--- title: 'Staff Product Security Engineer - Offensive Testing at Finite State' canonical: 'https://feeny.ai/job/staff-product-security-engineer-offensive-testing-finite-state-united-states-or-f2tn1ajgewnr' type: 'job' last_seen: '2026-09-08' --- # Staff Product Security Engineer - Offensive Testing at Finite State - **Company:** Finite State - **Location:** United States OR, Canada - **Work type:** remote - **Posted:** 2026-08-12 - **Last confirmed live:** 2026-09-08 - **Apply:** https://job-boards.greenhouse.io/finitestate/jobs/6142344004 ## Job description Finite State partners with product security teams, the guardians of our connected world, to create transparency for their connected devices and supply chains. Our platform handles connected devices and embedded systems across all industries, including those found in enterprises, healthcare, utilities, connected vehicles, manufacturing facilities, critical infrastructure, and government entities. We are a fast-growing series-B company with a fully distributed workforce. Led by a team of seasoned experts, we are a mission-driven team passionate about arming our customers with the actionable insights, critical vulnerability data, and remediation guidance necessary to mitigate product risk and protect the connected attack surface. We are committed to a remote first culture. Staff Product Security Engineer - Offensive Testing Department: Services Reports to: Head of PSC Engineering ## About the Role Connected products run the world: vehicles, medical devices, industrial systems, and critical infrastructure—and securing them is one of the hardest engineering problems there is. At Finite State, PSC Engineers are the technical owners of that problem for our customers: engineers who earn trust by building and shipping from the field. You will work directly with the security and engineering teams of some of the world’s largest device manufacturers, analyzing their firmware, testing their products, assessing their risk, and building solutions on our platform that measurably harden what they ship. You’ll do it with an outstanding and unique toolkit: our product security platform, the most advanced AI tooling available, and a team of genuinely world-class expert peers. This combination allows a single sharp engineer to deliver what once required an entire consulting team—and that is exactly the point. ## What You’ll Do - Own the technical relationship with a portfolio of customer accounts. You are the engineer they trust—the person who understands their products, architecture, and risk. - Analyze real-world devices through firmware and binary analysis, SBOM and software supply chain investigations, vulnerability triage, and remediation guidance for products that ship in the millions. - Execute penetration tests and hands-on security assessments of embedded systems, including both hardware and software, and deliver findings that engineers can act on and executives can understand and defend. - Run threat modeling and product risk assessments that shape how customers design, build, and ship secure products. - Build integrations, data-source feeds, automation, SDK-based extensions, and AI-driven agentic workflows on the Finite State platform that solve your customers’ specific problems faster than anyone thought possible. - Guide customers through the regulatory wave affecting connected devices, including the EU Cyber Resilience Act, RED, and FDA cybersecurity requirements, turning compliance pressure into engineering clarity. - Communicate at every altitude—from firmware engineers and security teams to CISOs and boardrooms—in writing and in the room. - Own customer outcomes across technical delivery, platform adoption, support, account health, renewals, and expansion opportunities. - Partner across Sales, Product, Engineering, and the broader PSC organization to identify customer risks, coordinate internal support, and ensure a consistent customer experience. - Capture reusable solutions, integrations, workflows, and customer insights that can improve the Finite State platform and benefit future customers. ## Qualifications - 5+ years of experience in customer engineering, solutions engineering, technical account management, security consulting, field engineering, or a similar customer-facing technical role. - Hands-on experience building integrations, SDKs, automation, APIs, or platform extensions. - Strong technical troubleshooting and problem-solving skills. - Experience translating customer needs into practical technical solutions. - Strong written and verbal communication skills. - Ability to build trusted customer relationships and communicate