30 Sep
|
KPMG Assurance and Consulting Services
|
Bengaluru
30 Sep
KPMG Assurance and Consulting Services
Bengaluru
Role Purpose
We are seeking a motivated and technically robust Hardware Security Consultant to support the assessment, design, testing, and assurance of hardware, embedded, IoT, and connected product ecosystems.
The role focuses on identifying security weaknesses across the hardware lifecycle, including secure product design, embedded systems security, device security testing, supply chain security, and compliance with emerging cybersecurity regulations and industry standards.
The successful candidate will work with multidisciplinary teams comprising hardware engineers, firmware developers, software security specialists, product owners, and client stakeholders to strengthen the security posture of connected and cyber-physical systems.
Key Responsibilities
Hardware Security Assessments & Testing
- Conduct security assessments of:
- Hardware devices
- Embedded systems
- IoT products
- Industrial devices
- Connected products and smart devices
- Perform hardware and firmware security reviews to identify design flaws and security weaknesses.
- Evaluate product resilience against
- Physical attacks
- Side-channel attacks
- Fault injection attacks
- Hardware tampering
- Supply chain threats
- Support security testing activities including:
- Hardware penetration testing
- Embedded device assessments
- Firmware analysis
- Secure boot validation
- Debug interface testing (JTAG, UART, SWD, SPI, I2C)
Secure Product Development & Architecture
- Review hardware architectures for security-by-design principles.
- Assess implementation of
- Root of Trust (RoT)
- Trusted Platform Modules (TPM)
- Hardware Security Modules (HSM)
- Secure Boot
- Secure Firmware Update mechanisms
- Secure Key Storage
- Identify architecture vulnerabilities and recommend remediation measures.
- Support threat modeling across hardware, firmware, software, and cloud integration layers.
Embedded & IoT Security
- Assess security of embedded operating systems and firmware.
- Evaluate device identity and authentication mechanisms.
- Review security controls protecting device communications.
- Assess lifecycle security controls including:
- Manufacturing
- Provisioning
- Maintenance
- Decommissioning
- Support assessment of connected ecosystems spanning edge devices, gateways, mobile applications, and cloud platforms.
Product Compliance & Assurance
- Perform gap assessments and readiness reviews against standards such as:
- IEC 62443
- ETSI EN 303 645
- NIST Cybersecurity Framework
- NIST IoT Security Guidance
- ISO 21434
- ISO 27001
- Common Criteria
- FIPS 140-3
- EU Cyber Resilience Act (CRA)
- Support product security certification and regulatory compliance initiatives.
- Develop compliance reports, security findings, and remediation roadmaps.
Client Engagement & Delivery
- Support end-to-end delivery of product security and hardware security engagements.
- Participate in workshops, architecture reviews, and client presentations.
- Prepare technical reports, executive summaries, and remediation recommendations.
- Work collaboratively with hardware, software, architecture, and product teams.
Required Skills & Experience
Hardware Security Knowledge
- Strong understanding of:
- Hardware architecture
- Embedded systems
- Microcontrollers
- System-on-Chip (SoC) architectures
- Secure hardware design principles
- Knowledge of attack techniques including:
- Side-channel analysis
- Fault injection
- Hardware reverse engineering
- Chip-off analysis
- Physical tampering
Embedded & Firmware Security Experience in one or more of the following areas:
- Firmware analysis
- Secure boot
- Secure firmware updates
- Cryptographic implementation reviews
- Embedded Linux security
- RTOS security
- Device authentication and identity management
Security Testing Skills
Experience with
- Hardware penetration testing
- Product security assessments
- Vulnerability analysis
- Threat modeling
- Security architecture reviews
- Firmware extraction and analysis
Exposure to tools such as:
- Logic analyzers
- Oscilloscopes
- Protocol analyzers
- JTAG/UART debuggers
- Firmware analysis tools
- Hardware emulators
Product Security & Compliance
Working knowledge of
- Secure Development Lifecycle (SDL)
- Threat Modelling
- SBOM (Software Bill of Materials)
- Secure Product Development
- Product Security Incident Response
- Vulnerability Disclosure Programs
📌 Consultant - Hardware Security (Bengaluru)
🏢 KPMG Assurance and Consulting Services
📍 Bengaluru