yandex
A
alarmcom
Страна
США
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
SeniorГибридПолная занятость

Staff Security Engineer

ИИОценка ИИ

Престижная компания в быстрорастущем секторе IoT с сильной инженерной культурой. Предлагается работа над сложными задачами и хороший пакет льгот, однако требование присутствия в офисе 4 дня в неделю может быть минусом для некоторых кандидатов.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
ИИОценка ИИ

Роль требует исключительного сочетания навыков: от глубокого реверс-инжиниринга прошивок до работы с аппаратными интерфейсами (JTAG, UART) и 10-летнего опыта в ИБ. Высокая планка ответственности за безопасность миллионов IoT-устройств делает эту позицию крайне сложной.

Анализ зарплаты

Медиана195 000 $
Рынок170 000 $ – 230 000 $
ИИОценка ИИ

Зарплата в объявлении не указана, но для позиции уровня Staff Security Engineer в Вирджинии (район Тайсонс/Вашингтон) рыночные показатели весьма высоки. Учитывая требования к 10+ годам опыта и узкую специализацию в IoT, компенсация должна находиться в верхнем сегменте рынка.

Сопроводительное письмо

I am writing to express my strong interest in the Staff Security Engineer position at Alarm.com. With over a decade of experience in offensive security and a deep specialization in IoT and embedded systems, I am confident in my ability to enhance the security posture of your intelligently connected property platform. My background in firmware reverse engineering using tools like IDA Pro and Ghidra, combined with hands-on experience with hardware protocols such as JTAG and UART, aligns perfectly with the technical requirements of this role.

Throughout my career, I have successfully identified and mitigated critical vulnerabilities in complex hardware-software ecosystems. I am particularly drawn to Alarm.com's commitment to 'serious security' and your collaborative culture. I look forward to the opportunity to bring my analytical mindset and passion for vulnerability research to your team, ensuring that your millions of users remain protected against evolving threats.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в alarmcom уже сейчас

Присоединяйтесь к лидерам рынка IoT и защитите миллионы умных домов по всему миру!

Описание вакансии

The Staff Security Engineer will identify security risks within our IoT device ecosystem, communicate those risks to management, and assist with the mitigation efforts.  This role requires hands-on experience with reverse engineering, networking, operating systems, and programming. The ideal engineer will bring these skills to bear on complex IoT security challenges. The Senior Security Engineer will also document security policies and procedures and ensure they remain up to date with applicable industry standards and compliance requirements.

Responsibilities:

The Staff Security Engineer primary job responsibilities include:

  • Perform IoT penetration testing, including firmware extraction, reverse engineering, and vulnerability discovery
  • Perform security research, analysis, and testing via threat modeling, vulnerability assessment, penetration testing, and/or social engineering across a wide variety of applications, platforms and systems
  • Use a combination of manual and automated techniques to assess risks and circumvent security mechanisms of devices and application
  • Oversee and manage the deployment, integration, and configuration of security solutions and enhancements to existing IoT infrastructure and the enterprise’s security documents
  • Select and acquire additional security solutions or enhancements to existing security solutions to improve overall IoT enterprise security
  • Clearly outline and document risk impacts of test findings in reports
  • Test, triage, and drive remediation of security issues reported by external parties
  • Actively partner with infrastructure, application, product, and other stakeholders to ensure deployed solutions minimize security and privacy risks
  • Other duties as assigned

REQUIREMENTS

  • B.A. or B.S. (or higher) in Computer Science, Electrical Engineering, or a related engineering program with strong academic performance preferred
  • 10+ years of information security experience, with a strong focus on offensive security, penetration testing, or vulnerability research
  • Prior experience performing security testing and assessment in IoT, embedded, or firmware based environments
  • Working knowledge of embedded system design and constraints (development experience a plus, but not required)
  • Familiarity with using hardware debugging equipment such as oscilloscopes, logic analyzer and other tools
  • Familiarity with interface protocols such as UART, I2C, SPI, JTAG, and related tooling.
  • Experience analyzing embedded Linux systems and firmware images.
  • Familiarity with ARM CPU architectures with exposure to x86, RISC-V, or others as a plus
  • Experience with reverse-engineering tools such as IDA Pro, Ghidra, and/or Binary Ninja
  • Certification in one or more Information Security disciplines is preferred or ability to obtain certifications.
  • Self-starter, analytical, tenacious problem solver
  • Strong verbal and written communication skills for a highly collaborative environment
  • Rigorous attention to detail and focus on quality of deliverables
  • Proven team experience and comfort in a team-oriented environment
  • Passion for working with technology and excitement for creating high quality consumer technology product

If you feel like you don’t meet all the requirements for this role, we encourage you to apply. We don’t want a few of them to get in the way of meeting a great candidate like you!

Please note that sponsorship of new applicants for employment authorization, or any other immigration-related support, is not available for this position at this time.

WHY WORK FOR ALARM.COM?

  • Collaborate with outstanding people: We hire only the best. Our standards are high and our employees enjoy working alongside other high achievers.
  • Make an immediate impact: New employees can expect to be given real responsibility for bringing new technologies to the marketplace. You are empowered to perform as soon as you join the Alarm.com team!
  • Gain well rounded experience: Alarm.com offers a diverse and dynamic environment where you will get the chance to work directly with executives and develop expertise across multiple areas of the business.
  • Community and Camaraderie: One of our core values is to 'Keep It Fun,' which to us means fostering a strong sense of community. Our culture is built on collaboration and connection, where we celebrate our successes and believe that a positive, engaging environment is key to doing our best work.
  • Alarm.com values working together and collaborating in person. Our employees work from the office 4 days a week.

