Finite State
IoT / ICS / OT Penetration Tester
United States or Canada · Mid
Sponsorship not specifiedDetected 83 days ago
PythonC++BashCode ReviewAWSCloud PlatformsMachine LearningLLMsSupply ChainPCB DesignEmbedded SystemsElectrical EngineeringControls5G/LTEResearchCommunicationSCADA
About the role
- Role Summary Finite State is seeking an experienced IoT / ICS / OT and Penetration Tester to join our growing Services team.
- Ship with urgency. - L - Leverage - Outsource the routine.
- Improve fast. - I - Integrity - Speak up.
Responsibilities
- Perform hardware interaction and firmware extraction using techniques such as JTAG, SWD, UART, SPI, I2C, eMMC, and NAND flash dumping
- Perform source code review, primarily in C, C++, and related embedded languages, to identify security weaknesses in firmware and embedded software.
- maintain awareness of evolving AI capabilities relevant to embedded security research.
- Collaborate with the product, engineering, and research teams to feed pentesting findings back into the Finite State platform and improve detection capabilities.
- Support customer-facing engagements including scoping calls, technical debriefs, and remediation follow-up.
- Own the result.
Requirements
- Bachelor's degree in Computer Science, Electrical Engineering, Computer Engineering, or a related field
- 5+ years of hands-on experience in IoT, embedded, ICS/OT, or automotive security.
- Proficiency with firmware reverse engineering tools, specifically Ghidra and/or Binary Ninja
- ability to analyze ARM, MIPS, PPC, x86, and x64 architectures.
- Experience testing IoT and automotive wireless protocols, including BLE, Zigbee, Z-Wave, Wi-Fi, CAN bus, and cellular interfaces.
- Ability to read and review source code in C and C++ to identify memory safety issues, authentication flaws, and other security weaknesses in embedded software.
- Familiarity with SBOM concepts, formats (CycloneDX, SPDX), and the use of SBOMs in vulnerability management.
- Working knowledge of relevant regulations and standards, including at least a subset of: EU CRA, CE RED / EN 303 645, UNECE WP.29, ISO 21434, or the US IoT Cyber Trust Mark.
- proven ability to write clear, well-structured technical reports and present findings to diverse audiences.
- Experience with scripting and automation using Python and Bash to support tooling and workflow efficiency.
Nice to have
- Hands-on automotive security experience: OBD-II assessment, ECU flashing and analysis, V2X protocols, or automotive HSM evaluation.
- Experience with industrial control system (ICS/SCADA) security assessments and familiarity with protocols such as Modbus, DNP3, EtherNet/IP, or OPC-UA.
- CVE or responsible disclosure history demonstrating original vulnerability research in embedded or IoT targets.
- Relevant certifications such as OSCP, GPEN, GICSP, or vendor-specific automotive security credentials.
- Familiarity with static and dynamic analysis platforms and SAST/DAST tooling in the context of firmware and embedded software.
- Experience with ML-based vulnerability detection models or AI-augmented reverse engineering pipelines.
- Experience working on small, fast-moving consulting or product security teams.
- Why Finite State?
Company info
- Learn from customers.
- Our mission-securing the connected products humanity depends on-is the reason Finite State exists.
Apply directly at Finite State →Create a free account for alerts like thisView Finite State immigration profile
This listing is sourced directly from Finite State's careers page and normalized into a canonical job model.