Full-Time

MTS Manager

Finite State

Finite State

51-200 employees

Automates product security for connected devices.

Compensation Overview

$200k - $215k/yr

+ Equity

Remote in USA + 1 more

More locations: Remote in Canada

Remote

Bachelor's

Category
Engineering Management (1)
Required Skills
Reverse Engineering
Vulnerability Analysis
SOC 2
Cryptography

Get referred to Finite State

See people who can refer or advise you

Requirements
  • Bachelor's degree in Computer Science, Mathematics, Physical Sciences, Electrical/Computer Engineering, or equivalent demonstrable experience and certifications; advanced degree desirable
  • Minimum 8 years of relevant experience in product security, embedded/connected device security, application security, or offensive security — a meaningful portion delivered in a customer-facing services, consulting, or managed services context
  • Minimum 4 years of direct people management experience, including hiring, performance management, mentorship, and team development
  • Demonstrated experience standing up new service offerings or productizing technical capabilities within a managed services or information technology environments is strongly preferred
  • Hands-on technical depth in two or more of: binary/firmware analysis, penetration testing of embedded or IoT systems, threat modeling and TARA, SBOM and software composition analysis, vulnerability management and disclosure (CVE/CNA workflows), PSIRT/ESIRT operations
  • Deep working knowledge of connected and embedded device security, including firmware, microcontrollers, wireless System on Chips, RTOS environments, and integrated IoT systems
  • Hands-on familiarity with binary and firmware analysis tooling and methodology (Ghidra, IDA, Binary Ninja, radare2, and platform-driven equivalents)
  • Strong understanding of SBOM standards (SPDX, CycloneDX), VEX, software composition analysis, and vulnerability correlation against CVE/CPE/PURL
  • Strong understanding of vulnerability disclosure and PSIRT operating models, including ISO/IEC 29147 (vulnerability disclosure) and ISO/IEC 30111 (vulnerability handling), CVSS v3.1/v4, and CNA operating procedures
  • Familiarity with offensive security methodology applied to embedded systems, including hardware-adjacent attacks (fault injection, side-channel concepts, debug interface exploitation) at a depth sufficient to scope, review, and quality-control the work
  • Working knowledge of TARA methodologies (ISO/SAE 21434 for automotive, IEC 62443-3-2 for industrial, MITRE ATT&CK and EMB3D where applicable)
  • Working knowledge of applied cryptography, secure protocols, secure boot, secure update, and key management as applied to embedded systems
  • Ability to ramp quickly on AI and agentic AI platforms and productivity systems; familiarity with the automated firmware/binary analysis platform category and AI-assisted vulnerability triage is preferred
  • Working knowledge of EU Cyber Resilience Act (CRA), including Annex I essential requirements, vulnerability handling obligations, conformity assessment routes, and post-market surveillance expectations
  • Working knowledge of IEC 62443, ETSI EN 303 645, NIST IR 8259 series, NIST SSDF (SP 800-218), and US Executive Order 14028 / OMB M-22-18 SBOM requirements
  • Familiarity with ISO 27001, SOC 2 Type I/II, and adjacent compliance regimes as they apply to a managed services delivery organization
  • Demonstrated ability to design and operate service delivery functions to defined SLAs, SLOs, and quality standards
  • Demonstrated ability to manage utilization, capacity, and engagement profitability in a billable services context
  • Strong project and program management capability
  • Excellent written and verbal communication skills; operates fluently with executives, technical individual contributors, customer technical staff, customer executives, regulators, and partners
  • Strong people leadership: hiring, coaching, performance management, conflict resolution, and team building in a fully remote environment
  • Demonstrated ability to translate technical findings into business and regulatory consequences for non-technical stakeholders
  • Customer-facing executive presence: owns escalations, leads difficult conversations, and represents Finite State at the most senior levels of customer organizations
  • One or more of the following is required: CISSP, CSSLP, CCSP, GIAC (GPEN/GXPN/GREM/GICSP), OSCP, or equivalent demonstrated technical depth
  • One or more of the following is desirable: CISM, CRISC, CISA, ISO/IEC 27001 Lead Auditor or Lead Implementer, IEC 62443 Cybersecurity Expert, PMP/PgMP, ITIL Foundation or higher
  • Familiarity with vulnerability analysis and reverse engineering tools
