Lead Software Engineer @FiniteStateInc

Joined May 2026
Photos and videos
A great recognition of the work our team is doing to advance firmware security, vulnerability analysis, and software supply chain security. x.com/FiniteStateInc/status/…

Finite State has been awarded the 2026 Cybersecurity Stars Award for Firmware Security & Vulnerability Analysis Platform, recognizing our innovation and impact in product security. Thank you to The Hacker News, the judges, our customers, and our team for this recognition. #Cybersecurity #ProductSecurity #FirmwareSecurity #SBOM #SoftwareSupplyChain
Alex Baker retweeted
Finite State is hiring across marketing, sales, engineering, and more! 🚀 Join a remote-first team to tackle critical cybersecurity challenges for the connected world. Deep autonomy, massive impact, and equity in our growth. Find your role: finitestate.io/careers #CybersecurityJobs #Hiring
5
3
50
Everyone's prepping their new products for the CRA. The real work is the firmware you shipped years ago and forgot about. That backlog is the deadline. x.com/FiniteStateInc/status/…

The CRA obligation most teams miss: it covers everything you still support, including devices shipped long ago. Sept 11, 2026: Exploited vulnerabilities must hit ENISA in 24 hours, for every product. Our Head of Policy and Compliance, Doc McConnell, breaks it down. finitestate.io/blog/cra-retr… #EUCRA #ProductSecurity
2
Whatever the federal review process settles on, capable AI is already on the market. Defenders who build it into monitoring now will be in better shape than the ones waiting for clearance. x.com/FiniteStateInc/status/…

The strongest tools for defending against AI-enabled attacks aren't on a federal waiting list; they're already available. Finite State's Doc McConnell in AI Business on putting today's AI to work now. #CyberDefense bit.ly/4x8UWgq
2
Are you generating compliance evidence continuously alongside your development cycle, or treating it as a separate, disconnected project? x.com/FiniteStateInc/status/…

Finite State runs product security continuously alongside your team, from first commit through end of support, generating audit-ready evidence at every stage without holding up a release. We call it the Parallel Rail. When an audit, customer security review, or new CVE lands, the answer is already in hand. See how it works: bit.ly/4upGNdf #ProductSecurity #SBOM #FirmwareSecurity #EUCRA #FiniteState
2
If AI already finds and exploits vulnerabilities faster than people can, who in your org gets that capability first, and how long does everyone else wait? x.com/FiniteStateInc/status/…

The new federal AI executive order reviews frontier AI models for cyber risk, then keeps the most capable behind classified benchmarking and early-access pilots. Finite State's Doc McConnell makes the case for sharing more, not less. #AISecurity bit.ly/43cGM0e
4
Honored to be part of a team whose work has been recognized with a shortlist placement for the 2026 AutoTech Awards Cybersecurity Excellence Award. x.com/FiniteStateInc/status/…

Finite State has been shortlisted for the 2026 AutoTech Awards Cybersecurity Excellence Award for our Product Security OS. Built for connected vehicles. Focused on compliance, visibility, and defensible risk decisions. bit.ly/4ejISSd #ConnectedVehicles #AutomotiveCybersecurity #FiniteState
2
Sharon Hagi on why product security has to be grounded in binary reality: what you actually compile and ship, not what the manifest says. x.com/FiniteStateInc/status/…

A monitor sees what your firmware does, not what it's made of, for example, a library that quietly hit end-of-life. Pre-ship analysis tells you what's in the build and what's actually reachable. More from our CSO, Sharon Hagi, on how pre-ship and runtime fit together: finitestate.io/blog/pre-ship… #ProductSecurity #SBOM
3
If governments are deploying frontier AI to defend critical infrastructure, who are they building it with? Responsible speed isn't a solo effort. x.com/FiniteStateInc/status/…

GCHQ wants a national AI cyber defense layer for UK critical infrastructure. Finite State's Doc McConnell: "The greatest risk right now is inaction," and responsible speed takes private-sector partners. #OTSecurity intelligentciso.com/2026/06/…
5
If a zero-day in your routing infrastructure was exploited today, how confident are you that your vendor would tell you? Read our team's take on the Luxembourg telecom outage in the IoT M2M Council. x.com/FiniteStateInc/status/…

