Jobs / engineering
PCI PTS Security Evaluator
SGS · Delft
What they look for
As a PCI PTS Security Evaluator, you will join a multidisciplinary team of international experts assessing the security of payment terminals and secure hardware modules. Your work will focus primarily on hardware penetration testing, logical security testing, and tamper‑resistance evaluation in line with PCI PTS and related security standards.
You will:
- Analyse payment terminal architectures, security modules, and embedded systems.
- Perform hands‑on hardware penetration testing using techniques such as side‑channel analysis, invasive and semi‑invasive attacks, and circuit‑level probing.
- Conduct logical security testing, including secure boot validation, key management verification, firmware inspection, and interface/communication protocol testing.
- Perform firmware code reviews to assess secure coding practices, cryptographic implementations, and compliance with PCI PTS requirements
- Use laboratory equipment such as oscilloscopes, and power analysis setups, as well as simple physical tools such as drills, milling tools, and other basic mechanical instruments used in tamper‑resistance testing.
- Document attack paths, assess exploit feasibility, and evaluate compliance with PCI PTS requirements.
- Contribute to internal R&D by researching emerging attack vectors, developing new tooling, and improving evaluation methodologies.
Your Hard Skills
- Technical degree (BSc, MSc, or PhD) in Computer Science, Electrical Engineering, Embedded Systems, Physics, Mathematics, or equivalent practical experience in hardware or embedded security.
- Experience or strong interest in hardware security techniques such as Board‑level probing and debugging (JTAG, SWD, UART).
- Familiarity with logical security testing, secure firmware design, cryptographic implementations, and secure boot chains.
- Knowledge of cryptographic protocols, authentication mechanisms, tamper protections, and attack countermeasures is highly desirable.
- A willingness to learn rapidly in a field that evolves continuously.
Your Soft Skills
- You can work both independently and collaboratively in a multidisciplinary team.
- You are persistent, creative, and resourceful—essential traits for hardware penetration testing, where bypassing protections requires experimentation and ingenuity.
- You enjoy learning new concepts and staying informed on the latest research, standards, and attack techniques.
- You appreciate structured teamwork coupled with personal accountability—security evaluation relies heavily on transparent cooperation.
- You are able to write clear, detailed technical evaluation reports in English.