1

Physical Penetration Testing Jobs in Michigan (NOW HIRING)

... testing. * Assist with tracking and resolving findings identified during penetration tests and security assessments. * Maintain cybersecurity training, incident, and remediation records Physical and ...

Coordinate with third-party vendors conducting penetration testing. * Assist with tracking and resolving findings identified during penetration tests and security assessments. Physical and Work ...

Required qualifications: • Successful Completion of Production Welder (Carbon) Testing. • ... Physical requirements of position: • Ability to lift, carry and move heavy materials (up to 50 ...

Physical Penetration Testing information

See Michigan salary details

$9.6K

$95.5K

$159.9K

How much do physical penetration testing jobs pay per year?

As of Sep 1, 2026, the average yearly pay for physical penetration testing in Michigan is $95,496.00, according to ZipRecruiter salary data. Most workers in this role earn between $69,700.00 and $124,600.00 per year, depending on experience, location, and employer.

What is physical penetration testing?

A Physical Penetration Testing job involves assessing the security of a facility by simulating real-world intrusion attempts. Testers use tactics like social engineering, lock picking, and bypassing security controls to identify vulnerabilities. The goal is to help organizations strengthen their physical security measures by uncovering weaknesses before malicious actors do. This role requires a combination of technical knowledge, stealth, and problem-solving skills.

What does a physical penetration tester do?

A typical day for a Physical Penetration Tester involves planning and executing simulated intrusions to assess and test the effectiveness of an organization's physical security controls. This often includes reconnaissance of target facilities, attempting authorized entry through various methods (such as bypassing locks or circumventing access controls), and documenting discovered vulnerabilities. Testers also collaborate closely with internal security teams and may present their findings through detailed reports and debriefing sessions. The work can be both hands-on and analytical, and it frequently requires flexibility, discretion, and strict adherence to client agreements. You'll gain exposure to a wide range of security environments and play a crucial role in helping organizations improve their overall security posture.

What skills and qualifications are needed for a physical penetration tester?

To thrive as a Physical Penetration Tester, you need a strong background in security assessment, physical security systems, and risk analysis, often supported by relevant certifications such as Certified Red Team Professional (CRTP) or Physical Security Professional (PSP). Familiarity with lock picking tools, badge cloning devices, RFID readers, and surveillance avoidance techniques is commonly required. Strong problem-solving, discretion, and clear communication skills set successful testers apart, especially when working under pressure or conveying findings to clients. These skills ensure comprehensive and ethical testing of physical security defenses, enabling organizations to identify and remediate real-world vulnerabilities effectively.

Is a physical penetration testing a good career?

Physical penetration testing is a specialized cybersecurity role that involves assessing physical security controls, such as access points and security procedures. It requires skills in security assessment, often supported by certifications like OSCP or CEH, and can offer opportunities in security consulting, corporate security, or government agencies. The career can be rewarding for those interested in hands-on security testing and problem-solving, with demand growing as organizations prioritize physical security measures.

What are popular job titles related to Physical Penetration Testing jobs in Michigan?

For Physical Penetration Testing jobs in Michigan, the most frequently searched job titles are:

Infographic showing various Physical Penetration Testing job openings in Michigan as of August 2026, with employment types broken down into 1% As Needed, 72% Full Time, 24% Part Time, 2% Contract, and 1% Nights. Highlights an 97% Physical, 1% Hybrid, and 2% Remote job distribution, with an average salary of $95,496 per year, or $45.9 per hour.

Automotive Embedded Security Tester (BH ID)

Sunrise Systems, Inc.

Plymouth, MI • On-site

Other

Posted 4 days ago


Job description

Job Title: Automotive Embedded Security Tester (BH ID) Location: Plymouth, MI Duration:2+ year contract
Key Requirements

  • Automotive industry background required
  • Experience with Electronic Control Units (ECUs)
  • Strong understanding of CAN (Controller Area Network) protocols


Technical Skills

  1. Penetration testing experience
  2. Must have experience beyond fuzz testing
  3. Looking for candidates with security testing experience in one or more of the following areas:
  • USB
  • Wireless communications
  • Bluetooth
  • Similar embedded/connected device technologies

Position Notes: Embedded Security / Pen Testing Engineer
Automotive Embedded Security Tester (BH ID)
Embedded Systems Penetration & Fuzz Testing

  • Design & Execute Campaigns: Build and execute comprehensive penetration testing campaigns against a wide variety of automotive embedded targets.
  • Advanced Fuzzing: Configure and deploy targeted fuzzing frameworks (e.g., AFL++, libFuzzer, Peach, Defensics) against vehicle computers, ECUs, and clusters.
  • Vulnerability Discovery: Uncover memory corruption vulnerabilities (buffer overflows, use-after-free), resource exhaustion, and complex logic flaws that automated static analyzers often miss.


