Senior Engineer - Penetration Testing
New
F
Finite StateProduct security
Remote, United States - no relocation required.Full-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 7+ years of hands-on experience in IoT, embedded, ICS/OT, or automotive security
- Required Skills
- PythonBashC++
Requirements
- Bachelor's degree in Computer Science, Electrical Engineering, Computer Engineering, or a related field, or equivalent hands-on experience.
- 7+ years of hands-on experience in IoT, embedded, ICS/OT, or automotive security, including autonomous ownership of senior-level engagements.
- Hands-on depth in at least one of IoT/embedded, ICS/OT, or automotive security, with working familiarity in the other two.
- Experience with hardware-level security assessments, including JTAG/SWD debugging, SPI/I2C/UART communication, and flash-memory extraction.
- Comfort soldering and reworking PCBs to access debug interfaces; fine-pitch and BGA rework is a plus.
- Proficiency with Ghidra and/or Binary Ninja and ability to analyze ARM, MIPS, PPC, RISC-V, x86, and x64 architectures.
- Experience testing wireless protocols and either vehicle buses or industrial control protocols.
- Working familiarity with network protocols and web/mobile application testing methodology.
- Ability to read and review C and C++ source code for security weaknesses.
- Familiarity with SBOM concepts and CycloneDX and SPDX formats.
- Working fluency with CVSS scoring and VEX.
- Experience mapping findings to at least one relevant regulatory or standards framework.
- Experience scripting and automating workflows with Python and Bash.
- Familiarity with AI-assisted security tooling and LLM-based workflows.
Responsibilities
- Plan and execute penetration tests against IoT, ICS/OT, and automotive targets.
- Own engagements, including scoping, attack-surface prioritization, testing, evidence collection, reporting, and debriefs.
- Use the Finite State platform and hands-on testing to identify vulnerabilities that are reachable and exploitable on target hardware.
- Perform hardware interaction and firmware extraction using debug interfaces, communication protocols, and flash-memory techniques.
- Reverse engineer firmware and review embedded source code to identify security weaknesses.
- Assess wireless protocols, vehicle buses, industrial control protocols, network protocols, and companion applications and APIs.
- Review third-party and open-source components and SBOMs for vulnerabilities and license risk.
- Write reports with technical findings, risk ratings, CVSS scores, and remediation guidance for technical and executive audiences.
- Participate in peer review, customer debriefs, and remediation follow-up.
- Collaborate with product, engineering, and research teams to improve platform detection, tools, and methodologies.
View Full Description & ApplyYou'll be redirected to the employer's site