  • Familiarity with SAST/DAST/IAST tooling categories
  • Familiarity with offensive security tooling
  • Familiarity with collaboration and delivery tooling
  • Comfort operating in a fully remote, cloud-only company environment
Responsibilities
  • Manages day-to-day execution of all active managed technical services customer engagements; ensures delivery quality, technical accuracy, schedule adherence, and consistent application of Finite State methodology across binary analysis, penetration testing, TARA, SBOM/SCA, vulnerability management, and remediation advisory
  • Owns the full engagement lifecycle: scoping, statement of work, kickoff, execution, deliverable review, customer communications, and renewal/expansion planning
  • Establishes, maintains, and continuously improves service delivery playbooks, technical methodologies, deliverable templates, peer review gates, and quality acceptance criteria
  • Drives consistent integration of Finite State automation platform into every engagement; ensures platform capabilities are leveraged to maximum effect and that field experience feeds the platform roadmap
  • Defines, monitors, and reports Service Level Agreements (SLAs), Service Level Objectives (SLOs), and engagement-level KPIs including billable utilization, time-to-deliverable, defect/escape rates, customer satisfaction (CSAT/NPS), and renewal rate
  • Acts as senior technical escalation point for engagement issues, customer concerns, and complex or contested technical findings
  • Leads operational design and standup of new product security managed service offerings — PSIRTaaS, EU CRA sustainable compliance, and other emerging services — including process design, runbook authoring, tooling integration, staffing model, pricing inputs, contractual scaffolding, and SLA framework
  • Partners with Product to ensure platform capabilities required for new managed services are scoped, prioritized, instrumented, and operationalized for service delivery
  • Designs and operates the customer-facing PSIRTaaS function: continuous vulnerability monitoring, automated and human-assisted triage, advisory issuance, CVE coordination with the appropriate CNA, customer disclosure workflow, remediation tracking, and post-disclosure verification
  • Builds the operating model for sustainable EU CRA compliance services: conformity assessment support, Annex I essential requirements mapping, vulnerability handling obligations, technical documentation maintenance, and post-market surveillance support for connected product manufacturers
  • Hires, onboards, develops, mentors, and retains a team of product security engineers and analysts across multiple technical disciplines (binary/firmware analysis, offensive security, embedded systems, SBOM/SCA, regulatory engineering, vulnerability management)
  • Sets individual performance objectives aligned to team and company OKRs; conducts regular 1:1s, delivers ongoing performance feedback, runs formal review cycles, and addresses performance issues directly and constructively
  • Builds and maintains team capacity plans and skills inventories; identifies gaps and drives hiring, cross-training, certification, and external training plans to close them
  • Manages utilization across the team to balance billable engagement work, capability development, and reserved capacity for new service launches and surge demand
  • Cultivates a culture of technical excellence, intellectual honesty, customer empathy, peer review, and continuous learning; fosters psychological safety in a fully remote operating environment
  • Serves as senior delivery contact and trusted technical advisor for strategic customer accounts; owns the technical health of those relationships
  • Leads recurring service reviews, escalation discussions, and quarterly business reviews; ensures customer outcomes are visible, measurable, and tied to renewal and expansion narratives
  • Partners with Sales on scoping, statements of work, pricing alignment, and pre-sales technical engagement; provides expert input to deal qualification and risk
  • Identifies and qualifies expansion opportunities (additional products, additional service lines, multi-year commitments) and works with Sales to convert them
  • Owns operational delivery against the Services ARR plan; accountable for margin discipline, utilization targets, and forecast accuracy
  • Provides input to pricing, packaging, and capacity planning for current and new service offerings
  • Tracks and reports delivery cost, gross margin per engagement, write-down and write-off rates, and other services-economics metrics; surfaces structural issues with concrete remediation proposals
  • Produces timely, accurate forecasts of staffing, hiring, and external contractor needs against the demand pipeline

