
Staff Application Security Engineer
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in Washington.
• Oversee the strategy, operations, and ongoing enhancement of Samsara's vulnerability management and core application security initiatives.
• Reduce the mean time to remediate issues within the vulnerability backlog.
• Develop and promote automation and tools for vulnerability detection and response across cloud, firmware/IoT, and corporate systems.
• Establish technical and architectural direction while converting strategic objectives into actionable plans.
• Facilitate remediation efforts by collaborating with engineering teams and offering practical guidance.
• Work alongside technical program management to ensure accurate reporting.
• Mentor and nurture engineers in secure design and remediation techniques.
• Articulate risk and remediation trade-offs to engineering leadership.
• Engage in security incident investigations related to high-profile vulnerabilities.
• Be available on-call for critical vulnerability responses.
• Advocate for and integrate Samsara's cultural principles as the company expands globally.
• Over 10 years of pertinent experience as a cloud engineer or security engineer.
• Practical experience in vulnerability management within a diverse, multi-product enterprise setting.
• Proficient in Go, Python, and JavaScript.
• Capable of independently determining technical and architectural direction for a security initiative.
• Skilled in driving remediation across a wide-ranging, multi-surface environment without direct authority over remediation teams.
• Extensive experience with contemporary vulnerability management tools, including Wiz and Semgrep.
• In-depth knowledge of CVSS and EPSS vulnerability scoring systems.
• Strong background in AWS cloud services.
• Comprehensive understanding of SAST, DAST, and SCA methodologies.
• Hands-on experience utilizing AI/LLM tools in security workflows.
• Ability to discuss the impact of AI on the threat landscape and security tools.
• Preferred experience with C/C++ related to firmware and embedded systems.
• Background in a cloud-native, AI-driven company is preferred.
• Experience with security automation platforms like Tines and serverless frameworks such as AWS Lambda is preferred.
• Familiarity with integrating vulnerability management into modern CI/CD pipelines is preferred.
• Experience across SaaS, firmware, and corporate IT security programs is preferred.
• Experience managing vulnerabilities within a FedRAMP-certified environment is preferred.
• Experience in building or enhancing AI copilots/agents for security workflows is preferred.
• Legal authorization to work at the company and in the specified location is required.
• Initial RSU grant with no vesting cliff.
• Continuous refresh opportunities linked to performance.
• Performance-based bonuses/variable pay.
• Eligibility for equity in applicable roles.
• Flexible, employee-driven remote working model.
• Stipend for professional development.
• Comprehensive health insurance plans.
• Parental leave benefits.
• Support for remote work.
• Option for in-person office attendance.
• Reasonable accommodations available throughout the recruitment process.
ExactCare
Devexperts
Motive
Get handpicked remote jobs straight to your inbox weekly.