Skip to main content
Finite State

Staff Product Security Engineer - Offensive Testing

RemoteUnited States, Canada only
Published
Role
Security
Experience
Staff
Company size
Startup
Salary not disclosed
Check eligibility

Open to US, CA only. Set where you work from to check your eligibility.

No BS summary

Staff-level product security engineer with 5+ years in customer-facing technical roles. Deep hands-on expertise in embedded/firmware security, penetration testing, and threat modeling. Must be US or Canada based, fully remote.

Core skills

Penetration Testing

Required skills

C/C++/Python/Go/Rust/TypeScriptAPIs

Optional skills

CISSPCSSLPOSCPOSWERTOSJTAGUARTSPI

What you'll do

  • Own the technical relationship with a portfolio of customer accounts.
  • Analyze real-world devices through firmware and binary analysis, SBOM and software supply chain investigations, vulnerability triage, and remediation guidance for products that ship in the millions.
  • Execute penetration tests and hands-on security assessments of embedded systems, including both hardware and software, and deliver findings that engineers can act on and executives can understand and defend.
  • Run threat modeling and product risk assessments that shape how customers design, build, and ship secure products.
  • Build integrations, data-source feeds, automation, SDK-based extensions, and AI-driven agentic workflows on the Finite State platform that solve your customers' specific problems faster than anyone thought possible.
  • Guide customers through the regulatory wave affecting connected devices, including the EU Cyber Resilience Act, RED, and FDA cybersecurity requirements, turning compliance pressure into engineering clarity.
  • Communicate at every altitude—from firmware engineers and security teams to CISOs and boardrooms—in writing and in the room.
  • Own customer outcomes across technical delivery, platform adoption, support, account health, renewals, and expansion opportunities.
  • Partner across Sales, Product, Engineering, and the broader PSC organization to identify customer risks, coordinate internal support, and ensure a consistent customer experience.
  • Capture reusable solutions, integrations, workflows, and customer insights that can improve the Finite State platform and benefit future customers.

What they require

  • 5+ years of experience in customer engineering, solutions engineering, technical account management, security consulting, field engineering, or a similar customer-facing technical role.
  • Hands-on experience building integrations, SDKs, automation, APIs, or platform extensions.
  • Strong technical troubleshooting and problem-solving skills.
  • Experience translating customer needs into practical technical solutions.
  • Strong written and verbal communication skills.
  • Ability to build trusted customer relationships and communicate effectively with both technical and nontechnical stakeholders.
  • Ability to manage multiple accounts, customer priorities, and technical deliverables simultaneously.
  • Experience working within established technical standards, delivery playbooks, or support processes.
  • Ability to own customer outcomes across adoption, delivery, support, and account health.

Benefits

  • Learning stipends to support your professional development
  • Equity so you can share in our growth and success
  • Work fully remotely with a high degree of autonomy and ownership

Finite State partners with product security teams, the guardians of our connected world, to create transparency for their connected devices and supply chains. Our platform handles connected devices and embedded systems across all industries, including those found in enterprises, healthcare, utilities, connected vehicles, manufacturing facilities, critical infrastructure, and government entities. We are a fast-growing series-B company with a fully distributed workforce. Led by a team of seasoned experts, we are a mission-driven team passionate about arming our customers with the actionable insights, critical vulnerability data, and remediation guidance necessary to mitigate product risk and protect the connected attack surface. We are committed to a remote first culture.

CybersecurityStartup
Salary not disclosed