Finite State automates product security for connected devices and embedded systems such as IoT, medical devices, ICS, and OT. Its platform provides deep visibility into device and supply chain risks and helps with compliance, delivered through a subscription service for continuous visibility and actionable remediation of security issues.

Company Size

51-200

Company Stage

Late Stage VC

Total Funding

$69.5M

Headquarters

Columbus, Ohio

Founded

2017

Get referred to Finite State

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Finite State won the 2026 IoT Industrial Solutions Award on June 29.
  • DEF CON 2026 sessions and manufacturing challenge keep Finite State visible to operators.
  • Ann Miller joined April 7 2026, sharpening category marketing and demand generation.

What critics are saying

  • AgentOS stayed private preview on February 17 2026, delaying broad revenue proof.
  • Synopsys and Microsoft bundle adjacent supply-chain tools, compressing Finite State pricing.
  • If OEMs standardize on bundled SBOM tooling, Finite State becomes a feature, not a company.

What makes Finite State unique

  • Finite State's AgentOS launch, February 17 2026, unifies firmware, source, and design evidence.
  • MergeBase's June 27 2024 acquisition adds source-code analysis to binary-first product security.
  • The platform auto-generates SBOM, VEX, and traceability reports for regulated devices.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Professional Development Budget

Company Equity

Remote Work Options

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

1%

2 year growth

1%
Finite State
Jul 16th, 2026
Past events.

Past events. From SBOM to submission: operationalizing CRA vulnerability handling. Webinar Virtual The September 11, 2026 CRA deadline is approaching. Join Finite State and ISMG to learn the practical steps manufacturers should take now to build a risk-based vulnerability handling process, prioritize real exposure, and maintain the evidence needed to support ongoing CRA compliance. Thursday, July 16, 2026 12:00 PM EDT Zoom meeting Auto-ISAC Europe Cybersecurity Workshop 2026. Conference In-Person Join Finite State in Maranello for the Auto-ISAC Europe Cybersecurity Workshop, June 23-25. Meet with our team to discuss how automotive organizations can prioritize real exposure and continuously produce audit-ready proof across software-defined vehicle platforms. Jun 24 - Jun 25, 2026 2:00 PM GMT+2 Ferrari Museum, Maranello, Italy Hackers Teaching Hackers 2026. Conference In-Person Join Finite State at Hackers Teaching Hackers, June 3-6 in Canal Winchester, Ohio. Meet with our team to discuss how security teams can unify firmware and source intelligence, prioritize real exposure, and continuously produce audit-ready proof across connected systems and embedded products. Jun 3 - Jun 5, 2026 8:00 AM EDT BrewDog Brewery and TapRoom, Canal Winchester ESCAR 2026. Conference In-Person Join Finite State in Novi for ESCAR USA, May 19-21. Meet with our team to discuss how OEMs and suppliers can unify firmware and source intelligence, prioritize real exposure, and continuously produce audit-ready proof across connected vehicle platforms. May 19 - May 21, 2026 9:00 AM EDT Sheraton Detroit Novi Hotel, Novi IoT Tech Expo north america 2026. Conference In-Person At IoT Tech Expo, see how Finite State transforms firmware, binaries, and source into a single, continuous workflow that prioritizes real exposure and produces audit-ready proof every release. May 18 - May 19, 2026 6:00 AM PDT San Jose McEnery Convention Center, San Jose Health ISAC Spring Summit 2026. Conference In-Person At the Health ISAC Spring Summit 2026, meet with Finite State to see how medical device teams unify firmware, binaries, and source intelligence, prioritize real exposure with reachability, and continuously produce audit-ready security and compliance proof grounded in what actually ships. May 4 - May 8, 2026 1:00 PM EDT Saddlebrook Resort Florida, Wesley Chapel, United States Wi-Fi World congress. Conference In-Person Join Finite State at WiFi World 2026 to see how organizations gain full visibility into shipped software, prioritize real risk with reachability, and produce continuous, audit-ready security and compliance proof. Apr 13 - Apr 15, 2026 6:30 AM PDT Computer History Museum, Mountain View, United States VulnCon 2026. Conference In-Person At VulnCon 2026, meet with Finite State to see how organizations unify firmware and source intelligence, prioritize real exposure with reachability, and continuously produce audit-ready proof grounded in what actually ships. Apr 13 - Apr 16, 2026 4:30 AM PDT DoubleTree Resort by Hilton Hotel Paradise Valley, Scottsdale, United States

Business Wire
Jun 22nd, 2026
Finite State CSO Sharon Hagi to present Auto-ISAC Europe Cybersecurity Workshop keynote "AI Closes the Window: Automotive Supply Chain Security in an Accelerated Threat Environment"

