{"id":2199285,"url":"https://alion.io/job/finitestate-senior-engineer-penetration-testing","title":"Senior Engineer - Penetration Testing","company":{"id":674179,"name":"Finitestate","domain":"finitestate.com","url":"https://alion.io/company/finitestate","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":{"grade":"B","score":75,"open_postings":4,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-10T05:45:15Z"}},"role":"Industrial Engineering","role_family":"Industrial Engineering","seniority":"senior","employment_type":null,"work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"posting_text","remote_working_hours":null,"hiring_geo_confidence":"explicit","locations":[],"countries":[],"hiring_countries":["US"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":83000,"max_usd":167000,"period":"year","method":"global_role_seniority_cell","sample_n":6537},"experience_years_min":7,"visa_sponsorship":true,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Binary Ninja","optional":false},{"name":"C++","optional":false},{"name":"CVSS","optional":false},{"name":"Ghidra","optional":false},{"name":"LLM","optional":false},{"name":"OPC UA","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"SBOM","optional":false},{"name":"TCP/IP","optional":false},{"name":"Wi-Fi","optional":false},{"name":"Zigbee","optional":false},{"name":"Assembly","optional":true},{"name":"AWS","optional":true},{"name":"CVE","optional":true},{"name":"Python","optional":true}],"status":"live","first_seen_at":"2026-10-09T18:26:12Z","employer_posted_date":"2026-10-09","last_verified_at":"2026-10-11T02:47:58Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"Finite State partners with product security teams, the guardians of our connected world, to create transparency for their connected devices and supply chains. Our platform handles connected devices and embedded systems across all industries, including those found in enterprises, healthcare, utilities, connected vehicles, manufacturing facilities, critical infrastructure, and government entities. \nWe are a fast-growing series-B company with a fully distributed workforce. Led by a team of seasoned experts, we are a mission-driven team passionate about arming our customers with the actionable insights, critical vulnerability data, and remediation guidance necessary to mitigate product risk and protect the connected attack surface. We are committed to a remote first culture.\nSenior Engineer - Penetration Testing \nDepartment: Services\nLocation: Remote, United States - no relocation required. Must be authorized to work in the U.S. without sponsorship.\nTravel: Limited - occasional trips for customer-site assessments, conferences, and team gatherings.\nEquipment: Finite State ships and funds your bench lab - soldering and rework station, probes, programmers, logic analyzer, and radios - to wherever you work. You do not fund your own gear, and the role is not tied to a company site.\nAbout the Role\nConnected products run the world: vehicles, medical devices, industrial systems, and critical infrastructure-and securing them is one of the hardest engineering problems there is.\nFinite State is seeking an experienced Senior Engineer - Penetration Testing to join our growing Offensive Security team. In this role you will conduct hands-on hardware and software penetration tests of connected devices, embedded systems, industrial control systems, and automotive platforms on behalf of our customers. You will combine deep hardware and firmware expertise with a consultative mindset to deliver clear, actionable findings that help manufacturers and operators understand and reduce risk.\nWhat makes this role different from a generalist penetration testing seat: you have Finite State's firmware analysis platform behind you, so your time goes to proving what is actually exploitable on real hardware rather than to building a baseline by hand.\nYour core mandate is hands-on penetration testing. Over time, as you build depth with our platform and customer base, there will be opportunities to expand your scope - platform integrations, direct account ownership, and building tools that drive the business.\nWhat You'll Do\nCore delivery - the majority of your time\nPlan and execute penetration tests against IoT, ICS/OT, and automotive targets, including connected consumer devices, industrial controllers, and automotive ECUs and telematics units.\nOwn engagements largely autonomously - scoping, prioritizing attack surfaces, testing, evidence, reporting, and debrief.\nUse Finite State's platform analysis alongside your own testing to focus effort on the vulnerabilities that are genuinely reachable and exploitable on the target.\nPerform hardware interaction and firmware extraction using techniques such as JTAG, SWD, UART, SPI, I2C, eMMC, NOR/SPI flash, and NAND flash dumping; solder and rework PCBs as needed to gain access to debug interfaces.\nConduct firmware reverse engineering using tools such as Ghidra and Binary Ninja to identify vulnerabilities including memory corruption, authentication bypasses, hard-coded credentials, and insecure update mechanisms.