Finite State logo
Finite StateΒ·

Senior Engineer - Penetration Testing

About Finite State

Finite State partners with product security teams to create transparency for connected devices and supply chains. Our platform handles connected devices and embedded systems across diverse industries, including enterprises, healthcare, utilities, connected vehicles, manufacturing facilities, critical infrastructure, and government entities.

We are a fast-growing series-B company with a fully distributed workforce and a committed remote-first culture.

About the Role

Finite State is seeking an experienced Senior Engineer β€” Penetration Testing to join our Offensive Security team. In this role, you will conduct hands-on hardware and software penetration tests of connected devices, embedded systems, industrial control systems (ICS), and automotive platforms on behalf of our customers.

You will combine deep hardware and firmware expertise with a consultative mindset to deliver clear, actionable findings. Backed by Finite State's firmware analysis platform, your focus will be on proving what is exploitable on real hardware rather than building a baseline manually.

  • Department: Services
  • Location: Remote, United States (Must be authorized to work in the U.S. without sponsorship)
  • Travel: Limited (occasional trips for customer-site assessments, conferences, and team gatherings)
  • Equipment: Finite State ships and funds your bench lab (soldering/rework station, probes, programmers, logic analyzer, and radios)

What You'll Do

Core Delivery

  • Plan and execute penetration tests against IoT, ICS/OT, and automotive targets, including connected consumer devices, industrial controllers, ECUs, and telematics units.
  • Own engagements autonomously across scoping, prioritizing attack surfaces, testing, evidence gathering, reporting, and debriefing.
  • Leverage the Finite State platform alongside manual testing to pinpoint reachable and exploitable vulnerabilities.
  • Perform hardware interaction and firmware extraction via JTAG, SWD, UART, SPI, I2C, eMMC, NOR/SPI flash, and NAND flash dumping, including PCB soldering and rework.
  • Conduct firmware reverse engineering using Ghidra and Binary Ninja to identify memory corruption, authentication bypasses, hard-coded credentials, and insecure update mechanisms.
  • Assess wireless protocols (BLE, Zigbee, Z-Wave, Wi-Fi, cellular) and vehicle buses (CAN, LIN, automotive Ethernet) or ICS/OT protocols (Modbus, DNP3, EtherNet/IP, OPC-UA).
  • Assess standard network protocols and companion attack surfaces (TCP/IP fundamentals, exposed services, cloud/mobile companion apps, and APIs).
  • Perform source code review in C, C++, and related embedded languages.
  • Review SBOMs and open-source components for known vulnerabilities and supply chain risk.
  • Produce high-quality technical reports with CVSS scoring, exploitability prioritization, and defensible VEX justifications.
  • Participate in peer reviews and support customer-facing debriefs.

Beyond Delivery

  • Collaborate with product, engineering, and research teams to feed findings back into the Finite State platform.
  • Contribute to internal tooling development, knowledge sharing, and methodology improvement.
  • Participate in industry conferences and external research publications.

Qualifications

  • Bachelor's degree in Computer Science, Electrical Engineering, Computer Engineering (or equivalent hands-on experience), plus 7+ years of hands-on experience in IoT, embedded, ICS/OT, or automotive security.
  • Hands-on depth in at least one target domain (IoT/embedded, ICS/OT, or automotive) and working familiarity with the other two.
  • Proven track record performing hardware-level security assessments, flash memory extraction, and PCB rework/soldering.
  • Proficiency with firmware reverse engineering tools (Ghidra, Binary Ninja) across ARM, MIPS, PPC, RISC-V, x86, and x64 architectures.
  • Experience testing relevant wireless protocols and vehicle or industrial control buses.
  • Ability to read and review source code in C and C++ for security vulnerabilities.
  • Familiarity with SBOM concepts, formats (CycloneDX, SPDX), CVSS scoring, and VEX justification.
  • Strong scripting and automation skills in Python and Bash.
  • Excellent written and verbal communication skills for technical and executive reporting.

Preferred Qualifications

  • Hands-on automotive security experience (OBD-II, ECU flashing, V2X, automotive HSM).
  • Experience with ICS/SCADA security assessments.
  • CVE disclosures, exploit development, or vulnerability research history.
  • Relevant certifications (OSCP, OSWE, GPEN, GICSP, or vendor-specific credentials).
  • Familiarity with relevant compliance standards (EU CRA, EN 303 645, ISO 21434, IEC 62443, FDA premarket guidance, US IoT Cyber Trust Mark).
  • Eligibility for U.S. government security clearance.
  • Experience with AI-augmented reverse engineering pipelines or ML-based vulnerability detection.

Timezone overlap

UTC-8–-4

Open to

US

Sign in to track applications and earn points.

More roles at Finite State

Similar remote roles