effectively with both technical and nontechnical stakeholders. - Ability to manage multiple accounts, customer priorities, and technical deliverables simultaneously. - Experience working within established technical standards, delivery playbooks, or support processes. - Ability to own customer outcomes across adoption, delivery, support, and account health. ## Skills and Competencies - Strong customer ownership and accountability - Technical judgment and problem-solving - Consultative communication - Solution design and implementation - Cross-functional collaboration - Ability to manage competing priorities - Clear documentation and knowledge sharing - Commercial awareness related to customer health, renewals, and expansion - Ability to work independently in customer-facing environments What Makes You a Fit You know your craft. You bring deep, hands-on product security expertise across embedded software and hardware security, firmware analysis, penetration testing, and threat and risk assessment. You’ve broken real devices and helped fix them. You know the stack. You have a hands-on background evaluating the security posture of firmware, applications, networks, IoT, and embedded systems. You improve the architecture. You have a proven track record of architecting features and hardening the security of complex networked or embedded environments, along with a strong command of the principles that drive secure product development and systemic design decisions. You ship production code. You are experienced in building and deploying resilient, production-ready Linux and embedded systems. You understand the adversary. You bring deep technical familiarity with reverse engineering techniques and the implementation of anti-tamper mechanisms. You communicate at every altitude. You demonstrate exceptional professional clarity in writing and speech, with the ability to earn trust across technical and executive teams. You build. You are proficient in one or more relevant modern programming languages, such as C/C++, Python, Go, Rust, TypeScript, or similar. You are comfortable working with APIs and automation and turning repetitive problems into scalable tools. You are AI-native. You already use LLMs and agentic tooling as force multipliers in technical work, and you have the judgment to know where human ownership and validation are essential. You are driven and self-directing. Give you a customer outcome and you find the path—no waiting to be told what to do. You hold yourself to a higher standard than anyone else sets for you. You make others better. You share what you learn, draw on the expertise of your peers without ego, and build the kind of trust that makes customers ask for you by name. You champion the team. You are committed to fostering a supportive, inclusive, and collaborative environment where every engineer and team member can excel. ## Nice to Have You are certified for the offensive. You hold advanced credentials such as CISSP, CSSLP, OSCP, or OSWE, or have a proven history in exploit development and hands-on vulnerability research. You navigate the regulatory landscape. You have practical familiarity with global standards and requirements, including the EU Cyber Resilience Act, RED EN 18031, FDA premarket cybersecurity requirements, or IEC 62443. You speak hardware and firmware. You have deep technical knowledge of RTOS and embedded Linux internals, including JTAG, UART, SPI interfaces, and wireless communication protocols. You secure complex systems. You have an expert understanding of the security architectures found in aerospace, medical, automotive, smart energy, smart city, home and commercial cyber-physical environments, and mission-critical embedded systems. You master federal cyber policy. You bring fluency in modern U.S. government methodologies, including JSIG, ICD 503, NIST SP 800-160, and Cyber Survivability guidance. You know the hardware logic. You have hands-on experience developing for programmable logic devices using industry-standard engineering tools. You ship resilient code. You have a consistent record of building, testing, and deploying production-ready embedded and Linux systems from the field. ## Why This Job Because you’ll spend your time on the hard, interesting work: real devices, real adversaries, and real regulatory stakes. You’ll have the leverage of a platform and AI stack that most security engineers do not yet have, while working on a team small enough that your contributions are visible and your standards help set the standard. We depend on smart engineers who use cutting-edge technology and each other’s expertise to deliver something no one else can. If