A zero-day in telecom routing infrastructure caused three hours of nationwide outages in Luxembourg. 10 months later: no public CVE and no patch confirmation. Finite State's Matt Wyckhouse and Sharon Hagi weigh in on the visibility defenders need today. iotm2mcouncil.org/iot-librar… #TelecomSecurity #FirmwareSecurity
3
The biggest practical security risk isn't who made the router. It's whether it still gets patched. x.com/FiniteStateInc/status/…

"Preventing updates could unintentionally make Americans less safe." Finite State's Doc McConnell in The Register on the FCC extending firmware update waivers for foreign-made routers and drones through Jan 2029. More insights: theregister.com/networks/202… #FirmwareSecurity #RouterSecurity
3
Great insights from Matt Wyckhouse on the operational reality of the FCC waiver and keeping deployed devices secure. x.com/FiniteStateInc/status/…

100M active US routers avoided being frozen in time. The FCC extended the firmware update waiver for deployed foreign-made routers through Jan 2029. Matt Wyckhouse in Inc. on why continuous patches remain the primary defense: inc.com/chris-morris/the-fcc… #FirmwareSecurity #FCC
3
Anyone looking for an engineering manager role? x.com/FiniteStateInc/status/…

Finite State is hiring a Sr. Engineering Manager! 💻 Lead AI-native development teams and redefine how we ship secure software by integrating modern AI tooling and automated quality systems into the SDLC. Apply here: job-boards.greenhouse.io/fin… #EngineeringJobs
3
Alex Baker retweeted
FCC extends firmware update waivers for foreign-made routers and drones through Jan 2029. Finite State’s Matt Wyckhouse and Joshua Marpet in Cybernews: blocking patches on deployed devices just widens the attack surface. cybernews.com/tech/us-eases-… #FirmwareSecurity #FCC
6
2
179
Alex Baker retweeted
At IoT Tech Expo in San Jose, Finite State’s Roland Lindsey emphasized securing the entire connected device stack: “What we ship to customers is what we’re responsible for.” Attackers look for vulnerabilities at every layer. Visibility across firmware, binaries, and source code is critical. See how Finite State helps teams prioritize real exposure: bit.ly/4uZL86G #IoTSecurity #Cybersecurity #FiniteState #IoTTechExpo
5
2
26
Alex Baker retweeted
A source-manifest SBOM won't survive EU CRA scrutiny. Auditors demand ground truth instead of build-time assumptions. Our CRA managed service uses deep binary analysis to generate five maintained compliance deliverables per release. Evaluate the workflow: finitestate.io/cra
4
3
32
Alex Baker retweeted
Without the FCC's extension last week, millions of US routers would have lost their patch pipeline in 2027. Why the reversal is the right cybersecurity call: bit.ly/3PbQTiB #ProductSecurity #FCC
1
5
3
34
Alex Baker retweeted
Automakers have made progress on engineering and vulnerability disclosure. 🚗 The harder test is proving it works across vehicles, cloud, mobile apps, and supplier code. Finite State CEO Matt Wyckhouse in the Wall Street Journal: wsj.com/pro/cybersecurity/co… #AutomotiveCybersecurity
4
3
159
Alex Baker retweeted
"Who owns your firmware? Your devices? The NAND chips inside them?" 🌐 Joshua Marpet tells Industrial Cyber's Anna Ribeiro why cyber sovereignty means cracking open the "black box" of connected devices. Defending IT/OT demands binary-level truth. Read: bit.ly/3R83BiB
4
3
211
Alex Baker retweeted
A university student with off-the-shelf SDR gear triggered emergency braking on Taiwan's high-speed rail. Finite State's Larry Pesce on what TETRA's design assumptions look like in 2026: bit.ly/4ff4O1E #OTSecurity #RailSecurity
5
4
156