MTS Manager

4 weeks, 2 days ago
Full-time
Lead
Cybersecurity
Finite State

Finite State

Finite State is a top provider of product cybersecurity solutions for connected devices, offering SBOM solutions and risk analysis to reduce supply chain risk.

Internet Software & Services
51-250
Founded 2017
$50M raised

Description

  • Lead day-to-day delivery of managed technical security services across binary firmware analysis, device penetration testing, TARA, SBOM/SCA, vulnerability response, triage, and remediation advisory.
  • Own the full customer engagement lifecycle, including scoping, statements of work, kickoff, execution, deliverable review, communications, and renewal or expansion planning.
  • Establish and continuously improve service delivery playbooks, technical methodologies, templates, review gates, and quality acceptance criteria.
  • Drive adoption of Finite State’s automation platform across managed service engagements and feed field learnings back into the product roadmap.
  • Define, monitor, and report SLAs, SLOs, and engagement KPIs such as utilization, delivery timing, defect rates, CSAT/NPS, and renewal rates.
  • Serve as the senior escalation point for customer issues, complex technical findings, and contested results.
  • Lead the design and operationalization of new managed service offerings, including PSIRTaaS and EU CRA compliance services.
  • Build and operate customer-facing PSIRT workflows, including vulnerability monitoring, triage, disclosure coordination, remediation tracking, and verification.
  • Manage and develop a multidisciplinary technical team through hiring, onboarding, mentoring, performance management, capacity planning, and skills development.
  • Partner with Sales, Product, Engineering, Marketing, Legal, and Regulatory Advisory teams on pricing, packaging, go-to-market enablement, platform requirements, and account growth.

Requirements

  • Bachelor's degree in Computer Science, Mathematics, Physical Sciences, Electrical/Computer Engineering, or equivalent demonstrable experience and certifications; advanced degree is desirable.
  • 8+ years of relevant experience in product security, embedded or connected device security, application security, or offensive security, with a meaningful portion in customer-facing services, consulting, or managed services.
  • 4+ years of direct people management experience, including hiring, performance management, mentorship, and team development.
  • Experience standing up new service offerings or productizing technical capabilities in managed services or IT environments is strongly preferred.
  • Hands-on technical depth in two or more of: binary/firmware analysis, embedded or IoT penetration testing, threat modeling and TARA, SBOM and software composition analysis, vulnerability management and disclosure, or PSIRT/ESIRT operations.
  • Deep working knowledge of connected and embedded device security, including firmware, microcontrollers, wireless SoCs, RTOS environments, and integrated IoT systems.
  • Familiarity with binary and firmware analysis tools such as Ghidra, IDA, Binary Ninja, and radare2.
  • Strong understanding of SBOM standards (SPDX, CycloneDX), VEX, software composition analysis, and vulnerability correlation using CVE/CPE/PURL.
  • Working knowledge of vulnerability disclosure and PSIRT models, including ISO/IEC 29147, ISO/IEC 30111, CVSS v3.1/v4, and CNA procedures.
  • Working knowledge of EU Cyber Resilience Act requirements, IEC 62443, ETSI EN 303 645, NIST IR 8259, NIST SSDF, and EO 14028 / OMB M-22-18 SBOM requirements.
  • One or more of the following certifications is required: CISSP, CSSLP, CCSP, GIAC (GPEN/GXPN/GREM/GICSP), OSCP, or equivalent demonstrated technical depth.
  • One or more of the following certifications is desirable: CISM, CRISC, CISA, ISO/IEC 27001 Lead Auditor or Lead Implementer, IEC 62443 Cybersecurity Expert, PMP/PgPg, or ITIL Foundation or higher.
  • Strong project and program management capability, with the ability to run service delivery to defined SLAs, SLOs, and quality standards.
  • Excellent written and verbal communication skills with executives, customers, regulators, and technical teams.
  • Comfort operating in a fully remote, cloud-only company environment.

Benefits

  • Base salary of $200,000-$215,000 in Tier 1 locations (San Francisco, New York, Seattle).
  • Base salary of $190,000-$207,000 in Tier 2 locations (all other locations).
  • Eligibility for equity in addition to base pay.
  • Benefits package included with the role.
  • Remote-first, fully distributed work environment.
  • Opportunity to work for a mission-driven company focused on securing connected devices and supply chains.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

AVP, New Business Evaluation & Integration

Puck 1-10 Internet Software & Services

Fortitude Re is seeking a Treasury professional to support the evaluation, integration, and ongoing management of reinsurance and acquisition transactions across its Life, Annuity, and Property & Casualty businesses.

10 hours, 10 minutes ago

Manager, IT & Cybersecurity GRC

Veracyte 251-1K Pharmaceuticals

Veracyte is hiring a Manager, IT & Cybersecurity GRC to lead enterprise technology controls, IT SOX compliance, and cybersecurity risk governance in a highly regulated environment.

Cybersecurity
10 hours, 10 minutes ago

Program Success Lead

DailyRemote 1-10 Professional Services

Springboard is hiring a Program Success Lead to own delivery and growth of its Allied Health and AI programs across B2C and B2B, building new offerings from concept through execution in a fast-moving, student-centered environment.

10 hours, 25 minutes ago

Production & Supply Chain Operations Lead

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is hiring a Production & Supply Chain Operations Lead to support the Mission Systems Division as it scales from engineering development into production and field deployment.

10 hours, 25 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers