Senior Engineer - Penetration Testing

New
F
Finite StateProduct security
Remote, United States - no relocation required.Full-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
7+ years of hands-on experience in IoT, embedded, ICS/OT, or automotive security
Required Skills
Python

Requirements

  • Bachelor's degree in Computer Science, Electrical Engineering, Computer Engineering, or a related field, or equivalent hands-on experience.
  • 7+ years of hands-on experience in IoT, embedded, ICS/OT, or automotive security, including autonomously owning engagements at a senior level.
  • Hands-on depth in at least one target domain—IoT/embedded, ICS/OT, or automotive—and working familiarity with the other two.
  • Experience with hardware-level security assessments, including JTAG/SWD debugging, SPI/I2C/UART communication, and flash memory extraction.
  • Comfort soldering and reworking PCBs to access debug interfaces.
  • Proficiency with Ghidra and/or Binary Ninja and ability to analyze ARM, MIPS, PPC, RISC-V, x86, and x64 architectures.
  • Experience testing wireless protocols and either vehicle buses or industrial control protocols.
  • Working familiarity with network protocols and web or mobile application testing methodology.
  • Ability to read and review C and C++ source code for security weaknesses in embedded software.
  • Familiarity with SBOM concepts and CycloneDX or SPDX formats.
  • Working fluency with CVSS scoring and VEX, including defending exploitability determinations to customers.
  • Experience mapping findings to at least one relevant regulatory or standards framework.
  • Experience with Python and Bash scripting and automation.
  • Familiarity with AI-assisted security tooling and LLM-based analysis and reporting workflows.

Responsibilities

  • Plan and execute penetration tests against IoT, ICS/OT, and automotive targets.
  • Own engagements, including scoping, attack-surface prioritization, testing, evidence collection, reporting, and debriefs.
  • Use the Finite State platform alongside hands-on testing to assess which vulnerabilities are reachable and exploitable.
  • Perform hardware interaction and firmware extraction using debugging interfaces, communication protocols, and flash memory techniques.
  • Conduct firmware reverse engineering to identify security vulnerabilities.
  • Assess wireless protocols, vehicle buses, industrial control protocols, network protocols, and companion applications and APIs.
  • Review embedded source code and third-party or open-source components for security weaknesses and supply-chain risks.
  • Produce reports with technical findings, risk ratings, CVSS scores, VEX justifications, and remediation guidance.
  • Participate in peer review and support customer scoping calls, technical debriefs, and remediation follow-up.
  • Collaborate with product, engineering, and research teams and contribute to tooling, knowledge sharing, and methodology improvements.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now