MTS Manager

53 minutes ago
Full-time
Lead
Cybersecurity
Finite State

Finite State

Finite State is a top provider of product cybersecurity solutions for connected devices, offering SBOM solutions and risk analysis to reduce supply chain risk.

Internet Software & Services
51-250
Founded 2017
$50M raised

Description

  • Lead day-to-day delivery of managed technical security services across binary firmware analysis, device penetration testing, TARA, SBOM/SCA, vulnerability response, triage, and remediation advisory.
  • Own the full customer engagement lifecycle, including scoping, statements of work, kickoff, execution, deliverable review, communications, and renewal or expansion planning.
  • Establish and continuously improve service delivery playbooks, technical methodologies, templates, review gates, and quality acceptance criteria.
  • Drive adoption of Finite State’s automation platform across managed service engagements and feed field learnings back into the product roadmap.
  • Define, monitor, and report SLAs, SLOs, and engagement KPIs such as utilization, delivery timing, defect rates, CSAT/NPS, and renewal rates.
  • Serve as the senior escalation point for customer issues, complex technical findings, and contested results.
  • Lead the design and operationalization of new managed service offerings, including PSIRTaaS and EU CRA compliance services.
  • Build and operate customer-facing PSIRT workflows, including vulnerability monitoring, triage, disclosure coordination, remediation tracking, and verification.
  • Manage and develop a multidisciplinary technical team through hiring, onboarding, mentoring, performance management, capacity planning, and skills development.
  • Partner with Sales, Product, Engineering, Marketing, Legal, and Regulatory Advisory teams on pricing, packaging, go-to-market enablement, platform requirements, and account growth.

Requirements

  • Bachelor's degree in Computer Science, Mathematics, Physical Sciences, Electrical/Computer Engineering, or equivalent demonstrable experience and certifications; advanced degree is desirable.
  • 8+ years of relevant experience in product security, embedded or connected device security, application security, or offensive security, with a meaningful portion in customer-facing services, consulting, or managed services.
  • 4+ years of direct people management experience, including hiring, performance management, mentorship, and team development.
  • Experience standing up new service offerings or productizing technical capabilities in managed services or IT environments is strongly preferred.
  • Hands-on technical depth in two or more of: binary/firmware analysis, embedded or IoT penetration testing, threat modeling and TARA, SBOM and software composition analysis, vulnerability management and disclosure, or PSIRT/ESIRT operations.
  • Deep working knowledge of connected and embedded device security, including firmware, microcontrollers, wireless SoCs, RTOS environments, and integrated IoT systems.
  • Familiarity with binary and firmware analysis tools such as Ghidra, IDA, Binary Ninja, and radare2.
  • Strong understanding of SBOM standards (SPDX, CycloneDX), VEX, software composition analysis, and vulnerability correlation using CVE/CPE/PURL.
  • Working knowledge of vulnerability disclosure and PSIRT models, including ISO/IEC 29147, ISO/IEC 30111, CVSS v3.1/v4, and CNA procedures.
  • Working knowledge of EU Cyber Resilience Act requirements, IEC 62443, ETSI EN 303 645, NIST IR 8259, NIST SSDF, and EO 14028 / OMB M-22-18 SBOM requirements.
  • One or more of the following certifications is required: CISSP, CSSLP, CCSP, GIAC (GPEN/GXPN/GREM/GICSP), OSCP, or equivalent demonstrated technical depth.
  • One or more of the following certifications is desirable: CISM, CRISC, CISA, ISO/IEC 27001 Lead Auditor or Lead Implementer, IEC 62443 Cybersecurity Expert, PMP/PgPg, or ITIL Foundation or higher.
  • Strong project and program management capability, with the ability to run service delivery to defined SLAs, SLOs, and quality standards.
  • Excellent written and verbal communication skills with executives, customers, regulators, and technical teams.
  • Comfort operating in a fully remote, cloud-only company environment.

Benefits

  • Base salary of $200,000-$215,000 in Tier 1 locations (San Francisco, New York, Seattle).
  • Base salary of $190,000-$207,000 in Tier 2 locations (all other locations).
  • Eligibility for equity in addition to base pay.
  • Benefits package included with the role.
  • Remote-first, fully distributed work environment.
  • Opportunity to work for a mission-driven company focused on securing connected devices and supply chains.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Program Manager, Special Projects

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is hiring a Senior Program Manager on its Real Estate & Facilities team to lead complex operational programs and special projects that improve facilities operations across the company.

ERP SQL Tableau
38 minutes ago

Program Manager - SkillBridge

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is seeking a Program Manager to lead cross-functional development programs that support its defense technology operations across multiple business units and locations.

Computer Vision
38 minutes ago

Programs and Business Operations Lead, Cities

Airbnb 5K-10K Hotels, Restaurants & Leisure

Airbnb is hiring a Programs and Business Operations Lead to drive global regulatory operations and cross-functional initiatives for the Cities team, ensuring compliance while supporting the company’s growth.

53 minutes ago

Global Partner Programs Manager

Nice Côte d'Azur Hotels, Restaurants & Leisure

NiCE is hiring a Global Partner Program Manager to evolve and operationalize a global partner program across regions and partner motions with clear governance, measurable performance, and scalable execution.

CRM
53 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers