jobify_logo ×
  • מִשׁתַמֵשׁ
  • התחברות/הרשמה
  • עמוד הבית
  • מי אנחנו
  • מעסיקים מובילים
  • פרסום משרה חינם
  • צרו קשר
  • תנאי שימוש
  • מדיניות פרטיות
  • הצהרת נגישות
קרן עזריאלי טקסט בעברית עם סמל אינסוף social_security the_israeli_employment_service work_office המקום
jobify_logo
  • מי אנחנו
  • מעסיקים מובילים
  • פרסום משרה חינם
  • צרו קשר
דילוג לתוכן

עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!

במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.

מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.

Medical Device Penetration Tester (Contract / One-Off Engagement)

Valletta.Software | AI-Care

Valletta.Software | AI-Care Valletta.Software | AI-Care

  • תל אביב - יפו
  • LinkedIn
LinkedIn

Medical Device Penetration Tester (Contract / One-Off Engagement)

Valletta.Software | AI-Care

Valletta.Software | AI-Care Valletta.Software | AI-Care

  • תל אביב - יפו
  • bag_icon מלאה
  • coins_icon 25,000-40,000 ₪ הערכה מבוססת AI ולא שכר שהתקבל מהמעסיק
    הערכה מבוססת AI ולא שכר של המעסיק
  • LinkedIn
LinkedIn


Vallettasoftware - custom mobile/web software developer in the US and Europe. Our teams implement IT projects of varying complexity, including website and mobile app development, enterprise systems, and solutions based on artificial intelligence and machine learning (AI/ML).

We are proud to be named as one of the Top 10 Software Development Companies in Q2 2026 by 50Pros|Discover top agencies.

Our thorough approach to every project and deep understanding of Client's needs allow us to manage the outstanding quality.

About the Opportunity

We are looking for an experienced Penetration Tester to conduct a one-off comprehensive white-box penetration-testing engagement for a portfolio of network-connected physical medical/aesthetic devices with embedded software. This is a remote engagement with remote access to the devices.

Client: Global leader in medical/aesthetic devices.

Engagement type: One-off project (not full-time).

Location: Remote (devices will be accessed remotely).

Duration: Approximately 6–10 weeks (40–60 person-days).

Reports: Up to 5 technical reports + executive summary.

What You Will Do

  • Conduct white-box penetration testing of network-connected medical/aesthetic devices with embedded software.
  • Assess current-generation devices (MILEO, LISA) built on a shared Windows 10 IoT Enterprise platform.
  • Assess legacy devices (UPA, Stellar) on an earlier Windows IoT platform.
  • Review software architecture, design documentation, REST APIs, and system credentials.
  • Identify vulnerabilities, assess risks, and provide remediation recommendations.
  • Deliver comprehensive technical reports (platform-level + product-specific) and an executive summary.

What We Are Looking For

Must-Have

  • ✅ Proven penetration-testing experience with network-connected medical devices or other embedded healthcare systems.
  • ✅ Experience testing Windows-based embedded or IoT platforms (Windows IoT Enterprise, Windows Embedded).
  • ✅ Experience with white-box penetration testing (source code review, architecture review).
  • ✅ Experience with REST API security testing.
  • ✅ Experience with operating system hardening (CIS benchmarks, STIG, etc.).
  • ✅ Ability to work fully remotely and access devices via remote connection (VPN, etc.).
  • ✅ Professional English — able to write technical reports and executive summaries.
  • ✅ Experience writing reports for regulated industries (FDA, HIPAA, etc.).

Preferred Certifications

  • 🎯 OSEP (Offensive Security Experienced Penetration Tester)
  • 🎯 CRTP (Certified Red Team Professional)
  • 🎯 OSCE3, GXPN, CREST CRT/CCT, or equivalent

Strongly Preferred Knowledge

  • 📚 FDA Cybersecurity Guidance for Medical Devices
  • 📚 AAMI TIR57 / AAMI TIR97
  • 📚 IEC 81001-5-1
  • 📚 ISO 14971 (cybersecurity risk management)
  • 📚 NIST SP 800-115, OWASP Testing Guide, PTES

What You Will Deliver

  • One consolidated report covering the shared software platform.
  • Individual product-specific reports for assessed products (MILEO, LISA, UPA, Stellar).
  • An executive summary suitable for management review.
  • Technical details for every finding: severity/risk rating (CVSS), exploitation evidence, impact assessment, remediation recommendations, and re-test guidance.

Why This Role Is Unique

  • You will be testing real medical devices used in clinical settings.
  • You will work with embedded Windows IoT systems and REST APIs.
  • You will contribute to regulatory compliance (FDA, IEC, ISO).
  • This is a high-impact, high-visibility engagement with a global medical device leader.



במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.

מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.

