Role Description
Operational leader accountable for hands-on management, planning, and delivery of all Finite State Product Security Technical Managed Services binary firmware analysis, device penetration testing, threat and risk assessments (TARAs), SBOM/SCA generation, vulnerability response coordination, triage and remediation, and long-term engagement support for connected product OEMs and manufacturers (strategic accounts).
-
Drives operational design, build-out, and scale of new and emerging managed services PSIRT-as-a-Service (PSIRTaaS), EU Cyber Resilience Act (CRA) sustainable compliance, and adjacent offerings with Finite State's AI Product Security Automation Platform as the delivery spine.
-
Direct people manager for the Technical Services team, accountable for hiring, onboarding, mentorship, performance management, capacity planning, skills development, and utilization optimization across a multi-disciplinary team of product security engineers and analysts.
-
Customer-facing managed services delivery leader accountable for engagement quality, technical accuracy, schedule adherence, customer satisfaction, renewal, and expansion across the active managed services portfolio.
-
Cross-functional partner to Product, Engineering, Sales, Marketing, Legal, and Regulatory Advisory Services Team, channeling field-level delivery experience into platform requirements, packaging and pricing, go-to-market enablement, and regulatory positioning.
Qualifications
-
Bachelor's degree in Computer Science, Mathematics, Physical Sciences, Electrical/Computer Engineering, or equivalent demonstrable experience and certifications; advanced degree desirable.
-
Minimum 8 years of relevant experience in product security, embedded/connected device security, application security, or offensive security — a meaningful portion delivered in a customer-facing services, consulting, or managed services context.
-
Minimum 4 years of direct people management experience, including hiring, performance management, mentorship, and team development.
-
Demonstrated experience standing up new service offerings or productizing technical capabilities within a managed services or information technology environments is strongly preferred.
-
Hands-on technical depth in two or more of: binary/firmware analysis, penetration testing of embedded or IoT systems, threat modeling and TARA, SBOM and software composition analysis, vulnerability management and disclosure (CVE/CNA workflows), PSIRT/ESIRT operations.
Requirements
-
Deep working knowledge of connected and embedded device security, including firmware, microcontrollers, wireless SoCs, RTOS environments, and integrated IoT systems.
-
Hands-on familiarity with binary and firmware analysis tooling and methodology (Ghidra, IDA, Binary Ninja, radare2, and platform-driven equivalents).
-
Strong understanding of SBOM standards (SPDX, CycloneDX), VEX, software composition analysis, and vulnerability correlation against CVE/CPE/PURL.
-
Strong understanding of vulnerability disclosure and PSIRT operating models, including ISO/IEC 29147 (vulnerability disclosure) and ISO/IEC 30111 (vulnerability handling), CVSS v3.1/v4, and CNA operating procedures.
-
Familiarity with offensive security methodology applied to embedded systems, including hardware-adjacent attacks (fault injection, side-channel concepts, debug interface exploitation) at a depth sufficient to scope, review, and quality-control the work.
-
Working knowledge of TARA methodologies (ISO/SAE 21434 for automotive, IEC 62443-3-2 for industrial, MITRE ATT&CK and EMB3D where applicable).
-
Working knowledge of applied cryptography, secure protocols, secure boot, secure update, and key management as applied to embedded systems.
-
Ability to ramp quickly on AI and agentic AI platforms and productivity systems; familiarity with the automated firmware/binary analysis platform category and AI-assisted vulnerability triage is preferred.
Benefits
-
Salary ranges categorized into two tiers based on geographic location:
-
Tier 1 (San Francisco, New York, Seattle): $200,000 - $215,000
-
Tier 2 (All Other Locations): $190,000 - $207,000
-
The final base salary will be determined by experience, skill set, and specific location.
-
This role is eligible for equity and benefits.
Company Description
At Finite State, we're on a mission to secure the connected world. Our platform empowers product security teams to detect vulnerabilities, manage software supply chain risks, and ensure compliance across complex device ecosystems. From IoT to critical infrastructure, we provide unparalleled visibility into firmware and software components, helping organizations protect their products and customers.
-
We move with urgency and intent — we’re transparent, own outcomes, put customers first, speak up, and learn fast — turning evidence into action.
-
CLARITY is how we move fast without breaking trust.
-
We are proud to be an Equal Employer Opportunity employer.