Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IoT / ICS / OT Penetration Tester

Full-time

Finite State

Finite State partners with product security teams, the guardians of our connected world, to create transparency for their connected devices and supply chains. Our platform handles connected devices and embedded systems across all industries, including those found in enterprises, healthcare, utilities, connected vehicles, manufacturing facilities, critical infrastructure, and government entities. 

We are a fast-growing series-B company with a fully distributed workforce. Led by a team of seasoned experts, we are a mission-driven team passionate about arming our customers with the actionable insights, critical vulnerability data, and remediation guidance necessary to mitigate product risk and protect the connected attack surface. We are committed to a remote first culture.

Role Summary

Finite State is seeking an experienced IoT / ICS / OT and Penetration Tester to join our growing Services team. In this role you will conduct hands-on security assessments of connected devices, embedded systems, industrial control systems, and automotive platforms on behalf of our customers. You will combine deep hardware and firmware expertise with a consultative mindset to deliver clear, actionable findings that help manufacturers and operators understand and reduce risk. 

Responsibilities

  • Plan and execute penetration tests and security assessments against IoT, ICS/OT, and automotive targets, including connected consumer devices, industrial controllers, and automotive ECUs and telematics units.

  • Perform hardware interaction and firmware extraction using techniques such as JTAG, SWD, UART, SPI, I2C, eMMC, and NAND flash dumping; solder and rework PCBs as needed to gain access to debug interfaces.

  • Conduct firmware reverse engineering using tools such as Ghidra and Binary Ninja to identify vulnerabilities including memory corruption, authentication bypasses, hard-coded credentials, and insecure update mechanisms.

  • Assess wireless protocols common in IoT and automotive environments, including Bluetooth / BLE, Zigbee, Z-Wave, Wi-Fi, Cellular (LTE/5G), CAN bus, LIN, and automotive Ethernet.

  • Perform source code review, primarily in C, C++, and related embedded languages, to identify security weaknesses in firmware and embedded software.

  • Conduct supply chain and software composition analysis, including SBOM review and analysis of third-party open-source components, to identify known vulnerabilities and license risks.

  • Evaluate customer products and programs for compliance with relevant regulations and standards, including EN 303 645, the EU Cyber Resilience Act (CRA), EU Radio Equipment Directive (CE RED), UNECE WP.29 / ISO 21434 for automotive, and the US IoT Cyber Trust Mark.

  • Produce high-quality written reports that clearly communicate technical findings, risk ratings, and remediation guidance to both technical and executive audiences.

  • Leverage AI-powered security tooling and LLM-assisted workflows to accelerate analysis, triage, and reporting; maintain awareness of evolving AI capabilities relevant to embedded security research.

  • Collaborate with the product, engineering, and research teams to feed pentesting findings back into the Finite State platform and improve detection capabilities.

  • Support customer-facing engagements including scoping calls, technical debriefs, and remediation follow-up.

  • Contribute to internal knowledge sharing, tooling development, and methodology improvement.

  • Participate in industry conferences, publish research, and represent Finite State externally as opportunities arise.

Required Qualifications

  • Bachelor's degree in Computer Science, Electrical Engineering, Computer Engineering, or a related field

  • 5+ years of hands-on experience in IoT, embedded, ICS/OT, or automotive security.

  • Demonstrated experience performing hardware-level security assessments: JTAG/SWD debugging, SPI/I2C/UART communication, flash memory extraction, and PCB soldering and rework.

  • Proficiency with firmware reverse engineering tools, specifically Ghidra and/or Binary Ninja; ability to analyze ARM, MIPS, PPC, x86, and x64 architectures.

  • Experience testing IoT and automotive wireless protocols, including BLE, Zigbee, Z-Wave, Wi-Fi, CAN bus, and cellular interfaces.

  • Ability to read and review source code in C and C++ to identify memory safety issues, authentication flaws, and other security weaknesses in embedded software.

  • Familiarity with SBOM concepts, formats (CycloneDX, SPDX), and the use of SBOMs in vulnerability management.

  • Working knowledge of relevant regulations and standards, including at least a subset of: EU CRA, CE RED / EN 303 645, UNECE WP.29, ISO 21434, or the US IoT Cyber Trust Mark.

  • Excellent written and verbal communication skills; proven ability to write clear, well-structured technical reports and present findings to diverse audiences.

  • Experience with scripting and automation using Python and Bash to support tooling and workflow efficiency.

  • Familiarity with AI-assisted security tooling and an interest in applying LLM-based workflows to accelerate security analysis and reporting.

Preferred Qualifications

  • Hands-on automotive security experience: OBD-II assessment, ECU flashing and analysis, V2X protocols, or automotive HSM evaluation.

  • Experience with industrial control system (ICS/SCADA) security assessments and familiarity with protocols such as Modbus, DNP3, EtherNet/IP, or OPC-UA.

  • CVE or responsible disclosure history demonstrating original vulnerability research in embedded or IoT targets.

  • Relevant certifications such as OSCP, GPEN, GICSP, or vendor-specific automotive security credentials.