\nAssess wireless protocols common in IoT and automotive environments: Bluetooth/BLE, Zigbee, Z-Wave, Wi-Fi, and cellular (LTE/5G).\nAssess vehicle buses - CAN, LIN, and automotive Ethernet - and the industrial control protocols riding on ICS/OT networks, including Modbus, DNP3, EtherNet/IP, and OPC-UA.\nAssess standard network protocols and companion attack surfaces - TCP/IP fundamentals, exposed services, cloud and mobile companion apps and APIs - using standard web application testing methodology (e.g., OWASP Top 10) where relevant.\nPerform source code review, primarily in C, C++, and related embedded languages, to identify security weaknesses in firmware and embedded software.\nReview third-party and open-source components in scope for the engagement - SBOM review and software composition analysis - to identify known vulnerabilities and license risk in the customer's supply chain.\nLeverage AI-powered security tooling and LLM-assisted workflows to accelerate analysis, triage, and reporting, using approved tooling and honoring customer data-handling and NDA constraints on firmware and findings. Maintain awareness of evolving AI capabilities relevant to embedded security research.\nEvaluate customer products for compliance with relevant regulations and standards where in scope for the engagement.\nProduce high-quality written reports that clearly communicate technical findings, risk ratings, and remediation guidance to both technical and executive audiences. Score findings on CVSS and prioritize by demonstrated exploitability - a proven-exploitable medium outranks an unreachable critical - and support not-affected determinations with a defensible VEX justification.\nParticipate in peer review of engagement deliverables, both as author and reviewer, before reports reach the customer.\nSupport customer-facing engagements including scoping calls, technical debriefs, and remediation follow-up.\nBeyond delivery\nCollaborate with the product, engineering, and research teams to feed engagement findings back into the Finite State platform and improve its detection capabilities.\nContribute to internal knowledge sharing, tooling development, and methodology improvement.\nParticipate in industry conferences, publish research, and represent Finite State externally as opportunities arise.\nQualifications\nBachelor's degree in Computer Science, Electrical Engineering, Computer Engineering, or a related field (or equivalent hands-on experience), plus 7+ years of hands-on experience in IoT, embedded, ICS/OT, or automotive security, with a track record of owning engagements autonomously at a senior level.\nHands-on depth in at least one of our three target domains - IoT/embedded, ICS/OT, or automotive - plus working familiarity with the other two. We staff engagements across all three; we do not expect equal mastery of all three.\nDemonstrated experience performing hardware-level security assessments: JTAG/SWD debugging, SPI/I2C/UART communication, and flash memory extraction. Comfort soldering and reworking PCBs to reach a debug interface is expected; fine-pitch and BGA rework is a plus, not a gate.\nProficiency with firmware reverse engineering tools, specifically Ghidra and/or Binary Ninja; ability to analyze ARM, MIPS, PPC, RISC-V, x86, and x64 architectures.\nExperience testing wireless protocols (BLE, Zigbee, Z-Wave, Wi-Fi, cellular) and either vehicle buses (CAN, LIN, automotive Ethernet) or industrial control protocols (Modbus, DNP3, EtherNet/IP, OPC-UA) - consistent with depth in one target domain and familiarity with the others.\nWorking familiarity with standard network protocols and web/mobile application testing methodology - many IoT and automotive targets ship with companion apps and cloud APIs that are part of the real attack surface.\nAbility to read and review source code in C and C++ to identify memory safety issues, authentication flaws, and other security weaknesses in embedded software.\nFamiliarity with SBOM concepts, formats (CycloneDX, SPDX), and the use of SBOMs in vulnerability management.\nWorking fluency with CVSS scoring and VEX, including how an exploitability determination is defended to a customer.\nAbility to map findings to at least one relevant regulatory or standards framework and explain the implications to a customer. Breadth across frameworks is a plus, not a requirement.\nExcellent written and verbal communication skills; proven ability to write clear, well-structured technical reports and present findings to diverse audiences.\nExperience with scripting and automation using Python and Bash to support tooling and workflow efficiency.\nFamiliarity with AI-assisted security tooling and an interest in applying LLM-based workflows to accelerate security analysis and reporting.\n---\nPreferred Qualifications\nHands-on automotive security experience: OBD-II assessment, ECU flashing and analysis, V2X protocols, or automotive HSM evaluation.