
Staff Application Security Engineer
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in United States.
• Lead the strategy, operations, and ongoing enhancement of Samsara's vulnerability management and application security initiatives.
• Take ownership of and minimize the mean time to remediate within the vulnerability backlog.
• Develop automation and tools for vulnerability detection and response across cloud, firmware/IoT, and corporate systems.
• Establish technical and architectural direction while translating strategic priorities into actionable execution plans.
• Facilitate remediation efforts by collaborating with engineering teams and providing actionable recommendations.
• Work alongside technical program management on reporting activities.
• Mentor engineers in secure design principles and remediation practices.
• Articulate risk and remediation trade-offs to engineering leadership.
• Involve yourself in security incident investigations related to high-profile vulnerabilities.
• Be on call regularly for critical vulnerability response situations.
• Advocate for Samsara's cultural principles as the organization expands globally.
• Over 10 years of relevant experience as a cloud engineer or security engineer.
• Hands-on experience with vulnerability management in a diverse, multi-product enterprise environment.
• Proficient in Go, Python, and JavaScript.
• Capability to independently determine technical and architectural direction for a security program.
• Proven ability to drive remediation efforts across a broad, multi-surface environment without direct authority over remediation teams.
• Extensive experience with vulnerability management tools such as Wiz and Semgrep.
• Strong understanding of CVSS and EPSS.
• Solid background in AWS cloud services.
• Comprehensive knowledge of SAST, DAST, and SCA.
• Practical experience utilizing AI/LLM tools within security workflows.
• Ability to articulate how AI is transforming the threat landscape and security tools.
• Experience with C/C++ related to firmware and embedded systems is preferred.
• Background in a cloud-native, AI-focused company developing agentic or AI-driven products is preferred.
• Familiarity with security automation platforms like Tines and serverless frameworks such as AWS Lambda is preferred.
• Experience in integrating vulnerability management into modern CI/CD pipelines with a shift-left approach is preferred.
• Experience covering SaaS, firmware, and corporate IT security programs is preferred.
• Experience managing vulnerabilities in a FedRAMP-certified environment is preferred.
• Experience in building, extending, or integrating AI copilots/agents for security workflows is preferred.
• Initial RSU grant with no vesting cliff.
• Continuous equity refresh opportunities linked to performance.
• Performance-based bonus/variable pay.
• Flexible, employee-led remote working model.
• Professional development stipend.
• Comprehensive health plans.
• Parental leave plans.
• Competitive total compensation above the market average.
• Flexible working arrangements.
• Support for remote work.
• Option for in-person office attendance.
ExactCare
Devexperts
Motive
Get handpicked remote jobs straight to your inbox weekly.