Security Testing Engineer (Devices)
Landis+Gyr EMEA, formerly part of the Landis+Gyr Group, supports electricity, gas, water and thermal utilities in managing increasingly complex networks, improving operational efficiency and enabling more sustainable use of resources.
With more than 2.800 employees in 19 countries and decades of experience in critical infrastructure technology, the company provides advanced metering, network intelligence and digital solutions to utilities and infrastructure operators primarily across Europe, Middle East and Africa. As a standalone organisation, Landis+Gyr EMEA builds on long-standing customer relationships and proven technology capabilities, backed by experienced regional teams.
Role Purpose
The Security Testing Engineer (Devices) is responsible for planning and executing vulnerability, hardening, and penetration tests on Landis+Gyr’s embedded and IoT products. This includes devices running RTOS or embedded Linux, as well as components such as IoT communication modules and gateways. The role ensures that security weaknesses are identified, remediated, and verified through systematic retesting, supporting compliance with IEC 62443, CRA, and RED DA requirements.
Key Responsibilities
-
Plan, execute, and document penetration tests, vulnerability scans, and hardening assessments for embedded and IoT devices.
-
Perform firmware and hardware analysis, identifying weaknesses in authentication, encryption, or system configuration.
-
Test devices with RTOS, embedded Linux, and IoT modem components for security flaws or misconfigurations.
-
Collaborate with R&D to provide technical remediation guidance and verify fixes through structured retesting.
-
Develop and maintain testing methodologies, scripts, and test benches for repeatable assessments.
-
Support SBOM/HBOM verification and dependency risk validation for firmware components.
-
Contribute to security validation during product certification (IEC 62443, CRA, RED DA).
-
Share testing results and lessons learned with Security Architecture and DevSecOps teams to improve design and process maturity.
Required Skills & Experience
-
4+ years of experience in embedded security testing or vulnerability assessment.
-
Hands-on experience with RTOS (e.g., FreeRTOS, ThreadX) and embedded Linux environments.
-
Familiarity with IoT communication stacks and modem interfaces (e.g., NB-IoT, LTE-M, LoRa, DLMS/COSEM).
-
Strong knowledge of network and protocol-level testing, including fuzzing and packet manipulation.
-
Proficiency in tools such as Burp Suite, Ghidra, Wireshark, Nmap, OpenVAS, or custom scripts.
-
Understanding of secure boot, firmware signing, and device provisioning mechanisms.
-
Good knowledge of IEC 62443 or similar product cybersecurity frameworks.
Preferred Qualifications
-
Degree in Computer Engineering, Electrical Engineering, or Cybersecurity.
-
Certifications such as OSCP, CEH, or GIAC GPEN.
-
Experience in hardware security testing (e.g., JTAG, UART, side-channel analysis) is a plus.
-
Familiarity with test automation frameworks for embedded systems.
Key Interfaces
-
Internal: R&D (Firmware and Hardware), Security Architecture, Governance & Certification, QA.
-
External: External test labs, penetration testing vendors, certification authorities.
Success Indicators
-
All new and existing device platforms tested for security weaknesses within release cycles.
-
Timely remediation and verification of vulnerabilities before product certification or deployment.
-
Continuous improvement of test coverage, automation, and repeatability.
-
Documented contribution to audit and certification evidence for CRA and IEC 62443.
We value and encourage diversity in our team. This position is open to all qualified candidates regardless of gender, race, age, disability, sexual orientation, or background. We're committed to shaping a better future for everyone. #EnergizeYourCareer and join us on our journey towards a greener tomorrow.
Title: Security Testing Engineer (Devices)
Noida, UP, IN