Senior Engineer - Penetration Testing
New
F
Finite StateProduct security
Remote, United States - no relocation required.Full-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 7+ years of hands-on experience in IoT, embedded, ICS/OT, or automotive security
- Required Skills
- Python
Requirements
- Bachelor's degree in Computer Science, Electrical Engineering, Computer Engineering, or a related field, or equivalent hands-on experience.
- 7+ years of hands-on experience in IoT, embedded, ICS/OT, or automotive security, including autonomously owning engagements at a senior level.
- Hands-on depth in at least one target domain—IoT/embedded, ICS/OT, or automotive—and working familiarity with the other two.
- Experience with hardware-level security assessments, including JTAG/SWD debugging, SPI/I2C/UART communication, and flash memory extraction.
- Comfort soldering and reworking PCBs to access debug interfaces.
- Proficiency with Ghidra and/or Binary Ninja and ability to analyze ARM, MIPS, PPC, RISC-V, x86, and x64 architectures.
- Experience testing wireless protocols and either vehicle buses or industrial control protocols.
- Working familiarity with network protocols and web or mobile application testing methodology.
- Ability to read and review C and C++ source code for security weaknesses in embedded software.
- Familiarity with SBOM concepts and CycloneDX or SPDX formats.
- Working fluency with CVSS scoring and VEX, including defending exploitability determinations to customers.
- Experience mapping findings to at least one relevant regulatory or standards framework.
- Experience with Python and Bash scripting and automation.
- Familiarity with AI-assisted security tooling and LLM-based analysis and reporting workflows.
Responsibilities
- Plan and execute penetration tests against IoT, ICS/OT, and automotive targets.
- Own engagements, including scoping, attack-surface prioritization, testing, evidence collection, reporting, and debriefs.
- Use the Finite State platform alongside hands-on testing to assess which vulnerabilities are reachable and exploitable.
- Perform hardware interaction and firmware extraction using debugging interfaces, communication protocols, and flash memory techniques.
- Conduct firmware reverse engineering to identify security vulnerabilities.
- Assess wireless protocols, vehicle buses, industrial control protocols, network protocols, and companion applications and APIs.
- Review embedded source code and third-party or open-source components for security weaknesses and supply-chain risks.
- Produce reports with technical findings, risk ratings, CVSS scores, VEX justifications, and remediation guidance.
- Participate in peer review and support customer scoping calls, technical debriefs, and remediation follow-up.
- Collaborate with product, engineering, and research teams and contribute to tooling, knowledge sharing, and methodology improvements.
View Full Description & ApplyYou'll be redirected to the employer's site