Full-Time

IoT / ICS / OT Penetration Tester

Finite State

Finite State

51-200 employees

Automates product security for connected devices.

No salary listed

Remote in USA + 1 more

More locations: Remote in Canada

Remote

Category
IT & Security (1)
Required Skills
LLM
Bash
Python
RISC
C/C++
Requirements
  • Bachelor's degree in Computer Science, Electrical Engineering, Computer Engineering, or a related field
  • 5+ years of hands-on experience in IoT, embedded, ICS/OT, or automotive security.
  • Demonstrated experience performing hardware-level security assessments: JTAG/SWD debugging, SPI/I2C/UART communication, flash memory extraction, and PCB soldering and rework.
  • Proficiency with firmware reverse engineering tools, specifically Ghidra and/or Binary Ninja; ability to analyze ARM, MIPS, PPC, x86, and x64 architectures.
  • Experience testing IoT and automotive wireless protocols, including BLE, Zigbee, Z-Wave, Wi-Fi, CAN bus, and cellular interfaces.
  • Ability to read and review source code in C and C++ to identify memory safety issues, authentication flaws, and other security weaknesses in embedded software.
  • Familiarity with SBOM concepts, formats (CycloneDX, SPDX), and the use of SBOMs in vulnerability management.
  • Working knowledge of relevant regulations and standards, including at least a subset of: EU CRA, CE RED / EN 303 645, UNECE WP.29, ISO 21434, or the US IoT Cyber Trust Mark.
  • Excellent written and verbal communication skills; proven ability to write clear, well-structured technical reports and present findings to diverse audiences.
  • Experience with scripting and automation using Python and Bash to support tooling and workflow efficiency.
  • Familiarity with AI-assisted security tooling and an interest in applying LLM-based workflows to accelerate security analysis and reporting.
Responsibilities
  • Plan and execute penetration tests and security assessments against IoT, ICS/OT, and automotive targets, including connected consumer devices, industrial controllers, and automotive ECUs and telematics units.
  • Perform hardware interaction and firmware extraction using techniques such as JTAG, SWD, UART, SPI, I2C, eMMC, and NAND flash dumping; solder and rework PCBs as needed to gain access to debug interfaces.
  • Conduct firmware reverse engineering using tools such as Ghidra and Binary Ninja to identify vulnerabilities including memory corruption, authentication bypasses, hard-coded credentials, and insecure update mechanisms.
  • Assess wireless protocols common in IoT and automotive environments, including Bluetooth / BLE, Zigbee, Z-Wave, Wi-Fi, Cellular (LTE/5G), CAN bus, LIN, and automotive Ethernet.
  • Perform source code review, primarily in C, C++, and related embedded languages, to identify security weaknesses in firmware and embedded software.
  • Conduct supply chain and software composition analysis, including SBOM review and analysis of third-party open-source components, to identify known vulnerabilities and license risks.
  • Evaluate customer products and programs for compliance with relevant regulations and standards, including EN 303 645, the EU Cyber Resilience Act (CRA), EU Radio Equipment Directive (CE RED), UNECE WP.29 / ISO 21434 for automotive, and the US IoT Cyber Trust Mark.
  • Produce high-quality written reports that clearly communicate technical findings, risk ratings, and remediation guidance to both technical and executive audiences.
  • Leverage AI-powered security tooling and LLM-assisted workflows to accelerate analysis, triage, and reporting; maintain awareness of evolving AI capabilities relevant to embedded security research.
  • Collaborate with the product, engineering, and research teams to feed pentesting findings back into the Finite State platform and improve detection capabilities.
  • Support customer-facing engagements including scoping calls, technical debriefs, and remediation follow-up.
  • Contribute to internal knowledge sharing, tooling development, and methodology improvement.
  • Participate in industry conferences, publish research, and represent Finite State externally as opportunities arise.
Desired Qualifications
  • Hands-on automotive security experience: OBD-II assessment, ECU flashing and analysis, V2X protocols, or automotive HSM evaluation.
  • Experience with industrial control system (ICS/SCADA) security assessments and familiarity with protocols such as Modbus, DNP3, EtherNet/IP, or OPC-UA.
  • CVE or responsible disclosure history demonstrating original vulnerability research in embedded or IoT targets.
  • Relevant certifications such as OSCP, GPEN, GICSP, or vendor-specific automotive security credentials.
  • Familiarity with static and dynamic analysis platforms and SAST/DAST tooling in the context of firmware and embedded software.
  • Experience with ML-based vulnerability detection models or AI-augmented reverse engineering pipelines.
  • Experience working on small, fast-moving consulting or product security teams.
  • Comfort operating in AWS or similar cloud environments used to support analysis pipelines or customer deliverables.

Finite State automates product security for connected devices and embedded systems such as IoT, medical devices, ICS, and OT. Its platform provides deep visibility into device and supply chain risks and helps with compliance, delivered through a subscription service for continuous visibility and actionable remediation of security issues.

Company Size

51-200

Company Stage

Late Stage VC

Total Funding

$69.5M

Headquarters

Columbus, Ohio

Founded

2017

Simplify Jobs

Simplify's Take

What believers are saying

  • Raised $20M growth round in March 2024 led by Energy Impact Partners.
  • Appointed Ann Miller as VP Marketing in April 2026 to scale go-to-market.
  • Partnered with Somos and Quectel to enhance supply chain security offerings.