that sounds like a job description written for you, we should talk. Why Finite State? - Be a part of building the leading platform for connected device cybersecurity. - Join a fast-moving team that values transparency, innovation, and impact. - Work fully remotely with a high degree of autonomy and ownership. - Comprehensive Benefits - Investment: We offer learning stipends to support your professional development - Equity: We offer equity so you can share in our growth and success - Help solve some of the most pressing cybersecurity challenges facing connected device  manufacturers and the millions of people who depend on them ## About Finite State At Finite State, we're on a mission to secure the connected world. Our platform empowers product security teams to detect vulnerabilities, manage software supply chain risks, and ensure compliance across complex device ecosystems. From IoT to critical infrastructure, we provide unparalleled visibility into firmware and software components, helping organizations protect their products and customers. We move with urgency and intent — we’re transparent, own outcomes, put customers first, speak up, and learn fast — turning evidence into action. CLARITY is how we move fast without breaking trust. - C - Customer first - Learn from customers. Ship with urgency. - L - Leverage - Outsource the routine. Own the result. - A - Agency - We take responsibility—end to end. - R - Results - Ship value. Improve fast. - I - Integrity - Speak up. Experiment boldly. Be kind. - T - Transparency - Clear context. Faster decisions. - Y - "Why" - Our mission—securing the connected products humanity depends on—is the reason Finite State exists. CLARITY is how we make that mission real, every day, at speed Bold Innovation – We push boundaries, explore new ideas, and take initiative to solve complex problems. The Finite State platform brings visibility and control to the supply chains that create connected devices and embedded systems—all in a simple to use platform and at the scale manufacturers need to keep device production on time and on budget. After unpacking and analyzing every file, configuration, and setting in a firmware build, the platform generates a complete bill of materials for software components, identifies known and 0-day vulnerabilities, shows a contextual risk score, and provides actionable insights that product teams can use to secure their software We are proud to be an Equal Employer Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. Finite State is committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities. ## About Finite State ## Company Overview - **One-liner**: Finite State provides an AI-native platform that automates product security across the full lifecycle for connected devices, enabling manufacturers to design, verify, and prove compliance with regulations like the EU Cyber Resilience Act. - **Entity Type**: Private (Series B) - **Headquarters**: Columbus, Ohio, United States - **Founded**: 2017 - **Founders**: Not publicly disclosed ## Core Business - **Primary industry**: Computer and Network Security / Product Cybersecurity (focusing on IoT, medical devices, automotive, and OT/ICS) - **Target customers**: B2B — Device OEMs and manufacturers in automotive, medical device, and industrial sectors; also serves enterprise and government clients - **Mission or purpose statement**: To empower device OEMs to ship securely while enabling engineering teams to move at the speed of AI, transforming product artifacts into audit-ready assurance through a single automated workflow. ## Products & Services - **[Finite State Platform]**: A SaaS platform that leverages deep binary analysis and AI-native execution to unify code, compiled components, and firmware in minutes. It automates threat modeling, generates SBOMs (Software Bills of Materials), VEX documents, and signed compliance packages. The platform connects security design with deployed software and is designed to help manufacturers meet regulations like the EU Cyber Resilience Act (CRA). - **[Managed Services]**: A managed service offering to help medical device manufacturers and others achieve EU CRA compliance, providing industry-leading security services to navigate evolving regulations and enhance product security posture. - **[Binary Analysis Engine]**: A core technology for reachability-based triage of vulnerabilities in binaries and firmware, enabling deep visibility into shipped code. ## Market Standing - **Valuation/Market Cap**: Not disclosed (Private company) - **Key Metric**: **Annual Revenue** of ~$8.7M (USD) | **Total Funding** of $69.5M across 4 rounds - **Notable