
Staff Offensive Security Engineer
Posted 20 hours ago

Posted 20 hours ago
This is a fully remote position, open to applicants in California, +1 more state.
• Lead the strategy, operations, and continuous enhancement of Samsara's vulnerability management and core application security initiatives.
• Take ownership of reducing the mean time to remediate issues within the vulnerability backlog.
• Develop and advocate for automation and tools designed for vulnerability detection and response across cloud, firmware/IoT, and corporate systems.
• Establish technical and architectural direction, translating strategic priorities into actionable execution plans.
• Foster remediation efforts by building trust with engineering teams and offering practical guidance.
• Collaborate with technical program management on reporting activities.
• Mentor and guide engineers on secure design principles and remediation techniques.
• Articulate risk and remediation trade-offs to engineering leadership.
• Engage in security incident investigations concerning high-profile vulnerabilities.
• Be available on call for critical vulnerability response.
• Promote Samsara's cultural principles as the company expands globally and opens new offices.
• 10+ years of relevant experience as a cloud engineer or security engineer.
• Practical experience in vulnerability management within a diverse, multi-product enterprise setting.
• Proficiency in programming languages such as Go, Python, and JavaScript.
• Capability to independently establish technical and architectural direction for a security program.
• Ability to drive remediation efforts across a wide-ranging, multi-surface environment without direct authority over the teams responsible for fixes.
• Extensive experience with vulnerability management tools like Wiz and Semgrep.
• Strong familiarity with CVSS and EPSS vulnerability scoring frameworks.
• Solid background in AWS cloud services.
• In-depth understanding of SAST, DAST, and SCA methodologies.
• Practical experience using AI/LLM tools in security workflows.
• Credibility in discussing the impact of AI on the threat landscape and security tools.
• Must reside in Central or Eastern time zones.
• Ideal candidates will have experience with C/C++ for firmware and embedded systems.
• A background in a cloud-native, AI-driven company is preferred.
• Familiarity with Tines and AWS Lambda is a plus.
• Experience integrating vulnerability management into CI/CD pipelines is desirable.
• Experience that spans SaaS, firmware, and corporate IT security programs is advantageous.
• Familiarity with managing vulnerabilities in a FedRAMP-certified environment is preferred.
• Experience building or enhancing AI copilots/agents for security workflows is ideal.
• Initial RSU grant with no vesting cliff.
• Ongoing equity refresh opportunities linked to performance.
• Performance-based bonus/variable pay.
• Flexible, employee-driven remote work model.
• Stipend for professional development.
• Comprehensive health plans.
• Parental leave policies.
• Above-market total compensation.
• Flexible working arrangements.
• Reasonable accommodations provided throughout the recruiting process.
Atos
Meridian Bioscience Inc.
Providence
Frontera
Get handpicked remote jobs straight to your inbox weekly.