שאלות ותשובות עבור משרת Medical Device Penetration Tester (Contract / One-Off Engagement)

פרויקט זה כולל ביצוע בדיקת חדירה מקיפה מסוג White-Box למגוון מכשירים רפואיים/אסתטיים פיזיים המחוברים לרשת ובעלי תוכנה משובצת. הבדיקה תתמקד במכשירים מהדור הנוכחי (MILEO, LISA) וגם במכשירי Legacy (UPA, Stellar), ותכלול סקירת ארכיטקטורת תוכנה, תיעוד עיצוב, ממשקי REST API ואישורי מערכת. המטרה היא לזהות פגיעויות, להעריך סיכונים ולספק המלצות לתיקון.

לתפקיד זה נדרש ניסיון מוכח בבדיקות חדירה למכשירים רפואיים מחוברים לרשת או למערכות בריאות משובצות אחרות. כמו כן, נדרש ניסיון בבדיקת פלטפורמות Windows מבוססות IoT או Embedded, ניסיון בבדיקות White-Box (כולל סקירת קוד מקור וארכיטקטורה), ובדיקות אבטחה של REST API. יכולת עבודה מרחוק וכתיבת דוחות טכניים באנגלית מקצועית הם חובה.

התוצרים הצפויים כוללים דוח מאוחד המכסה את פלטפורמת התוכנה המשותפת, דוחות ספציפיים למוצרים שנבדקו (MILEO, LISA, UPA, Stellar), וסיכום מנהלים. כל ממצא יכלול פרטים טכניים, דירוג חומרה/סיכון (CVSS), ראיות לניצול, הערכת השפעה, המלצות לתיקון והנחיות לבדיקה חוזרת. דוחות אלו מיועדים לתמוך בעמידה בתקנות כמו FDA, IEC ו-ISO.

משרות נוספות מומלצות עבורך
  • רשימת משאלות

    Penetration Tester

    • map_icon תל אביב - יפו
    comblack

    comblack

  • רשימת משאלות

    Senior Penetration Tester

    • map_icon תל אביב - יפו
    cyforce

    cyforce

  • רשימת משאלות

    Penetration Tester

    • map_icon מיקום לא צוין
    Undisclosed

    Undisclosed

  • רשימת משאלות

    Penetration Tester

    • map_icon לוד
    Logica-IT

    Logica-IT

  • רשימת משאלות

    Penetration Tester (36970)

    • map_icon תל אביב - יפו
    מרטנס | Mertens – מקבוצת מלם תים

    מרטנס | Mertens – מקבוצת מלם תים

  • רשימת משאלות

    Junior Penetration Tester

    • map_icon נס ציונה
    ARMORY

    ARMORY

לכל המשרות של בודק חדירות

הכשרות רלוונטיות

ITSafe

ITSafe

בודק חוסן

  • map_icon אונליין
  • אונליין
  • clk_icon 12 חודשים
אס.קיו.לינק

אס.קיו.לינק

Penetration Testing

  • map_icon רמת גן
  • בוקר
  • clk_icon 1 חודשים
היחידה ללימודי חוץ

היחידה ללימודי חוץ

Certified Ethical Hacker

  • map_icon אונליין
  • אונליין
  • clk_icon 6 חודשים
מכללת האקריו

מכללת האקריו

קורס סייבר ואבטחת מידע Ethical Hacking

  • map_icon רמת גן
  • ערב
  • clk_icon 14 חודשים

ניתן לצפות במשרות שסימנת בכל שלב תחת התפריט הראשי בקטגוריית 'משרות שאהבתי'

המקום קרן עזריאלי טקסט בעברית עם סמל אינסוף
  • מי אנחנו
  • מעסיקים מובילים
  • צרו קשר
  • תנאי שימוש
  • מדיניות פרטיות
  • הצהרת נגישות

2026 Ⓒ ג'וביפיי - כל הזכויות שמורות

קרן עזריאלי טקסט בעברית עם סמל אינסוף social_security the_israeli_employment_service israel_innovation_authority work_office המקום
המערכת בונה את הפרופיל התעסוקתי שלך

עוד רגע...

המערכת זיהתה ששינית את הנתונים באזור האישי ומעדכנת את ההמלצות על תפקידים ומשרות בהתאם.

מצטערים, לא הצלחנו לנתח בהצלחה את הנתונים שהזנת.
אתם מוזמנים לנסות להזין שוב או להעלות קובץ קורות חיים במידה ויש לכם.
בהצלחה

הגעת להגבלה היומית של שלושה עדכונים בפרופיל האישי ביום

loader

הבקשה שלך נשלחה בהצלחה!

יש באפשרותך לשלוח בקשה לקבלת ייעוץ אישי ללא עלות מיועצת קריירה.

באפשרותך לשלוח בקשה לקבלת ייעוץ אישי ללא עלות

  • בעיה טכנית

  • סיוע בכתיבת קורות חיים או בהכנה לראיון עבודה

  • התאמה של משרות

  • אחר:

פנייתך נשלחה בהצלחה. נציג מטעם ארגון נכי צהל ייצור איתך קשר בהקדם