MTS Manager
$190,000–$215,000 year
Remote · United States
Job Summary
Operationally lead and deliver Finite State’s Product Security Technical Managed Services, including binary firmware analysis, device penetration testing, TARAs, SBOM/SCA generation, vulnerability response, triage, remediation, and long-term engagement support for connected product OEMs. Drive the design, build-out, and scaling of PSIRT-as-a-Service, EU CRA compliance, and related offerings, using the company's AI Product Security Automation Platform as the delivery spine. Manage a multi-disciplinary team of security engineers and analysts, own engagement lifecycles, define SLAs/SLOs/KPIs, mentor staff, and partner with Product, Engineering, Sales, Marketing, Legal, and Regulatory teams to translate field experience into platform requirements, packaging, pricing, and go-to-market enablement. Lead senior customer-facing delivery for strategic accounts, ensure delivery quality, and identify expansion opportunities while maintaining a fully remote operating environment.
Required Qualifications
- Bachelor's degree in Computer Science, Mathematics, Physical Sciences, Electrical/Computer Engineering, or equivalent demonstrable experience and certifications; advanced degree desirable
- Minimum 8 years of relevant experience in product security, embedded/connected device security, application security, or offensive security — a meaningful portion delivered in a customer-facing services, consulting, or managed services context
- Minimum 4 years of direct people management experience, including hiring, performance management, mentorship, and team development
- Demonstrated experience standing up new service offerings or productizing technical capabilities within a managed services or information technology environments is strongly preferred
- Hands-on technical depth in two or more of: binary/firmware analysis, penetration testing of embedded or IoT systems, threat modeling and TARA, SBOM and software composition analysis, vulnerability management and disclosure (CVE/CNA workflows), PSIRT/ESIRT operations
- Technical
- One or more of the following is required: CISSP, CSSLP, CCSP, GIAC (GPEN/GXPN/GREM/GICSP), OSCP, or equivalent demonstrated technical depth
- Certifications
- Familiarity with vulnerability analysis and reverse engineering tools
- Familiarity with SAST/DAST/IAST tooling categories
- Familiarity with offensive security tooling
- Familiarity with collaboration and delivery tooling
- Comfort operating in a fully remote, cloud-only company environment
- Compensation
- Tier 1 (San Francisco, New York, Seattle): $200,000 - $215,000; Tier 2 (All Other Locations): $190,000 - $207,000
- Tools and Environments
- Familiarity with vulnerability analysis and reverse engineering tools
- Familiarity with SAST/DAST/IAST tooling categories
- Familiarity with offensive security tooling
- Familiarity with collaboration and delivery tooling
- Familiarity with in-house platform and AI-assisted vulnerability triage
Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf — no cover letters, no 40-minute forms.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.