COMPANY INFO

Alarm.com is the leading platform for intelligently connected properties. Millions of homeowners and businesses rely on Alarm.com's technology to secure, monitor, and manage their environments from anywhere. Our comprehensive suite of solutions—including security, video surveillance, access control, active shooter detection, intelligent automation, energy management, and wellness—is delivered exclusively through a trusted network of thousands of professional service providers and commercial integrators across North America and worldwide. Alarm.com's common stock is traded on Nasdaq under the ticker symbol ALRM. Alarm.com delivers serious security for serious people.

For more information, please visit www.alarm.com.

COMPANY BENEFITS

Our total rewards package is designed to support you holistically—in your health, your finances, and your life outside of work. The package includes medical plans with company subsidies, a Health Savings Account (HSA) with a company contribution, and a 401(k) with an employer match. We encourage a healthy work-life balance with paid vacation that increases with tenure, paid holidays, wellness time, and paid maternity and bonding leave. To complete the package, we also provide company-paid disability and life insurance, all within a collaborative and casual work environment.

Alarm.com is an Equal Opportunity Employer

In connection with your application, we collect information that identifies, reasonably relates to or describes you ("Personal Information"). The categories of Personal Information that we may collect include your name, government-issued identification number(s), email address, mailing address, other contact information, emergency contact information, employment history, educational history, criminal record, and demographic information. We collect and use those categories of Personal Information about you for human resources and other business management purposes, including identifying and evaluating you as a candidate for potential or future employment or future positions, recordkeeping in relation to recruiting and hiring, conducting criminal background checks as permitted by law, conducting analytics, and ensuring compliance with applicable legal requirements and Company policies. By submitting your application, you acknowledge that we may retain some of the personal data that you provide in your application for our internal operations such as managing our recruitment system and ensuring that we comply with labor laws and regulations even after we have made our employment decision.

Notice To Third Party Agencies:

Alarm.com understands the value of professional recruiting services. However, we are not accepting resumes from recruiters or employment agencies for this position. In the event we receive a resume or candidate referral for this position from a third-party recruiter or agency without a previously signed agreement, we reserve the right to pursue and hire those candidate(s) without any financial obligation to you. If you are interested in working with Alarm.com, please email your company information and standard agreement to RecruitingPartnerships@Alarm.com.

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • Threat Modeling
  • SPI
  • I2C
  • UART
  • IDA Pro
  • Ghidra
  • Reverse Engineering
  • Penetration Testing
  • Vulnerability Research
  • ARM Architecture
  • Embedded Linux
  • JTAG
  • IoT Security
  • Firmware Analysis
  • Binary Ninja

Возможные вопросы на собеседовании

Проверка практических навыков работы с оборудованием и понимания низкоуровневых интерфейсов.

Опишите ваш процесс поиска точек входа на незнакомой печатной плате (PCB) для извлечения прошивки через UART или JTAG.

Оценка опыта в реверс-инжиниринге и владении специализированным ПО.

Расскажите о самом сложном случае реверса бинарного файла, с которым вы сталкивались. Какие инструменты (IDA Pro, Ghidra) и методы деобфускации вы использовали?

IoT-устройства часто имеют специфические векторы атак.

Какие основные риски безопасности вы видите в архитектуре современных умных домов и как бы вы организовали процесс Threat Modeling для нового датчика?

Проверка умения работать с Linux на уровне ядра и драйверов.

С какими типичными уязвимостями в кастомных сборках Embedded Linux вы сталкивались чаще всего и как предлагали их устранять?

Позиция Staff подразумевает лидерство и взаимодействие с другими отделами.

Как вы доносите критические риски безопасности до продуктовых команд, которые сфокусированы на скорости выпуска фич, а не на защищенности?

Похожие вакансии

OS
Omega Solutions
280 000 ₽ – 300 000 ₽

Senior Information Security Specialist

SeniorУдалённо
Information Security · Cyber Risk Management · FAIR · NIST · ISO 27001 · CISSP · CISM · CRISCBase · SQL · Power BI · Tableau · GRC · Threat Intelligence · Vulnerability Management · PCI DSS · GDPR
+16 навыков
H
HuntTech
225 000 ₽ – 285 000 ₽

ИБ-специалист (Middle+ / Senior)

SeniorУдалённо
Information Security · FSTEC · ISO 27001 · NIST · Risk Assessment · Compliance · Technical Writing
+7 навыков
А
Альфа-Банк
Не указана

Старший эксперт по контролю защищенности

SeniorУдалённо
Nessus · Qualys · Max Patrol 8 · RedCheck · Rapid7 · OWASP Top 10 · Kali Linux · Metasploit · Burp Suite · Nuclei · Windows · Linux · Active Directory · DNS · DHCP · Terminal Services · Python · Bash
+18 навыков
NDA
Не указана

ИБ-специалист Middle+ / Senior

SeniorУдалённо
Cybersecurity · Information Security · FSTEC · ISO 27001 · NIST · CISSP · CISM · Risk Assessment
+8 навыков
BA
Breef Agency
450 000 ₽ – 508 000 ₽

Senior Application Security Engineer

SeniorУдалённо
SAST · DAST · SCA · Secret Detection · CI/CD · SSDLC · Application Security
+7 навыков
J
JETLYN
210 000 ₽ – 260 000 ₽

Специалист по защите информации (Mobile Security Engineer)

SeniorУдалённо
iOS · Cryptography · Jailbreak · HTTPS · REST API · gRPC · TCP · UDP · HTTP · Protobuf · JSON · Avro · MessagePack · Reverse Engineering
+14 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

A
alarmcom
Страна
США