Full-Time

Director – Product Security Services

Product Security Services

Posted on 9/18/2025

Finite State

Finite State

51-200 employees

Automates product security for connected devices.

No salary listed

Remote in USA

Remote

Candidates must be based in and authorized to work in the US.

Category
IT & Security (1)
Requirements
  • 10+ years of experience in product security, including embedded systems, firmware security, or connected device platforms OR 8+ years with demonstrable experience in adjacent areas such as application security, cloud security, or security architecture with embedded systems, firmware security, or connected device platforms experience.
  • Experience leading or co-leading a product security program at a hardware or IoT device manufacturer.
  • Proven success delivering product security consulting services or cross-functional stakeholder engagement experience, including customer-facing roles in technical sales, solutions architecture, or internal consulting.
  • Deep familiarity with regulatory mandates including (but not limited to) FDA Premarket Guidance, Cyber Resilience Act, NIST 800-53/82, or ISO 62443 and 26262.
  • Strong understanding of SBOMs, vulnerability management, binary/static analysis, and secure SDLC practices.
  • Ability to communicate with technical, executive, and regulatory audiences in both written and verbal formats.
Responsibilities
  • Lead engagements to design, assess, and mature product security programs for device manufacturers.
  • Drive the creation and execution of gap assessments, control frameworks, threat models, and roadmap plans.
  • Deliver tailored reporting and recommendations for key customer stakeholders and external regulators.
  • Serve as a trusted advisor to customer engineering, product, and compliance leaders.
  • Provide expert consultation on global regulatory mandates (e.g., Connected Vehicle Rule, CRA, FDA, EO 14028, Cyber Trust Mark).
  • Guide customers in public/private stakeholder communication, including strategic reporting and reputation management.
  • Expand testing programs to cover firmware, hardware, SBOMs, and runtime environments.
  • Oversee engagements involving advanced assessments, security control validation, and continuous monitoring.
  • Translate testing results into business-aligned risk insights and action plans.
  • Consult with R&D and DevOps teams to embed security testing within CI/CD pipelines.
  • Define and deliver integrations and automation strategies across SBOM, vulnerability, and compliance tooling.
  • Guide clients in implementing APIs and workflows that support scalable DevSecOps.
  • Design and deliver dashboards that provide real-time views of security posture, compliance gaps, and risk trends.
  • Define KPIs for program success and continuous improvement.
  • Support clients in communicating status and outcomes to executive and regulatory stakeholders.
Desired Qualifications
  • Experience engaging directly with regulators, partners, or key customers on security posture or compliance standing.
  • Familiarity with commercial or open-source tools for binary analysis, SCA, and vulnerability correlation.
  • Prior experience integrating or consulting on security automation within CI/CD environments.
  • Ability to influence product and platform roadmap based on customer feedback and services insights.

Finite State automates product security for connected devices and embedded systems such as IoT, medical devices, ICS, and OT. Its platform provides deep visibility into device and supply chain risks and helps with compliance, delivered through a subscription service for continuous visibility and actionable remediation of security issues.

Company Size

51-200

Company Stage

Late Stage VC

Total Funding

$69.5M

Headquarters

Columbus, Ohio

Founded

2017

Simplify Jobs

Simplify's Take

What believers are saying

  • Raised $20M growth round in March 2024 led by Energy Impact Partners.
  • Appointed Ann Miller as VP Marketing in April 2026 to scale go-to-market.
  • Partnered with Somos and Quectel to enhance supply chain security offerings.

What critics are saying

  • Black Duck undercuts subscriptions with broader SCA, capturing 35% larger market share.
  • Snyk replicates binary analysis, eroding 25% IoT customers via freemium pricing.
  • Microsoft Defender bundles free scanning, displacing 70% cloud-dependent medical clients.

What makes Finite State unique

  • Finite State's Reachability Engine reduces vulnerability noise by 90% via execution context analysis.
  • AgentOS automates design-to-binary reconciliation and generates EU CRA compliance packages.
  • Platform ingests 120+ data sources for unified SBOM management across firmware and apps.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Professional Development Budget

Company Equity

Remote Work Options

Growth & Insights and Company News

Headcount

6 month growth

-3%

1 year growth

-2%

2 year growth

0%
Industrial Cyber
Apr 7th, 2026
Finite State appoints Ann Miller to scale product security and software supply chain strategy.