Comprehensive Wireless & Wired Protocol Analysis

  • Wired Vehicle Networks: Intercept, manipulate, and inject traffic across internal wired topologies, including CAN, CAN-FD, Automotive Ethernet (SOME/IP, DoIP), LIN, and FlexRay. You will utilize industry-standard tools like Vector CANoe/CANalyzer and Vehicle Spy.
  • Wireless Ecosystems: Aggressively analyze and exploit vulnerabilities across every wireless communication interface. This includes deep-dive assessments of Bluetooth/BLE, Wi-Fi (802.11), Cellular networks (4G/LTE, 5G, and C-V2X), UWB, NFC, and traditional RF/Keyless Entry Systems (RKE/PEPS) using Software Defined Radios (SDRs like HackRF, USRP).


Hardware & Firmware Reverse Engineering

  • Physical Attack Vectors: Conduct hands-on, hardware-level security testing to identify physical attack vectors.
  • Hardware Debugging & Exploitation: Utilize tools like Logic Analyzers, Bus Pirate, J-Link, and UART/JTAG/SPI debuggers, side-channel analysis (SCA), and voltage/clock fault injection techniques.
  • Firmware Analysis: Extract firmware from flash memory for subsequent reverse engineering and static analysis using disassemblers like IDA Pro.


AI-Enhanced Fuzzing and Vulnerability Discovery

  • Develop and apply AI-driven fuzzing techniques, using machine learning to intelligently guide test case generation and uncover complex vulnerabilities in vehicle software.
  • Utilize ML models to perform automated analysis of source code and binaries, identifying potential zero-day vulnerabilities that evade traditional static and dynamic analysis tools.


Automated Anomaly Detection in Vehicle Networks

  • Implement and manage machine learning systems to analyze real-time data from CAN, Automotive Ethernet, and wireless channels, automatically detecting anomalous patterns indicative of a cyberattack.


Adversarial AI/ML System Testing

  • Conduct security assessments of on-board AI/ML systems (e.g., those used for perception, sensor fusion, or decision-making in autonomous driving).
  • Design and execute adversarial attacks (e.g., data poisoning, evasion attacks) to test the resilience and integrity of automotive AI models.


Strategic Remediation

  • Actionable Reporting: Document findings in meticulous, highly technical reports that include mitigation strategies.
  • Engineering Collaboration: Partner directly with other security tester/consultants to craft actionable, robust remediation strategies that fix the root cause of vulnerabilities.


What We Are Looking For
Experience & Education

  • Bachelor's or Master's degree in Computer Science, Cybersecurity, Computer Engineering, or a heavily related technical discipline.
  • Proven experience in applying AI/ML techniques to cybersecurity challenges, such as intelligent fuzzing, anomaly detection, or securing machine learning systems.
  • 3+ years of hands-on experience in penetration testing, vulnerability research, or reverse engineering, specifically focused on automotive embedded systems, IoT devices, or specialized custom hardware.


Deep Technical Expertise & Certifications

  • Deep understanding of automotive E/E architectures, RTOS (e.g., QNX, VxWorks, AUTOSAR OS), and POSIX-based systems (Automotive Linux).
  • Familiarity with automotive microcontrollers (e.g., Infineon AURIX TriCore, Renesas RH850, ARM Cortex-R/M) and hardware security modules (HSM/SHE).
  • Strong grasp of industry-standard cybersecurity regulations and frameworks, specifically ISO/SAE 21434, UNECE WP.29 R155, and MITRE Telecommunication&CK.
  • Knowledge of common machine learning frameworks (e.g., TensorFlow, PyTorch, scikit-learn) and their application in a security context.


Understanding of adversarial ML concepts and defenses.

  • Preferred Certifications: OSCP, OSCE, OSWE, eCPTX, GXPN, or specialized automotive/IoT security certifications.


Programming & Tooling Proficiency

  • Proficiency in scripting and low-level programming languages such as Python, C/C++, Bash, or Assembly (ARM/x86/TriCore).
  • Experience with data science and machine learning libraries within Python (e.g., Pandas, NumPy).
  • Extensive hands-on experience with hardware/software testing tools (e.g., Oscilloscopes, Wireshark, Burp Suite, GNU Radio, Binwalk).