About The Position

Finite State is seeking an experienced Senior Engineer — Penetration Testing to join our growing Offensive Security team. In this role you will conduct hands-on hardware and software penetration tests of connected devices, embedded systems, industrial control systems, and automotive platforms on behalf of our customers. You will combine deep hardware and firmware expertise with a consultative mindset to deliver clear, actionable findings that help manufacturers and operators understand and reduce risk. This role is differentiated by the use of Finite State's firmware analysis platform, allowing engineers to focus on exploitability on real hardware rather than manual baseline creation. The core mandate is hands-on penetration testing, with opportunities to expand into platform integrations, account ownership, and tool development.

Requirements

  • Bachelor's degree in Computer Science, Electrical Engineering, Computer Engineering, or a related field (or equivalent hands-on experience), plus 7+ years of hands-on experience in IoT, embedded, ICS/OT, or automotive security, with a track record of owning engagements autonomously at a senior level.
  • Hands-on depth in at least one of our three target domains - IoT/embedded, ICS/OT, or automotive - plus working familiarity with the other two.
  • Demonstrated experience performing hardware-level security assessments: JTAG/SWD debugging, SPI/I2C/UART communication, and flash memory extraction. Comfort soldering and reworking PCBs to reach a debug interface is expected; fine-pitch and BGA rework is a plus, not a gate.
  • Proficiency with firmware reverse engineering tools, specifically Ghidra and/or Binary Ninja; ability to analyze ARM, MIPS, PPC, RISC-V, x86, and x64 architectures.
  • Experience testing wireless protocols (BLE, Zigbee, Z-Wave, Wi-Fi, cellular) and either vehicle buses (CAN, LIN, automotive Ethernet) or industrial control protocols (Modbus, DNP3, EtherNet/IP, OPC-UA) — consistent with depth in one target domain and familiarity with the others.
  • Working familiarity with standard network protocols and web/mobile application testing methodology - many IoT and automotive targets ship with companion companion apps and cloud APIs that are part of the real attack surface.
  • Ability to read and review source code in C and C++ to identify memory safety issues, authentication flaws, and other security weaknesses in embedded software.
  • Familiarity with SBOM concepts, formats (CycloneDX, SPDX), and the use of SBOMs in vulnerability management.
  • Working fluency with CVSS scoring and VEX, including how an exploitability determination is defended to a customer.
  • Ability to map findings to at least one relevant regulatory or standards framework and explain the implications to a customer.
  • Excellent written and verbal communication skills; proven ability to write clear, well-structured technical reports and present findings to diverse audiences.
  • Experience with scripting and automation using Python and Bash to support tooling and workflow efficiency.
  • Familiarity with AI-assisted security tooling and an interest in applying LLM-based workflows to accelerate security analysis and reporting.

Nice To Haves

  • Hands-on automotive security experience: OBD-II assessment, ECU flashing and analysis, V2X protocols, or automotive HSM evaluation.
  • Experience with industrial control system (ICS/SCADA) security assessments and familiarity with protocols such as Modbus, DNP3, EtherNet/IP, or OPC-UA.
  • CVE or responsible disclosure history, or other demonstrated exploit development / vulnerability research.
  • Relevant certifications a plus, not required: Offensive Security (OSCP, OSWE) or SANS/GIAC (GPEN, GICSP), or vendor-specific automotive security credentials.
  • Working knowledge of specific regulations and standards - a subset is plenty, not comprehensive mastery: EU Cyber Resilience Act (CRA), CE RED / EN 303 645, UNECE WP.29 / ISO 21434 (automotive), IEC 62443, FDA premarket cybersecurity requirements, or the US IoT Cyber Trust Mark.
  • Eligibility for U.S. government security clearance.
  • Familiarity with static and dynamic analysis platforms and SAST/DAST tooling in the context of firmware and embedded software.
  • Experience with ML-based vulnerability detection models or AI-augmented reverse engineering pipelines.
  • Experience working on small, fast-moving consulting or product security teams.
  • Comfort operating in AWS or similar cloud environments used to support analysis pipelines or customer deliverables.
  • Strong attention to detail, intellectual curiosity and the ability to adjust priorities quickly in a dynamic environment.
  • Interest in expanding into broader customer-facing and engineering responsibilities.

Responsibilities

  • Plan and execute penetration tests against IoT, ICS/OT, and automotive targets, including connected consumer devices, industrial controllers, and automotive ECUs and telematics units.
  • Own engagements largely autonomously - scoping, prioritizing attack surfaces, testing, evidence, reporting, and debrief.
  • Use Finite State's platform analysis alongside your own testing to focus effort on the vulnerabilities that are genuinely reachable and exploitable on the target.
  • Perform hardware interaction and firmware extraction using techniques such as JTAG, SWD, UART, SPI, I2C, eMMC, NOR/SPI flash, and NAND flash dumping; solder and rework PCBs as needed to gain access to debug interfaces.
  • Conduct firmware reverse engineering using tools such as Ghidra and Binary Ninja to identify vulnerabilities including memory corruption, authentication bypasses, hard-coded credentials, and insecure update mechanisms.
  • Assess wireless protocols common in IoT and automotive environments: Bluetooth/BLE, Zigbee, Z-Wave, Wi-Fi, and cellular (LTE/5G).
  • Assess vehicle buses - CAN, LIN, and automotive Ethernet - and the industrial control protocols riding on ICS/OT networks, including Modbus, DNP3, EtherNet/IP, and OPC-UA.
  • Assess standard network protocols and companion attack surfaces - TCP/IP fundamentals, exposed services, cloud and mobile companion apps and APIs - using standard web application testing methodology (e.g., OWASP Top 10) where relevant.
  • Perform source code review, primarily in C, C++, and related embedded languages, to identify security weaknesses in firmware and embedded software.
  • Review third-party and open-source components in scope for the engagement - SBOM review and software composition analysis - to identify known vulnerabilities and license risk in the customer's supply chain.
  • Leverage AI-powered security tooling and LLM-assisted workflows to accelerate analysis, triage, and reporting, using approved tooling and honoring customer data-handling and NDA constraints on firmware and findings. Maintain awareness of evolving AI capabilities relevant to embedded security research.
  • Evaluate customer products for compliance with relevant regulations and standards where in scope for the engagement.
  • Produce high-quality written reports that clearly communicate technical findings, risk ratings, and remediation guidance to both technical and executive audiences. Score findings on CVSS and prioritize by demonstrated exploitability - a proven-exploitable medium outranks an unreachable critical - and support not-affected determinations with a defensible VEX justification.
  • Participate in peer review of engagement deliverables, both as author and reviewer, before reports reach the customer.
  • Support customer-facing engagements including scoping calls, technical debriefs, and remediation follow-up.
  • Collaborate with the product, engineering, and research teams to feed engagement findings back into the Finite State platform and improve its detection capabilities.
  • Contribute to internal knowledge sharing, tooling development, and methodology improvement.
  • Participate in industry conferences, publish research, and represent Finite State externally as opportunities arise.

Benefits

  • Finite State ships and funds your bench lab - soldering and rework station, probes, programmers, logic analyzer, and radios - to wherever you work.
  • Fully distributed workforce.
  • Remote first culture.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service