Finite State CSO Sharon Hagi to present Auto-ISAC Europe Cybersecurity Workshop keynote "AI Closes the Window: Automotive Supply Chain Security in an Accelerated Threat Environment" MARANELLO, Italy & COLUMBUS, Ohio-(BUSINESS WIRE)-Finite State, a leader in product security and software supply chain risk management, today announced that Chief Security Officer Sharon Hagi will present the keynote address "AI Closes the Window: Automotive Supply Chain Security in an Accelerated Threat Environment" at the Auto-ISAC (Information Sharing and Analysis Center) Europe Cybersecurity Workshop, 11:40 a.m.-12:10 p.m. Wednesday, June 24, 2026, at the Spazio Ferrari Maranello in Maranello, Italy. Modern cars are hackable in the same way any complex connected product is hackable. The most realistic risk is a chain of weaknesses across the vehicle, the mobile app, the cloud backend, or supplier-provided software. Share The session will explore the evolving realities of securing software-defined vehicle ecosystems and scaling defensible product security workflows across modern automotive development environments. With connected vehicle ecosystems becoming increasingly software-defined, automotive organizations face growing pressure to manage software complexity across ECUs and supply chains, reduce vulnerability noise, and continuously demonstrate security and compliance readiness across the product lifecycle. Hagi's keynote is designed to help European OEMs, suppliers, and mobility providers navigate evolving cybersecurity regulations, vulnerability disclosure expectations and issues, and the operational realities of securing modern vehicle platforms built on rapidly changing software. Recognizing that fragmented tools and manual workflows cannot keep pace with the scale and complexity of firmware-heavy systems, supplier ecosystems, and continuous software delivery, the session will help equip automotive security and engineering teams to move at the speed of modern vehicle development. Finite State CEO and Founder Matt Wyckhouse said, "Modern cars are hackable in the same way any complex connected product is hackable. The most realistic risk is a chain of weaknesses across the vehicle, the mobile app, the cloud backend, or supplier-provided software. "The industry has made real progress with secure update mechanisms, stronger engineering practices, vulnerability disclosure programs, SBOMs, and automotive cybersecurity standards. But the hard part is proving, continuously, what is actually in the vehicle and whether it is exposed, recognizing that it's impossible to secure what isn't understood." Finite State Live Demonstrations The Finite State team will run live demonstrations of artifact-backed workflows for connected vehicle security with: * Unified product intelligence - analyzing and connecting firmware, binaries, source, and supplier inputs into a complete, continuously updated system of record grounded in what actually ships across ECUs and vehicle platforms * Exploitability-based prioritization - focusing on real exposure using reachability and context, with a defensible rationale for what matters across in-vehicle systems and what does not * New CVE to impacted vehicle platforms - enabling teams to move from vulnerability disclosure to impact analysis quickly, with consistent VEX decisions and traceable outputs across ECUs, builds, and variants * Design-to-deployment traceability - connecting architecture, threats, risks, and requirements directly to deployed vehicle software, and keeping them aligned as systems evolve * Continuous compliance outputs - automatically generating SBOM, VEX, traceability, and audit-ready reports that stay current across releases and support evolving automotive cybersecurity regulations Attendees interested in meeting with the Finite State team during the Auto-ISAC Europe Cybersecurity Workshop 2026 can book a meeting here. About Finite State Finite State empowers device OEMs to ship securely while enabling engineering teams to move at the speed of AI, immediately transforming product artifacts into audit-ready assurance through a single automated workflow. Leveraging deep binary analysis and AI-native execution, the platform unifies code, compiled components, and firmware in minutes - connecting security design with deployed software. By continuously generating SBOMs, VEX, and signed compliance packages, Finite State enables connected device companies across industries such as medical devices and automotive to meet evolving regulations, including the EU Cyber Resilience Act (CRA), and deliver continuous compliance at speed. Learn more at https://finitestate.io/ More News From Finite State COLUMBUS, Ohio-( BUSINESS WIRE )-Finite State, a leader in product security and software supply chain risk management, today announced it has been named the winner in the Firmware Security & Vulnerability Analysis category in the 2026 Cybersecurity Stars Awards from The Hacker News.The award recognizes Finite State's leadership in helping manufacturers and product security teams understand, secure, and prove the integrity of the software running inside connected products. Through deep analys... SAN JOSE, Calif. & COLUMBUS, Ohio-( BUSINESS WIRE )-Finite State, a leader in connected device and product security, today announced that Founder and CEO Matt Wyckhouse will lead a panel on "Designing Connected Devices with Security Built In" at 2:35-3:20 p.m. PT, May 19, 2026, at IoT Tech Expo North America. The conference, one of the industry's largest gatherings focused on IoT, AI, cybersecurity, edge computing, and digital transformation, will be held at the San Jose McEnery Convention Cent... COLUMBUS, Ohio-( BUSINESS WIRE )-Finite State, a leader in product security and software supply chain risk management, today announced the appointment of Ann Miller as Vice President of Marketing. Miller brings more than 15 years of experience scaling high-growth technology companies, with deep expertise in cybersecurity and AI-driven platforms, and is known for turning emerging technologies into market-defining categories. Miller joins Finite State at a pivotal moment as enterprises face incre... Finite State. Release Versions

