethical and scoping discipline.
- Familiarity with SDR platforms (GNU Radio, HackRF, etc.) and PHY-level analysis (CSS, UNB, FHSS, Doppler/jamming effects).
- Background in gateway and network-server security (PKI, join servers, multi-tenant backends).
- Hardware security expertise, including bootloaders, secure elements, and side-channel analysis.
- All offensive research is strictly authorized, scoped, and documented.
- We prioritize real-world resilience under hostile network conditions over checkbox compliance.
- We value creative solutions for imperfect radios and legacy constraints; we bridge the gap between "this breaks" and "here is the fix."
If you have ever identified a flaw in an LPWAN join flow, sketched out the attack, and designed a survival strategy, we want to talk. Please share a summary of a wireless or embedded system you broke, what you learned, and how you would rebuild.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search