Full-Time

Hardware Penetration Tester

Python, Firmware Extraction

Posted on 9/10/2025

Cisco

Cisco

10,001+ employees

Networking hardware, security software, collaboration services

No salary listed

Bengaluru, Karnataka, India

In Person

Category
Software Engineering (2)
,
Required Skills
Bash
Python
Machine Learning
C/C++
Requirements
  • A security-focused mindset with genuine passion for penetration testing and vulnerability research
  • Familiarity with firmware extraction techniques and methodologies
  • Strong understanding of embedded hardware interfaces and protocols
  • Expertise in conducting JTAG, UART, and SPI-based testing
  • Ability to identify and bypass hardware security mechanisms
  • Familiarity with embedded operating systems and architectures
  • Proficiency in programming and scripting (e.g., Python, C, Bash)
  • Experience with hardware debug tools and test equipment
  • Solid understanding of network security and penetration testing methodologies
  • Bachelor's degree in Computer Science, Information Security, or 5+ years of related work experience
  • 4+ years of hands-on experience in web application security, firmware security, embedded system penetration testing, authentication and security protocols
  • Working knowledge of industry frameworks: OWASP Web Security Testing Guide (WSTG), OWASP IoT Security Testing Guide (ISTG), Penetration Testing Execution Standard (PTES)
  • Strong written and verbal communication skills—you can explain complex security issues clearly to both technical and non-technical audiences
Responsibilities
  • Proactively engage in technical and hands-on security assessments, dissecting hardware, analyzing firmware, and identifying critical vulnerabilities in Cisco's latest devices and products still in development.
  • Perform in-depth analysis of hardware components and their interactions, including JTAG, UART, SPI, and I2C communication analysis, secure boot, and examining how firmware interacts with underlying hardware.
  • Extract and analyze content from SPI flash and other on-board memory and audit the security of hardware protocols and communication interfaces as part of the analysis.
  • Focus on uncovering technically challenging and highly impactful vulnerabilities, directly contributing to the security and trustworthiness of Cisco's extensive product portfolio.
  • Engineer and implement novel exploit chains to bypass advanced hardware and firmware security mechanisms, demonstrating full compromise scenarios.
  • Conduct in-depth research into emerging hardware attack surfaces and develop innovative techniques for exploitation that push the boundaries of current security understanding.
  • Continuously enhance your offensive security skillset across a broad spectrum of targets, including web applications, embedded firmware, hardware components, and network protocols.
  • Document all identified vulnerabilities with comprehensive technical write-ups and collaborate directly with engineering teams to provide detailed insights, driving effective remediation throughout the product development lifecycle.
  • Leverage automation, custom scripting, and AI/ML technologies to accelerate vulnerability discovery, streamline security analysis workflows, and enhance testing capabilities across a diverse range of hardware and embedded systems.
  • Analyze recurring vulnerability patterns across diverse systems, translating these findings into actionable security insights and baseline test sets to influence secure design and prevent future vulnerabilities.
Desired Qualifications
  • Experience with source code security assessments and adjacency analysis in C/C++, Golang, Rust, or Ruby
  • Comfort working in Linux environments
  • Exposure to hardware injection attacks such as EMFI
  • Understanding of secure development lifecycle practices including threat modeling, code review, SAST, DAST, and security architecture review
  • OSCP or similar penetration testing certification
  • Experience participating in bug bounty programs or responsible disclosure initiatives

Cisco designs and sells networking hardware, software, and services that help organizations connect, protect, and manage data. Its products include networking gear, security solutions, cloud services, and collaboration tools like Webex to support hybrid work. Cisco differentiates itself with a broad, integrated stack—routing and switching, security, cloud, and collaboration—that works together at scale. Its goal is to help customers securely connect people, devices, and applications, enabling reliable communication and digital transformation across enterprises of all sizes.

Company Size

10,001+

Company Stage

IPO

Headquarters

San Jose, California

Founded

1984

Simplify Jobs

Simplify's Take

What believers are saying

  • Networking revenues surged 21% YoY to $8.29 billion in Q2 FY2026 from AI infrastructure demand.
  • Six consecutive quarters of 20%+ networking orders driven by Wi-Fi 7 and campus upgrades.
  • JPMorgan raised price target to $96 citing AI growth in servers, switches, and optics.

