Wireless Security Engineer – SDR & PHY Layer
- Moves you to
- Denmark
- Support
- Visa sponsorship
- Posted
- Sep 24, 2026
Is this job info correct?
Location: Hybrid, Copenhagen
Full-time
Visa sponsorship available
Role Summary
We are looking for a wireless security engineer to work at the physical layer, with Software Defined Radio as the primary tool. You will study how wireless links behave – and how they fail – over the air: reverse engineering waveforms and protocols, assessing their resilience to jamming, spoofing, replay and interception, and turning that understanding into detection and countermeasure capability in our products.
Key Responsibilities
- Analyse and reverse engineer wireless protocols at the PHY and lower MAC layers from live captures: framing, preambles, modulation, coding, scrambling, hopping patterns and timing.
- Build SDR-based tooling to capture, decode, replay and synthesise signals for security testing and evaluation.
- Assess RF link resilience: jamming and interference susceptibility, spoofing and replay attacks, message injection, GNSS spoofing and meaconing, and metadata or side-channel leakage from the waveform itself.
- Develop detection methods for anomalous or hostile RF activity: RF fingerprinting and specific emitter identification, protocol-conformance and timing anomaly detection, and spoofing detection.
- Design and run controlled over-the-air test campaigns in shielded or anechoic environments and in the field, with repeatable methodology and clear reporting.
- Evaluate the PHY-layer security of standard and proprietary systems (UAS command-and-control and video links, GNSS, Wi-Fi, Bluetooth/BLE, LoRa, LTE/5G NR) and document realistic threat models.
- Translate findings into product requirements and features together with the SDR software, DSP and RF hardwares.
- Track public research and disclosures in wireless and RF security, and keep our threat picture current.
- Work within the legal and regulatory limits for RF transmission and testing, and help define our internal rules of engagement.
Required Qualifications
- Hands-on experience with SDR platforms and toolchains (USRP/UHD, AD936x, HackRF, bladeRF, GNU Radio, Inspectrum or equivalent) applied to real signals, not only tutorials.
- Solid DSP and communications fundamentals: modulation, coding, synchronisation, spread spectrum and frequency hopping, link budgets.
- Demonstrated protocol reverse engineering or wireless security work – prior professional experience, published research, disclosures, open-source tooling or serious CTF results.
- Strong Python, and enough C/C++ to work inside a real-time signal processing codebase.
- Applied cryptography knowledge, and a clear view of where it does and does not protect a wireless link (authentication, replay protection, key management, and the limits of encryption at the PHY).
- Structured, evidence-driven approach to testing, with the discipline to document methodology and results so others can reproduce them.
Nice-to-Haves
- Counter-UAS, electronic warfare, SIGINT or spectrum monitoring experience.
- GNSS signal structure and anti-spoofing / anti-jamming techniques.
- Machine learning for RF (specific emitter identification, anomaly detection).
- Cellular PHY familiarity (LTE/5G NR) and tools such as srsRAN or OpenAirInterface.
- Embedded, firmware or hardware-level security experience (JTAG/UART, firmware extraction, bus analysis).
- Familiarity with relevant regulatory frameworks and with responsible disclosure practice.
- Eligibility for, or willingness to undergo, a security clearance.