
Finite State is seeking an experienced Senior Engineer — Penetration Testing to join our growing Offensive Security team. In this role, you will conduct hands-on hardware and software penetration tests of connected devices, embedded systems, industrial control systems, and automotive platforms on behalf of our customers.
What makes this role different from a generalist penetration testing seat is that you have Finite State's firmware analysis platform behind you, allowing you to focus your time on proving what is actually exploitable on real hardware rather than building a baseline by hand.
What You'll Do
- Plan and execute penetration tests against IoT, ICS/OT, and automotive targets, including connected consumer devices, industrial controllers, and automotive ECUs and telematics units.
- Own engagements largely autonomously — scoping, prioritizing attack surfaces, testing, evidence, reporting, and debrief.
- Use Finite State's platform analysis alongside your own testing to focus effort on genuinely reachable and exploitable vulnerabilities.
- Perform hardware interaction and firmware extraction using techniques such as JTAG, SWD, UART, SPI, I2C, eMMC, NOR/SPI flash, and NAND flash dumping; solder and rework PCBs as needed.
- Conduct firmware reverse engineering using tools such as Ghidra and Binary Ninja to identify vulnerabilities.
- Assess wireless protocols (Bluetooth/BLE, Zigbee, Z-Wave, Wi-Fi, cellular) and vehicle buses (CAN, LIN, automotive Ethernet) or ICS/OT protocols.
- Perform source code review, primarily in C, C++, and related embedded languages.
- Review third-party and open-source components via SBOM review and software composition analysis.
- Leverage AI-powered security tooling and LLM-assisted workflows to accelerate analysis, triage, and reporting.
- Produce high-quality written reports communicating technical findings, risk ratings, and remediation guidance to technical and executive audiences.
Qualifications
- 7+ years of hands-on experience in IoT, embedded, ICS/OT, or automotive security, with a track record of owning engagements autonomously at a senior level.
- Hands-on depth in at least one target domain (IoT/embedded, ICS/OT, or automotive) plus working familiarity with the other two.
- Demonstrated experience performing hardware-level security assessments: JTAG/SWD debugging, SPI/I2C/UART communication, and flash memory extraction.
- Proficiency with firmware reverse engineering tools (Ghidra, Binary Ninja) across architectures like ARM, MIPS, PPC, RISC-V, x86, and x64.
- Ability to read and review source code in C and C++.
- Experience with scripting and automation using Python and Bash.
- Authorized to work in the U.S. without sponsorship.
Equipment
Finite State ships and funds your bench lab — soldering and rework station, probes, programmers, logic analyzer, and radios — to wherever you work.
Timezone overlap
UTC-8–-4
Benefits
Open to
NA
Sign in to track applications and earn points.