4000$-4500$
We are looking for an experienced Penetration Tester to conduct a one-off comprehensive white-box penetration-testing engagement for a portfolio of network-connected physical medical/aesthetic devices with embedded software. This is a remote engagement with remote access to the devices.
Client: Global leader in medical/aesthetic devices.
Engagement type: One-off project (not full-time).
Location: Remote (devices will be accessed remotely).
Duration: Approximately 6–10 weeks (40–60 person-days).
Reports: Up to 5 technical reports + executive summary.
Conduct white-box penetration testing of network-connected medical/aesthetic devices with embedded software.
Assess current-generation devices (MILEO, LISA) built on a shared Windows 10 IoT Enterprise platform.
Assess legacy devices (UPA, Stellar) on an earlier Windows IoT platform.
Review software architecture, design documentation, REST APIs, and system credentials.
Identify vulnerabilities, assess risks, and provide remediation recommendations.
Deliver comprehensive technical reports (platform-level + product-specific) and an executive summary.
✅ Proven penetration-testing experience with network-connected medical devices or other embedded healthcare systems.
✅ Experience testing Windows-based embedded or IoT platforms (Windows IoT Enterprise, Windows Embedded).
✅ Experience with white-box penetration testing (source code review, architecture review).
✅ Experience with REST API security testing.
✅ Experience with operating system hardening (CIS benchmarks, STIG, etc.).
✅ Ability to work fully remotely and access devices via remote connection (VPN, etc.).
✅ Professional English — able to write technical reports and executive summaries.
✅ Experience writing reports for regulated industries (FDA, HIPAA, etc.).
🎯 OSEP (Offensive Security Experienced Penetration Tester)
🎯 CRTP (Certified Red Team Professional)
🎯 OSCE3, GXPN, CREST CRT/CCT, or equivalent
📚 FDA Cybersecurity Guidance for Medical Devices
📚 AAMI TIR57 / AAMI TIR97
📚 IEC 81001-5-1
📚 ISO 14971 (cybersecurity risk management)
📚 NIST SP 800-115, OWASP Testing Guide, PTES
One consolidated report covering the shared software platform.
Individual product-specific reports for assessed products (MILEO, LISA, UPA, Stellar).
An executive summary suitable for management review.
Technical details for every finding: severity/risk rating (CVSS), exploitation evidence, impact assessment, remediation recommendations, and re-test guidance.
You will be testing real medical devices used in clinical settings.
You will work with embedded Windows IoT systems and REST APIs.
You will contribute to regulatory compliance (FDA, IEC, ISO).
This is a high-impact, high-visibility engagement with a global medical device leader.
Published on: 8/13/2026

Valletta Software
Valletta Software - custom mobile/web software developer in the US and Europe.
Please let Valletta Software know you found this job on Wantapply.com. It helps us to get more jobs on our site. Thanks!