What critics are saying

  • Black Duck undercuts subscriptions with broader SCA, capturing 35% larger market share.
  • Snyk replicates binary analysis, eroding 25% IoT customers via freemium pricing.
  • Microsoft Defender bundles free scanning, displacing 70% cloud-dependent medical clients.

What makes Finite State unique

  • Finite State's Reachability Engine reduces vulnerability noise by 90% via execution context analysis.
  • AgentOS automates design-to-binary reconciliation and generates EU CRA compliance packages.
  • Platform ingests 120+ data sources for unified SBOM management across firmware and apps.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Finite State who can refer or advise you

Benefits

Professional Development Budget

Company Equity

Remote Work Options

Growth & Insights and Company News

Headcount

6 month growth

-3%

1 year growth

-2%

2 year growth

2%
Industrial Cyber
Apr 7th, 2026
Finite State appoints Ann Miller to scale product security and software supply chain strategy.

Finite State appoints Ann Miller to scale product security and software supply chain strategy. April 07, 2026 Finite State, a vendor of product security and software supply chain risk management, announced the appointment of Ann Miller as vice president of marketing. Miller brings more than 15 years of experience scaling high-growth technology companies, with deep expertise in cybersecurity and AI-driven platforms, and turning emerging technologies into market-defining categories. Miller joins Finite State at a pivotal moment as enterprises face increasing pressure to secure software embedded across critical infrastructure, connected devices, and regulated environments. Her appointment underscores the company's commitment to defining the future of product security through data, automation, and AI. "Ann has a proven track record of building category-defining marketing engines in cybersecurity," said Matt Wyckhouse, CEO of Finite State. "Her ability to translate complex, technical innovation into market leadership will be instrumental as we accelerate our growth and expand our position in product security." Prior to joining Finite State, Miller led marketing at Horizon3.ai, where she helped scale the company from early-stage to thousands of customers, driving rapid market adoption. During her tenure, Horizon3.ai was recognized as the #1 fastest-growing cybersecurity company on the 2025 Inc. 5000 list and established leadership in autonomous security testing. Earlier in her career, she held strategic roles at Cylance, a pioneer in AI-driven endpoint security, and iboss, a leader in cloud security. "Product security is quickly becoming one of the most critical and under-addressed challenges in cybersecurity," said Miller. "What impressed me about Finite State is what they've built. It's an AI-native platform that automates product security end to end, from deep binary analysis through prioritization and remediation across the software supply chain. That's incredibly hard to do, and has been a key driver in building trust across their customer base." Miller will lead all aspects of marketing, including branding, demand generation, product marketing, and go-to-market strategy. She is the latest expansion of the Finite State executive team, following the February 2026 appointment of Sharon Hagi as chief security officer, and January 2026 appointment of Chris Overton as executive vice president of engineering. Hagi brings more than 30 years of experience building and operating security programs across semiconductors, IoT, embedded systems, AI-enabled platforms, and cloud environments. Leading Finite State's Security and Services organization, Hagi ensures execution, customer outcomes, and operational excellence. Overton brings more than 20 years of engineering leadership experience. He drives Finite State's engineering innovation at a critical stage of the company's growth, as device manufacturers face increasing pressure to ship faster while meeting requirements such as the EU Cyber Resilience Act and other emerging security mandates. Last May, Finite State expanded its executive team with the appointments of Tim Quock as chief operating officer and Beth Linker as chief product officer. The additions come as the company accelerates its global efforts to secure connected systems across critical infrastructure. Quock has a background in guiding security companies through key growth stages, with experience supporting solutions used by Fortune 1000 organizations. Industrial Cyber News Desk

Morningstar
Apr 24th, 2025
Somos Partners with Finite State to Strengthen Supply Chain Security through Enhanced Binary and Source Code Analysis and SBOM Solutions

EAST BRUNSWICK, N.J. and COLUMBUS, Ohio, April 24, 2025 /PRNewswire/ - Somos, Inc., an industry expert in connected device security intelligence services, identity management and fraud prevention, is pleased to announce its partnership with Finite State, an IoT security organization providing comprehensive software risk management solutions.

Cision
Jun 27th, 2024
Finite State Acquires MergeBase to Form a Powerhouse in Application Security

/PRNewswire-PRWeb/ -- Finite State, Inc., the leader in comprehensive software risk management for the connected world, announced today the acquisition of...

Unable to determine - website not found in search results
Mar 23rd, 2024
Finite State Raises $20 Million to Grow Software Supply Chain Security Business

Finite State raises $20 million to grow software supply chain security business.

VC News Daily
Mar 22nd, 2024
Finite State Raises $20 Million Growth Round

Finite State Raises $20 Million Growth Round Back to HomeCOLUMBUS, OH, Finite State, the leader in comprehensive software risk management for the connected world, announced that it raised a $20 million growth round led by Energy Impact Partners (EIP).Finite State, the leader in comprehensive software risk management for the connected world, announced that it raised a $20 million growth round led by Energy Impact Partners (EIP). This investment underscores Finite State's pivotal role in addressing critical cybersecurity challenges faced by organizations worldwide and its commitment to advancing innovative solutions for securing connected devices and critical infrastructure.(c) by Massinvestor, Inc. For contact info, please check out our about page