Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Careers

    Apply: Medical Device Penetration Tester

    Set aside 20 to 30 minutes. This is a long application on purpose, and a real person reads every one.

    Back to the role

    Before you start

    This takes 20 to 30 minutes and asks you to do a small piece of real work. That is deliberate. We would rather read fifty considered applications than five hundred generic ones, and the questions below are the ones a resume cannot answer.

    Draft it somewhere else if you prefer. The page does not save as you go.

    About you

    Optional, but it helps. You can also paste a link above instead.

    Paste a link to a 90 second video telling us why you are a fit. Unlisted YouTube, Loom, Google Drive, anything we can open. A phone camera is fine and we are not judging production quality. Optional, but it is the fastest way to stand out.

    The work

    Answer these in your own words. We are reading for how you think, not for length, and a generic answer is worse than a short one.

    You find an unauthenticated service on a device, and the manufacturer says it is unreachable in clinical use. How do you decide whether that is a finding, and what evidence would you put in the report?

    You have three days left on an engagement and you have not found anything of consequence. What do you do with the time, and what does the report say at the end of it?

    You captured Bluetooth traffic from a patient monitor and the pairing exchange uses Just Works with no out-of-band confirmation. Write that finding the way it would appear in a report: what it is, why it matters for the patient, and what you would recommend. Under 200 words.

    What tooling do you reach for first on an unfamiliar embedded target, and in what order? Then tell us about the last thing that had you stuck for more than a day and how it resolved.

    Quick questions

    Ten of them, a few minutes at most. Pick the best answer. We are not testing trivia, and getting a few wrong will not disqualify you.

    1. On an embedded target, an exposed UART header on the board most often gives an attacker:
    2. In medical device security risk assessment, exploitability is used in place of which ISO 14971 term?
    3. A CVSS base score on its own is not sufficient for medical device risk because it:
    4. Before touching a clinical device on a client site, the first thing you confirm is:
    5. Just Works BLE pairing is a concern mainly because it:
    6. Finding secrets in extracted firmware most often indicates:
    7. A report finding is most useful to a reviewer when it states:
    8. You discover a vulnerability that is out of the agreed scope. You:
    9. Fuzzing an external interface is intended to reveal:
    10. The main reason a monitoring agent is usually not installed on a medical device is:

    Who does this role report to? The answer is on the job posting.

    We use AI every day and we expect you to. Tell us honestly how you used it on this application: which tool, on which parts, and what you changed afterwards. "I did not use it" is a completely fine answer. What we cannot work with is a no when the writing says otherwise.

    Tell us something unique about you that will not show up anywhere else in this application. A hobby that got out of hand, something you build or collect or compete in, a language, a detour in your career, an unpopular opinion about our industry. Or, if you have an idea for how we should be working, tell us that instead. Optional, and there is no right answer.

    Prefer email? Write to careers@bluegoatcyber.com.

    We use what you send here only to evaluate you for this and future roles. We do not sell or share it.