
Finite State partners with product security teams to create transparency for connected devices and supply chains across enterprises, healthcare, utilities, automotive, manufacturing, critical infrastructure, and government sectors. We are a fast-growing, Series B, fully distributed company committed to a remote-first culture.
About the Role
Finite State is seeking an experienced Senior Engineer β Penetration Testing to join our Offensive Security team. In this role, you will conduct hands-on hardware and software penetration tests of connected devices, embedded systems, industrial control systems (ICS/OT), and automotive platforms on behalf of our customers.
You will combine deep hardware and firmware expertise with a consultative approach to deliver clear, actionable findings. Backed by Finite State's firmware analysis platform, your focus will be on validating what is genuinely exploitable on physical hardware rather than building baselines manually.
What You'll Do
- Plan and execute penetration tests against IoT, ICS/OT, and automotive targets, including connected devices, industrial controllers, and automotive ECUs/telematics units.
- Own engagements autonomously from scoping and threat modeling to hands-on testing, evidence collection, reporting, and debriefing.
- Perform hardware interaction and firmware extraction using JTAG, SWD, UART, SPI, I2C, eMMC, NOR/SPI, and NAND flash dumping; rework and solder PCBs as needed to access debug interfaces.
- Reverse engineer firmware using Ghidra and Binary Ninja to identify vulnerabilities such as memory corruption, authentication bypasses, hard-coded credentials, and insecure update mechanisms.
- Assess wireless protocols (BLE, Zigbee, Z-Wave, Wi-Fi, cellular) and bus/industrial protocols (CAN, LIN, automotive Ethernet, Modbus, DNP3, EtherNet/IP, OPC-UA).
- Assess standard network protocols and companion attack surfaces (APIs, web, and mobile companion apps) using OWASP methodologies.
- Perform source code reviews in C, C++, and related embedded languages.
- Review SBOMs and open-source dependencies to identify known supply chain vulnerabilities.
- Leverage approved AI-assisted tooling to accelerate triage and analysis while adhering to strict customer NDA guidelines.
- Produce comprehensive reports scoring findings via CVSS, prioritize by exploitability, and provide defensible VEX justifications.
- Collaborate with product, engineering, and research teams to integrate engagement findings back into the Finite State core platform.
Qualifications
- Bachelor's degree in Computer Science, Electrical Engineering, Computer Engineering, or equivalent practical experience.
- 7+ years of hands-on experience in IoT, embedded, ICS/OT, or automotive security, with proven ability to lead engagements autonomously.
- Deep domain expertise in at least one area (IoT/embedded, ICS/OT, or automotive) and working familiarity with the others.
- Demonstrated experience performing hardware-level security assessments, flash extraction, and PCB rework/soldering.
- Proficiency in firmware reverse engineering using Ghidra or Binary Ninja across architectures like ARM, MIPS, RISC-V, PPC, x86, and x64.
- Experience auditing source code in C and C++ for memory safety and logic vulnerabilities.
- Working knowledge of SBOM standards (CycloneDX, SPDX), CVSS scoring, and VEX determinations.
- Proficiency in scripting and automation with Python and Bash.
- Excellent written and verbal communication skills for technical reporting and client debriefs.
- Must be authorized to work in the United States without sponsorship.
Preferred Qualifications
- Hands-on automotive security experience (OBD-II, ECU flashing, V2X, automotive HSMs).
- Hands-on ICS/SCADA security assessment experience.
- Documented CVE disclosures or security research track record.
- Relevant certifications (OSCP, OSWE, GPEN, GICSP, or automotive credentials).
- Familiarity with standards like EU Cyber Resilience Act, IEC 62443, ISO 21434, or FDA cybersecurity requirements.
- Eligibility for U.S. government security clearance.
Working Conditions
- Remote bench lab setup funded and shipped directly by Finite State (soldering station, probes, programmers, logic analyzer, radios).
- Limited travel for occasional customer-site assessments, conferences, and internal gatherings.
- Some engagements involve export-controlled hardware/data (ITAR/EAR) restricted to U.S. persons.
Timezone overlap
UTC-8β-4
Benefits
Open to
US
Sign in to track applications and earn points.