Finite State appoints Ann Miller to scale product security and software supply chain strategy. April 07, 2026 Finite State, a vendor of product security and software supply chain risk management, announced the appointment of Ann Miller as vice president of marketing. Miller brings more than 15 years of experience scaling high-growth technology companies, with deep expertise in cybersecurity and AI-driven platforms, and turning emerging technologies into market-defining categories. Miller joins Finite State at a pivotal moment as enterprises face increasing pressure to secure software embedded across critical infrastructure, connected devices, and regulated environments. Her appointment underscores the company's commitment to defining the future of product security through data, automation, and AI. "Ann has a proven track record of building category-defining marketing engines in cybersecurity," said Matt Wyckhouse, CEO of Finite State. "Her ability to translate complex, technical innovation into market leadership will be instrumental as we accelerate our growth and expand our position in product security." Prior to joining Finite State, Miller led marketing at Horizon3.ai, where she helped scale the company from early-stage to thousands of customers, driving rapid market adoption. During her tenure, Horizon3.ai was recognized as the #1 fastest-growing cybersecurity company on the 2025 Inc. 5000 list and established leadership in autonomous security testing. Earlier in her career, she held strategic roles at Cylance, a pioneer in AI-driven endpoint security, and iboss, a leader in cloud security. "Product security is quickly becoming one of the most critical and under-addressed challenges in cybersecurity," said Miller. "What impressed me about Finite State is what they've built. It's an AI-native platform that automates product security end to end, from deep binary analysis through prioritization and remediation across the software supply chain. That's incredibly hard to do, and has been a key driver in building trust across their customer base." Miller will lead all aspects of marketing, including branding, demand generation, product marketing, and go-to-market strategy. She is the latest expansion of the Finite State executive team, following the February 2026 appointment of Sharon Hagi as chief security officer, and January 2026 appointment of Chris Overton as executive vice president of engineering. Hagi brings more than 30 years of experience building and operating security programs across semiconductors, IoT, embedded systems, AI-enabled platforms, and cloud environments. Leading Finite State's Security and Services organization, Hagi ensures execution, customer outcomes, and operational excellence. Overton brings more than 20 years of engineering leadership experience. He drives Finite State's engineering innovation at a critical stage of the company's growth, as device manufacturers face increasing pressure to ship faster while meeting requirements such as the EU Cyber Resilience Act and other emerging security mandates. Last May, Finite State expanded its executive team with the appointments of Tim Quock as chief operating officer and Beth Linker as chief product officer. The additions come as the company accelerates its global efforts to secure connected systems across critical infrastructure. Quock has a background in guiding security companies through key growth stages, with experience supporting solutions used by Fortune 1000 organizations. Industrial Cyber News Desk

Morningstar
Apr 24th, 2025
Somos Partners with Finite State to Strengthen Supply Chain Security through Enhanced Binary and Source Code Analysis and SBOM Solutions

EAST BRUNSWICK, N.J. and COLUMBUS, Ohio, April 24, 2025 /PRNewswire/ - Somos, Inc., an industry expert in connected device security intelligence services, identity management and fraud prevention, is pleased to announce its partnership with Finite State, an IoT security organization providing comprehensive software risk management solutions.

Cision
Jun 27th, 2024
Finite State Acquires MergeBase to Form a Powerhouse in Application Security

/PRNewswire-PRWeb/ -- Finite State, Inc., the leader in comprehensive software risk management for the connected world, announced today the acquisition of...

Unable to determine - website not found in search results
Mar 23rd, 2024
Finite State Raises $20 Million to Grow Software Supply Chain Security Business

Finite State raises $20 million to grow software supply chain security business.

VC News Daily
Mar 22nd, 2024
Finite State Raises $20 Million Growth Round

Finite State Raises $20 Million Growth Round Back to HomeCOLUMBUS, OH, Finite State, the leader in comprehensive software risk management for the connected world, announced that it raised a $20 million growth round led by Energy Impact Partners (EIP).Finite State, the leader in comprehensive software risk management for the connected world, announced that it raised a $20 million growth round led by Energy Impact Partners (EIP). This investment underscores Finite State's pivotal role in addressing critical cybersecurity challenges faced by organizations worldwide and its commitment to advancing innovative solutions for securing connected devices and critical infrastructure.(c) by Massinvestor, Inc. For contact info, please check out our about page

INACTIVE