\nExperience with industrial control system (ICS/SCADA) security assessments and familiarity with protocols such as Modbus, DNP3, EtherNet/IP, or OPC-UA.\nCVE or responsible disclosure history, or other demonstrated exploit development / vulnerability research - valuable but understood to often be scarce or NDA-restricted; not a gating requirement.\nRelevant certifications a plus, not required: Offensive Security (OSCP, OSWE) or SANS/GIAC (GPEN, GICSP), or vendor-specific automotive security credentials.\nWorking knowledge of specific regulations and standards - a subset is plenty, not comprehensive mastery: EU Cyber Resilience Act (CRA), CE RED / EN 303 645, UNECE WP.29 / ISO 21434 (automotive), IEC 62443, FDA premarket cybersecurity requirements, or the US IoT Cyber Trust Mark.\nEligibility for U.S. government security clearance - a plus for accounts with federal/defense exposure, but not a requirement and should not disqualify strong candidates otherwise.\nFamiliarity with static and dynamic analysis platforms and SAST/DAST tooling in the context of firmware and embedded software.\nExperience with ML-based vulnerability detection models or AI-augmented reverse engineering pipelines.\nExperience working on small, fast-moving consulting or product security teams.\nComfort operating in AWS or similar cloud environments used to support analysis pipelines or customer deliverables.\nStrong attention to detail, intellectual curiosity, and the ability to adjust priorities quickly in a dynamic environment.\nInterest in expanding into broader customer-facing and engineering responsibilities.\n---\nWorking Conditions\nThis is a hands-on hardware role. You will work in a bench lab environment with soldering and rework equipment, and occasionally on customer sites where live industrial or medical equipment is present - engagements in those environments follow customer safety procedures and agreed rules of engagement, and testing against production OT is never performed without written authorization. Some customer hardware and technical data is subject to U.S. export control (ITAR/EAR), and a subset of engagements is restricted to U.S. persons as those rules define the term. Baseline eligibility for this role is U.S. work authorization without sponsorship; the export-restricted subset is a portion of the work, not the whole role, and we will be explicit about which accounts it affects.\nAbout Finite State\nAt Finite State, we're on a mission to secure the connected world. Our platform empowers product security teams to detect vulnerabilities, manage software supply chain risks, and ensure compliance across complex device ecosystems. From IoT to critical infrastructure, we provide unparalleled visibility into firmware and software components, helping organizations protect their products and customers.\nWe move with urgency and intent - we’re transparent, own outcomes, put customers first, speak up, and learn fast - turning evidence into action. CLARITY is how we move fast without breaking trust.\nC - Customer first - Learn from customers. Ship with urgency.\nL - Leverage - Outsource the routine. Own the result.\nA - Agency - We take responsibility-end to end.\nR - Results - Ship value. Improve fast.\nI - Integrity - Speak up. Experiment boldly. Be kind.\nT - Transparency - Clear context. Faster decisions.\n Y - \"Why\" - Our mission-securing the connected products humanity depends on-is the reason Finite State exists. CLARITY is how we make that mission real, every day, at speed\nBold Innovation - We push boundaries, explore new ideas, and take initiative to solve complex...","description_format":"text","description_chars":13112,"description_truncated":true,"requirements":{"experience_years_min":7,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":true,"industries":["Penetration Testing","Information Security","Application Security","Vulnerability Management"],"lifecycle":[{"event":"open","at":"2026-10-09T20:44:02Z"}],"visa":[],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":33,"reasons":["conf:3","win:early"],"computed_at":"2026-10-10T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/finitestate-senior-engineer-penetration-testing","json_url":"https://alion.io/job/finitestate-senior-engineer-penetration-testing.json","meta":{"generated_at":"2026-10-11T04:19:39Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2907,"day_limit":5000,"remaining_today":2093,"minute_limit":60,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":674179},"rest":"https://alion.io/mcp/rest/get_company?id=674179"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Ffinitestate-senior-engineer-penetration-testing"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Ffinitestate-senior-engineer-penetration-testing"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Ffinitestate-senior-engineer-penetration-testing"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/finitestate-senior-engineer-penetration-testing\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Ffinitestate-senior-engineer-penetration-testing"}]}