What critics are saying

  • Arista erodes Cisco's share in high-performance Ethernet switches for AI data centers within 12 months.
  • HPE's Juniper acquisition undercuts Cisco's SASE offerings, accelerating defections in 6 months.
  • BWG Global downgrade reveals weakening demand for Cisco's legacy campus gear in 3 months.

What makes Cisco unique

  • Cisco's $28 billion Splunk acquisition integrates data analytics with ThousandEyes for $31.4 billion ARR.
  • Cisco open-sourced AI-BOM tool tracking 150 models to combat shadow AI security risks.
  • Cisco's Universal Quantum Switch connects incompatible quantum systems at room temperature with <4% degradation.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Paid Vacation

Hybrid Work Options

Flexible Work Hours

Professional Development Budget

Company News

Dolphin Publications
Apr 10th, 2026
Cisco acquires Galileo to strengthen Splunk's AI observability capabilities

Cisco is acquiring Galileo, an AI observability specialist, to strengthen Splunk's position in the AI monitoring market. The deal is expected to close in July 2026. Galileo provides tools to evaluate AI output quality, detect errors before they reach users, and improve AI agent behaviour in production. The platform monitors hallucinations, bias, security risks and cost metrics across the entire agent development lifecycle, offering real-time observability for multi-agent systems. The acquisition will integrate Galileo into Splunk Observability Cloud, expanding existing AI agent monitoring capabilities. Galileo offers over 20 evaluation metrics including hallucination detection and supports major AI platforms like OpenAI, Anthropic, Azure OpenAI and AWS Bedrock. Cisco and Galileo previously collaborated on Cisco's AGNTCY initiative. Both companies will operate independently until the deal closes.

SiliconANGLE Media
Apr 10th, 2026
Cisco buys Galileo to strengthen Splunk’s agentic monitoring capabilities

Cisco buys Galileo to strengthen Splunk's agentic monitoring capabilities - SiliconANGLE

Yahoo Finance
Apr 10th, 2026
Cisco joins Project Glasswing with Anthropic and Amazon to detect software vulnerabilities using AI

Cisco Systems has joined Project Glasswing alongside Anthropic, Amazon and other tech companies to detect software vulnerabilities using advanced AI models. The collaboration includes early access to Anthropic's Claude Mythos Preview and has already identified security flaws missed by existing tools. The initiative aligns with Cisco's strategy of integrating AI-driven security capabilities into its networking and collaboration products. For investors, the partnership positions Cisco to address software risks for large enterprise and government customers as AI reshapes cybersecurity. Cisco shares currently trade at $83.17, approximately 7% below the analyst target of $89.04. The company has raised $295 million to date, with recent 30-day returns of roughly 7%. Success depends on real-world effectiveness and maintaining customer trust in AI-based defences.

Yahoo Finance
Apr 6th, 2026
Cisco appoints former Deloitte executive Pete Shimer to board of directors

Cisco has appointed Pete Shimer to its board of directors, effective immediately. Shimer will serve on the board's Audit Committee. Shimer brings 40 years of executive leadership experience from Deloitte, where he held C-suite positions including chief operating officer, chief financial officer and interim chief executive officer. His expertise spans enterprise transformation, strategic planning and digital innovation. He currently serves on the boards of Alaska Airlines, Korn Ferry and Synopsys, and is executive chair of the Cancer Artificial Intelligence Alliance. Shimer holds a Bachelor of Arts degree in Accounting from the University of Washington. Cisco chair and CEO Chuck Robbins said Shimer's experience leading global organisations and guiding digital transformation brings valuable insight as Cisco delivers infrastructure for AI innovation.

Yahoo Finance
Apr 6th, 2026
Cisco beats Q4 revenue estimates with $15.35B, stock falls 7.6% amid sector downturn

Applied Digital topped Q4 IT services and tech stocks, while the sector overall saw revenues beat analyst estimates by 5.3%. The 20 tracked companies reported strong results, though share prices averaged a 10.4% decline following earnings announcements. Cisco reported revenues of $15.35 billion, up 9.7% year on year, exceeding analyst expectations by 1.5%. The networking equipment maker delivered a strong quarter with revenue guidance surpassing forecasts. CEO Chuck Robbins highlighted the company's portfolio strength and its role in connecting and protecting customers. Despite positive results, Cisco's stock fell 7.6% post-earnings to $79.08. The IT services sector faces growth opportunities from cloud adoption and AI-driven automation, whilst navigating challenges including competition from cloud-native providers and supply chain constraints for networking hardware.

INACTIVE