Staff Offensive Security Engineer

Posted 20 hours ago

This is a fully remote position, open to applicants in California, +1 more state.

📋 Description

• Lead the strategy, operations, and continuous enhancement of Samsara's vulnerability management and core application security initiatives.

• Take ownership of reducing the mean time to remediate issues within the vulnerability backlog.

• Develop and advocate for automation and tools designed for vulnerability detection and response across cloud, firmware/IoT, and corporate systems.

• Establish technical and architectural direction, translating strategic priorities into actionable execution plans.

• Foster remediation efforts by building trust with engineering teams and offering practical guidance.

• Collaborate with technical program management on reporting activities.

• Mentor and guide engineers on secure design principles and remediation techniques.

• Articulate risk and remediation trade-offs to engineering leadership.

• Engage in security incident investigations concerning high-profile vulnerabilities.

• Be available on call for critical vulnerability response.

• Promote Samsara's cultural principles as the company expands globally and opens new offices.


⛳️ Requirements

• 10+ years of relevant experience as a cloud engineer or security engineer.

• Practical experience in vulnerability management within a diverse, multi-product enterprise setting.

• Proficiency in programming languages such as Go, Python, and JavaScript.

• Capability to independently establish technical and architectural direction for a security program.

• Ability to drive remediation efforts across a wide-ranging, multi-surface environment without direct authority over the teams responsible for fixes.

• Extensive experience with vulnerability management tools like Wiz and Semgrep.

• Strong familiarity with CVSS and EPSS vulnerability scoring frameworks.

• Solid background in AWS cloud services.

• In-depth understanding of SAST, DAST, and SCA methodologies.

• Practical experience using AI/LLM tools in security workflows.

• Credibility in discussing the impact of AI on the threat landscape and security tools.

• Must reside in Central or Eastern time zones.

• Ideal candidates will have experience with C/C++ for firmware and embedded systems.

• A background in a cloud-native, AI-driven company is preferred.

• Familiarity with Tines and AWS Lambda is a plus.

• Experience integrating vulnerability management into CI/CD pipelines is desirable.

• Experience that spans SaaS, firmware, and corporate IT security programs is advantageous.

• Familiarity with managing vulnerabilities in a FedRAMP-certified environment is preferred.

• Experience building or enhancing AI copilots/agents for security workflows is ideal.


🏝️ Benefits

• Initial RSU grant with no vesting cliff.

• Ongoing equity refresh opportunities linked to performance.

• Performance-based bonus/variable pay.

• Flexible, employee-driven remote work model.

• Stipend for professional development.

• Comprehensive health plans.

• Parental leave policies.

• Above-market total compensation.

• Flexible working arrangements.

• Reasonable accommodations provided throughout the recruiting process.

People also viewed

Atos14 hours ago

Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Meridian Bioscience Inc.14 hours ago

Medical Device Cybersecurity Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Providence14 hours ago

Senior Security Engineer – Identity and Access Management

US flagCalifornia, +2 more statesFull-timeCybersecurity / Security Engineer$54 – $122/hour
ApplyView job
Frontera14 hours ago

Head of Information Security – Compliance

US flagColorado OnlyFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job
Accela15 hours ago

Cybersecurity Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$90k – $110k/year
ApplyView job
Climb Channel Solutions NA18 hours ago

Senior Director, Enterprise Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$225k – $260k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers