
Staff Application Security Engineer
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in United States.
• Oversee the strategy, operations, and ongoing enhancement of Samsara's vulnerability management and application security initiatives.
• Reduce the average time needed to resolve issues within the vulnerability backlog.
• Develop and advocate for automation and tools aimed at vulnerability detection and response across cloud, firmware/IoT, and corporate systems.
• Establish technical and architectural direction while converting strategic priorities into actionable plans.
• Facilitate remediation efforts by collaborating with engineering teams and offering practical guidance.
• Collaborate with technical program management on reporting activities.
• Mentor and nurture engineers in secure design and remediation techniques.
• Articulate risks and remediation tradeoffs to engineering leadership effectively.
• Engage in security incident investigations related to high-profile vulnerabilities.
• Be available on call for urgent vulnerability responses.
• Promote and integrate Samsara's cultural principles as the organization expands globally.
• Minimum of 10 years of relevant experience as a cloud or security engineer.
• Hands-on experience in vulnerability management across a diverse, multi-product enterprise landscape.
• Proficient in programming languages such as Go, Python, and JavaScript.
• Capability to independently establish technical and architectural guidance for a security program.
• Ability to drive remediation across a wide-ranging, multi-surface environment without direct authority over remediation teams.
• Extensive experience with vulnerability management tools like Wiz and Semgrep.
• Thorough understanding of CVSS and EPSS vulnerability scoring frameworks.
• Strong background in AWS cloud services.
• In-depth knowledge of SAST, DAST, and SCA methodologies.
• Practical experience with AI/LLM tools in security workflows.
• Experience with C/C++ related to firmware and embedded systems (preferred).
• Background in a cloud-native, AI-driven company focused on building agentic or AI-enhanced products (preferred).
• Familiarity with security automation platforms such as Tines and serverless frameworks like AWS Lambda (preferred).
• Experience integrating vulnerability management within CI/CD pipelines with a shift-left approach (preferred).
• Exposure to SaaS, firmware, and corporate IT security programs (preferred).
• Experience managing vulnerabilities within a FedRAMP-certified environment (preferred).
• Experience in creating or enhancing AI copilots/agents for security workflows (preferred).
• Initial RSU grant with no vesting cliff.
• Continuous equity refresh opportunities based on performance.
• Performance-driven bonus or variable compensation.
• Equity options available for eligible positions.
• Flexible, employee-driven remote work model.
• Stipend for professional development.
• Comprehensive health coverage options.
• Parental leave benefits.
• Adaptable working arrangements.
• Remote work assistance aligned with operational needs.
ExactCare
Devexperts
Motive
Get handpicked remote jobs straight to your inbox weekly.