  • Familiarity with static and dynamic analysis platforms and SAST/DAST tooling in the context of firmware and embedded software.

  • Experience with ML-based vulnerability detection models or AI-augmented reverse engineering pipelines.

  • Experience working on small, fast-moving consulting or product security teams.

  • Comfort operating in AWS or similar cloud environments used to support analysis pipelines or customer deliverables.

Why Finite State?

  • Be part of building the leading platform for connected device cybersecurity

  • Join a fast-moving team that values transparency, innovation and impact

  • Work fully remotely with a high degree of autonomy and ownership

  • Comprehensive benefits

  • Investment: learning stipends to support your professional development

  • Equity: share in our growth and success

  • Help solve some of the most pressing cybersecurity challenges facing connected device manufacturers and the millions of people who depend on them

About Finite State

At Finite State, we're on a mission to secure the connected world. Our platform empowers product security teams to detect vulnerabilities, manage software supply chain risks, and ensure compliance across complex device ecosystems. From IoT to critical infrastructure, we provide unparalleled visibility into firmware and software components, helping organizations protect their products and customers.

We move with urgency and intent — we’re transparent, own outcomes, put customers first, speak up, and learn fast — turning evidence into action. CLARITY is how we move fast without breaking trust.

  • C - Customer first - Learn from customers. Ship with urgency.

  • - Leverage - Outsource the routine. Own the result.

  • A - Agency - We take responsibility—end to end.

  • R - Results - Ship value. Improve fast.

  • I - Integrity - Speak up. Experiment boldly. Be kind.

  • T - Transparency - Clear context. Faster decisions.

  • Y - 'Why' - Our mission—securing the connected products humanity depends on—is the reason Finite State exists. CLARITY is how we make that mission real, every day, at speed

Bold Innovation – We push boundaries, explore new ideas, and take initiative to solve complex problems.

The Finite State platform brings visibility and control to the supply chains that create connected devices and embedded systems—all in a simple to use platform and at the scale manufacturers need to keep device production on time and on budget. After unpacking and analyzing every file, configuration, and setting in a firmware build, the platform generates a complete bill of materials for software components, identifies known and 0-day vulnerabilities, shows a contextual risk score, and provides actionable insights that product teams can use to secure their software

We are proud to be an Equal Employer Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. Finite State is committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities.

Vacancy posted 10 hours ago
Similar jobs that could be interesting for youBased on the IoT / ICS / OT Penetration Tester in United States vacancy
  •  ...business growth.  ~ Maintain and enhance relationships with existing clients to ensure satisfaction and retention.   ~ Explore and penetrate new markets to expand the company’s footprint.  ~ Identify and assess potential markets and customer segments for product or... 
    Suggested
    Temporary work
    Work at office
    Flexible hours

    Mohawk Industries

    United States
    16 days ago
  • $145k - $260k per year

     ...focus on building a community and an ecosystem of terminal plugins and apps, creating network effects. At higher levels of team penetration, we will offer an enterprise plan with features around privacy, security and environment management (e.g. secure distribution and management... 
    Suggested
    Remote job
    Remplacement
    Internship
    Work at office
    Immediate start
    Flexible hours

    Warp

    United States
    more than 2 months ago
  •  ...MaintainX is the world's leading Asset and Work Intelligence platform for industrial and frontline environments. We are a modern IoT-enabled cloud-based tool for reliability, safety, and operations on physical equipment and facilities. MaintainX powers operational excellence... 
    Suggested
    Remote job
    Long term contract

    MaintainX

    United States
    more than 2 months ago
  •  ...organizations Skilled at selling to owners and senior leaders, not just L&D Strong communicator and natural storyteller High-performing IC mindset: ownership, urgency, consistency, resilience Nice to have ~ Familiarity with AI , workforce transformation, learning, or... 
    Suggested
    Remote work
    Worldwide

    CGS Immersive

    United States
    a month ago
  • $65k - $75k per year

     ...What you’ll be doing Researching new accounts to create a strong point of view as to the value InfluxDB could bring to their DevOps, IoT, AI or Data Science use cases. Creating a high volume & high quality output of daily outbound outreach into senior level contacts... 
    Suggested
    Remote job
    Long term contract
    Full time
    Temporary work
    Internship
    Flexible hours

    InfluxData

    United States
    more than 2 months ago
  •  ...MaintainX is the world's leading Asset and Work Intelligence platform for industrial and frontline environments. We are a modern IoT-enabled cloud-based tool for reliability, safety, and operations on physical equipment and facilities. MaintainX powers operational excellence... 
    Remote job
    Worldwide

    MaintainX

    United States
    more than 2 months ago
  •  ...expansion, Slack bot launch, automated eval framework, and the Figma Data Assistant Coordinate delivery across Data Engineering, DS ICs, Security, IT, and business stakeholders (Sales, Product, Finance, Research) to expand self-serve data coverage and drive adoption Lead... 
    Minimum wage
    Full time
    Local area
    Remote work
    Flexible hours
    Shift work

    Figma

    United States
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IoT / ICS / OT Penetration Tester. Be the first to apply!