Senior Engineer - Penetration Testing

New
F
Finite StateProduct security
Remote, United States - no relocation required.Full-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
7+ years of hands-on experience in IoT, embedded, ICS/OT, or automotive security
Required Skills
PythonBashC++

Requirements

  • Bachelor's degree in Computer Science, Electrical Engineering, Computer Engineering, or a related field, or equivalent hands-on experience.
  • 7+ years of hands-on experience in IoT, embedded, ICS/OT, or automotive security, including autonomous ownership of senior-level engagements.
  • Hands-on depth in at least one of IoT/embedded, ICS/OT, or automotive security, with working familiarity in the other two.
  • Experience with hardware-level security assessments, including JTAG/SWD debugging, SPI/I2C/UART communication, and flash-memory extraction.
  • Comfort soldering and reworking PCBs to access debug interfaces; fine-pitch and BGA rework is a plus.
  • Proficiency with Ghidra and/or Binary Ninja and ability to analyze ARM, MIPS, PPC, RISC-V, x86, and x64 architectures.
  • Experience testing wireless protocols and either vehicle buses or industrial control protocols.
  • Working familiarity with network protocols and web/mobile application testing methodology.
  • Ability to read and review C and C++ source code for security weaknesses.
  • Familiarity with SBOM concepts and CycloneDX and SPDX formats.
  • Working fluency with CVSS scoring and VEX.
  • Experience mapping findings to at least one relevant regulatory or standards framework.
  • Experience scripting and automating workflows with Python and Bash.
  • Familiarity with AI-assisted security tooling and LLM-based workflows.

Responsibilities

  • Plan and execute penetration tests against IoT, ICS/OT, and automotive targets.
  • Own engagements, including scoping, attack-surface prioritization, testing, evidence collection, reporting, and debriefs.
  • Use the Finite State platform and hands-on testing to identify vulnerabilities that are reachable and exploitable on target hardware.
  • Perform hardware interaction and firmware extraction using debug interfaces, communication protocols, and flash-memory techniques.
  • Reverse engineer firmware and review embedded source code to identify security weaknesses.
  • Assess wireless protocols, vehicle buses, industrial control protocols, network protocols, and companion applications and APIs.
  • Review third-party and open-source components and SBOMs for vulnerabilities and license risk.
  • Write reports with technical findings, risk ratings, CVSS scores, and remediation guidance for technical and executive audiences.
  • Participate in peer review, customer debriefs, and remediation follow-up.
  • Collaborate with product, engineering, and research teams to improve platform detection, tools, and methodologies.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now