Industrial Cyber
Apr 7th, 2026
Finite State appoints Ann Miller to scale product security and software supply chain strategy.

Finite State appoints Ann Miller to scale product security and software supply chain strategy. April 07, 2026 Finite State, a vendor of product security and software supply chain risk management, announced the appointment of Ann Miller as vice president of marketing. Miller brings more than 15 years of experience scaling high-growth technology companies, with deep expertise in cybersecurity and AI-driven platforms, and turning emerging technologies into market-defining categories. Miller joins Finite State at a pivotal moment as enterprises face increasing pressure to secure software embedded across critical infrastructure, connected devices, and regulated environments. Her appointment underscores the company's commitment to defining the future of product security through data, automation, and AI. "Ann has a proven track record of building category-defining marketing engines in cybersecurity," said Matt Wyckhouse, CEO of Finite State. "Her ability to translate complex, technical innovation into market leadership will be instrumental as we accelerate our growth and expand our position in product security." Prior to joining Finite State, Miller led marketing at Horizon3.ai, where she helped scale the company from early-stage to thousands of customers, driving rapid market adoption. During her tenure, Horizon3.ai was recognized as the #1 fastest-growing cybersecurity company on the 2025 Inc. 5000 list and established leadership in autonomous security testing. Earlier in her career, she held strategic roles at Cylance, a pioneer in AI-driven endpoint security, and iboss, a leader in cloud security. "Product security is quickly becoming one of the most critical and under-addressed challenges in cybersecurity," said Miller. "What impressed me about Finite State is what they've built. It's an AI-native platform that automates product security end to end, from deep binary analysis through prioritization and remediation across the software supply chain. That's incredibly hard to do, and has been a key driver in building trust across their customer base." Miller will lead all aspects of marketing, including branding, demand generation, product marketing, and go-to-market strategy. She is the latest expansion of the Finite State executive team, following the February 2026 appointment of Sharon Hagi as chief security officer, and January 2026 appointment of Chris Overton as executive vice president of engineering. Hagi brings more than 30 years of experience building and operating security programs across semiconductors, IoT, embedded systems, AI-enabled platforms, and cloud environments. Leading Finite State's Security and Services organization, Hagi ensures execution, customer outcomes, and operational excellence. Overton brings more than 20 years of engineering leadership experience. He drives Finite State's engineering innovation at a critical stage of the company's growth, as device manufacturers face increasing pressure to ship faster while meeting requirements such as the EU Cyber Resilience Act and other emerging security mandates. Last May, Finite State expanded its executive team with the appointments of Tim Quock as chief operating officer and Beth Linker as chief product officer. The additions come as the company accelerates its global efforts to secure connected systems across critical infrastructure. Quock has a background in guiding security companies through key growth stages, with experience supporting solutions used by Fortune 1000 organizations. Industrial Cyber News Desk

Morningstar
Apr 24th, 2025
Somos Partners with Finite State to Strengthen Supply Chain Security through Enhanced Binary and Source Code Analysis and SBOM Solutions

EAST BRUNSWICK, N.J. and COLUMBUS, Ohio, April 24, 2025 /PRNewswire/ - Somos, Inc., an industry expert in connected device security intelligence services, identity management and fraud prevention, is pleased to announce its partnership with Finite State, an IoT security organization providing comprehensive software risk management solutions.

PR Newswire
Jun 27th, 2024
Finite State Acquires MergeBase to Form a Powerhouse in Application Security

/PRNewswire-PRWeb/ -- Finite State, Inc., the leader in comprehensive software risk management for the connected world, announced today the acquisition of...