
Staff Application Security Engineer
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in United States.
• Lead the overall technical strategy for application security and vulnerability management initiatives.
• Oversee the strategy, operations, and ongoing enhancement of the vulnerability management program.
• Take ownership of and work to minimize the mean time to remediate vulnerabilities in the backlog.
• Develop and advocate for automation and tools to enhance vulnerability detection and response across cloud platforms, firmware/IoT, and corporate systems.
• Establish technical and architectural guidelines, translating strategic objectives into actionable plans.
• Facilitate remediation efforts by building trust with engineering teams and providing clear, actionable guidance.
• Collaborate with technical program management on reporting initiatives.
• Mentor and enhance the skills of engineers in secure design and remediation practices.
• Articulate risk and remediation trade-offs to engineering leadership effectively.
• Engage in security incident investigations concerning high-profile vulnerabilities.
• Be available on call for urgent vulnerability response situations.
• Promote and integrate Samsara's cultural principles as the organization expands globally.
• A minimum of 10 years of relevant experience as a cloud engineer or security engineer.
• Practical experience in vulnerability management within a diverse, multi-product enterprise environment.
• Proficient in programming languages such as Go, Python, and JavaScript.
• Capability to independently establish technical and architectural direction for a security program.
• Ability to drive remediation across various platforms without direct authority over the teams implementing fixes.
• Extensive experience with vulnerability management tools like Wiz and Semgrep.
• Strong familiarity with CVSS and EPSS vulnerability scoring systems.
• Solid background in AWS cloud services.
• In-depth knowledge of SAST, DAST, and SCA methodologies.
• Practical experience using AI/LLM tools in security workflows.
• Credibility in discussing the impact of AI on the threat landscape and security tools.
• Experience with C/C++ for firmware and embedded systems (preferred).
• Background in a cloud-native, AI-focused company that develops agentic or AI-driven products (preferred).
• Familiarity with security automation platforms like Tines and serverless technologies such as AWS Lambda (preferred).
• Experience in integrating vulnerability management into contemporary CI/CD pipelines (preferred).
• Experience that encompasses SaaS, firmware, and corporate IT security programs (preferred).
• Experience managing vulnerabilities in a FedRAMP-certified environment (preferred).
• Experience in developing, extending, or integrating AI copilots/agents for security workflows (preferred).
• Initial RSU grant without a vesting cliff.
• Continuous equity refresh opportunities based on performance.
• Performance-related bonus/variable pay.
• Equity available for eligible positions.
• Flexible, employee-driven remote working model.
• Professional development stipend.
• Comprehensive health insurance plans.
• Parental leave policies.
• Flexible working arrangements.
• Support for remote work.
• Option for in-person office work.
• Commitment to equal opportunity employment.
• Reasonable accommodations provided throughout the recruitment process.
ExactCare
Devexperts
Motive
Get handpicked remote jobs straight to your inbox weekly.