Investors/Partners**: - Energy Impact Partners (Lead investor in Series A and Series B) - Drive Capital (Lead investor in Seed Round) - Zetta Venture Partners (Seed Round) - National Grid Partners (NGP) - Energize Capital (Lead investor in Series B) - **Growth Signals**: - Headcount grew **+24.2% YoY** (15 people added), now employing 61 people. - Acquired **MergeBase** in June 2024 to expand capabilities. - Expanding globally with offices in Canada, UK, Argentina, Singapore, and Israel. - Recent job postings (Senior Software Engineer AI/ML, Regional Sales Director) indicate continued investment. ## Competitive Advantages - **AI-Native, Full Lifecycle Automation**: Differentiates by automating the entire security lifecycle (design → verify → prove) rather than just scanning or vulnerability management. - **Deep Binary Analysis**: Proprietary reachability-based triage that goes beyond typical SCA (Software Composition Analysis) to understand which vulnerabilities are actually exploitable in a shipped device. - **Regulatory Compliance Focus**: Specifically built to help manufacturers navigate complex, emerging regulations like the EU Cyber Resilience Act (CRA) and FDA requirements for medical devices, a key pain point for OEMs. - **Continuous Compliance Output**: Automatically generates audit-ready artifacts (SBOMs, VEX, compliance packages) tied to every release, reducing friction between security and engineering teams. ## Strategic Focus - **Expanding into Automotive & Medical Devices**: The platform and managed services are heavily tailored for these regulated, high-stakes industries. - **Scaling AI & Automation**: Continued investment in AI/ML capabilities (as seen in current hiring for Senior Software Engineer AI/ML). - **Post-Acquisition Integration**: Absorbing MergeBase’s technology and talent to broaden its software supply chain security offerings. - **Global Market Penetration**: Growing presence in key markets (Canada, UK, Singapore, Israel) to support multinational OEMs. ## Why Work Here - **Culture**: Described as a "leading provider" in product cybersecurity with a focus on mission-driven work — securing critical infrastructure and medical devices. LinkedIn reviews rate compensation highly (4.3/5) but suggest work-life balance is a challenge (2.8/5). - **Engineering & Tech Stack**: A modern stack including **Python, Django, Kubernetes, PostgreSQL, Redis, GraphQL, React, Docker, and Node.js**. The team works on advanced AI/ML for binary analysis and threat modeling. - **Remote/Hybrid Policy**: Not explicitly stated, but offices are located in Columbus, OH (HQ), with a distributed team across the US, Canada, UK, Argentina, Singapore, and Israel, suggesting a flexible or hybrid model is likely. - **Notable Perks**: Working on a cutting-edge platform at the intersection of cybersecurity and AI; involvement in high-impact regulatory compliance work; opportunity to shape product security for connected devices globally. ## Sources 1. [finitestate.io](https://finitestate.io/) 2. [finitestate.io/careers](https://finitestate.io/careers) 3. [finitestate.io/about](https://finitestate.io/about) 4. [linkedin.com/company/finitestate](https://www.linkedin.com/company/finitestate) 5. [finitestate.io/platform](https://finitestate.io/platform) ## Other roles at Finite State - [BDR Leader , East](https://feeny.ai/job/bdr-leader-east-finite-state-united-states-tgtxynkhtybz) — United States - [Senior QA Engineer - AI/ML](https://feeny.ai/job/senior-qa-engineer-ai-ml-finite-state-singapore-60e18151jphz) — Singapore - [Director of Product Management](https://feeny.ai/job/director-of-product-management-finite-state-united-states-or-3t5bjh2bypa8) — United States OR, Canada - [Director, GTM Operations](https://feeny.ai/job/director-gtm-operations-finite-state-united-states-or-wy9kbtnze73t) — United States OR, Canada - [Regional Sales Director (Northeast)](https://feeny.ai/job/regional-sales-director-northeast-finite-state-united-states-cpkp0rr29ggp) — United States - [Regional Sales Director (West)](https://feeny.ai/job/regional-sales-director-west-finite-state-united-states-3xh8585q3pzv) — United States - [Lead Architect](https://feeny.ai/job/lead-architect-finite-state-singapore-90fhaycee39k) — Singapore - [MTS Manager](https://feeny.ai/job/mts-manager-finite-state-united-states-or-qmvzveb7wh20) — United States OR, Canada - [Senior Software Engineer AI/ML](https://feeny.ai/job/senior-software-engineer-ai-ml-finite-state-singapore-f238mwq0563r) — Singapore - [IoT / ICS / OT Penetration Tester](https://feeny.ai/job/iot-ics-ot-penetration-tester-finite-state-united-states-or-xt3zgtvz33s2) — United States OR, Canada