SlipstreamJobsFresh Startup & VC-Backed Jobs

Head of PSC Engineering

Finite State - Remote - Remote - posted 2026-09-10

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 250,000 - 300,000 / annual

Finite State is a Series B, fully distributed company that partners with product security teams to create transparency for connected devices and supply chains across enterprises, healthcare, utilities, connected vehicles, manufacturing, critical infrastructure, and government. The company's platform analyzes firmware and embedded systems to identify vulnerabilities, manage software supply chain risks, and ensure compliance. You will lead the Product Security Concierge (PSC) Engineering team, reporting to the Chief Security Officer. This is a manager-first role (~75-80% leadership, ~20-25% hands-on technical work) overseeing field-deployed product security solution engineers across firmware and binary analysis, penetration testing, platform support and integration, and managed-service delivery. Key responsibilities include: **People & Leadership:** Hire, onboard, coach, and develop PSC Engineers. Set objectives, run 1:1s and review cycles, provide direct feedback, and grow engineers into technical account owners and leaders. **Delivery Execution:** Own end-to-end engagement execution from technical scoping and staffing to deliverable review and debrief, including Level 2 support. Set playbooks, peer-review gates, and quality criteria. Report KPIs: utilization, time-to-deliverable, escape rate, and customer satisfaction. **Capacity & Utilization:** Plan team work against demand pipeline, balance billable work with managed-service shifts and capability development, and manage utilization to target. **Managed Services:** Stand up and scale PSIRTaaS and Standards and Regulations Compliance-as-a-Service, including runbooks, staffing model, SLAs, and platform capabilities. **Field-to-Product:** Collaborate with the Chief Product Security Engineer to ensure field-built tooling is logged and paved into the product. Represent the team in the Product Paving Council. **Strategic Customer Outcomes:** Serve as a trusted senior delivery contact for strategic accounts, lead service reviews and escalations, and partner with Sales on technical scoping and expansion. Travel is occasional for customer executive reviews, on-site engagements, conferences, and team gatherings. **Requirements:** - 3+ years of direct people management: hired, supervised, and developed engineers; run performance cycles; handled underperformance directly. This is core to the role. - Record of mentoring, coaching, and teaching with specific examples of people developed and outcomes achieved. - Prior exposure to formal management or leadership training (company leadership development program, management course/certificate, or equivalent structured program). - 8+ years in product security, embedded and connected device security, application security, or offensive security, with meaningful customer-facing services, consulting, or managed services experience. - Bachelor's degree in Computer Science, Electrical or Computer Engineering, Mathematics, Physical Sciences, or related field, or equivalent hands-on experience. - Hands-on depth in two or more of: firmware and binary analysis; penetration testing of embedded or IoT systems; threat modeling and TARA; SBOM and software composition analysis; vulnerability disclosure and CVE/CNA workflows; PSIRT operations. - Demonstrated ability to run a technical delivery function to SLAs, SLOs, and quality standards, including capacity and utilization management in a billable context. - Working knowledge of EU Cyber Resilience Act and at least one of: IEC 62443, RED EN 18031, FDA premarket cybersecurity requirements, ETSI EN 303 645, or NIST SSDF. Knowledge of ISO/IEC 29147 and 30111, CVSS, VEX, and SBOM formats (SPDX, CycloneDX). **Nice to Have:** - Experience building a service line (managed service or consulting offering) from process and runbooks to staffing model and SLAs. - Relevant credentials: CISSP, CSSLP, GIAC, OSCP, CISM, CRISC, ISO/IEC 27001 Lead Implementer, or IEC 62443 Cybersecurity Expert. - Sector depth in aerospace, medical, automotive, energy, or industrial cyber-physical systems and their TARA methods. - Knowledge of federal cyber policy (JSIG, ICD 503, NIST SP 800-160). Clearance eligibility is a plus.

Similar roles