
Staff Offensive Security Engineer
Posted 20 hours ago

Posted 20 hours ago
This is a fully remote position, open to applicants in United States.
• Spearhead the strategy, operations, and ongoing enhancement of Samsara's vulnerability management and core application security initiatives.
• Take ownership of and minimize the mean time to remediate vulnerabilities in the backlog.
• Develop and promote automation and tools for vulnerability detection and response across cloud, firmware/IoT, and corporate systems.
• Establish technical and architectural direction, translating strategic objectives into an actionable execution plan.
• Foster remediation efforts by building trust with engineering teams and offering practical guidance.
• Collaborate with technical program management to provide comprehensive reporting.
• Mentor and nurture engineers in secure design and remediation methodologies.
• Articulate risk and remediation trade-offs to engineering leadership.
• Engage in security incident investigations involving significant vulnerabilities.
• Be available on-call for urgent vulnerability responses.
• Advocate for and integrate Samsara's cultural principles throughout the organization.
• Over 10 years of relevant experience as a cloud engineer or security engineer.
• Practical experience in vulnerability management within a diverse, multi-product enterprise environment.
• Proficiency in programming languages such as Go, Python, and JavaScript.
• Capacity to independently establish technical and architectural direction for a security program.
• Ability to drive remediation efforts across a varied, multi-surface environment without direct authority.
• Extensive familiarity with modern vulnerability management tools like Wiz and Semgrep.
• In-depth understanding of CVSS and EPSS vulnerability scoring frameworks.
• Strong background in AWS cloud services.
• Comprehensive knowledge of SAST, DAST, and SCA.
• Hands-on experience utilizing AI/LLM tools in security workflows.
• Capability to discuss the evolving threat landscape and the impact of AI on available security tools.
• Must reside in Central or Eastern time zones.
• Ideal candidates will have experience with C/C++ relevant to firmware and embedded systems.
• Preferred background in a cloud-native, AI-driven company focused on developing agentic or AI-based products.
• Experience with security automation platforms such as Tines and serverless frameworks like AWS Lambda is a plus.
• Familiarity with integrating vulnerability management into modern CI/CD pipelines is desirable.
• Experience encompassing SaaS, firmware, and corporate IT security programs is preferred.
• Experience managing vulnerabilities in a FedRAMP-certified environment is ideal.
• Experience in building or enhancing AI copilots/agents for security workflows is a plus.
• Initial RSU grant without a vesting cliff.
• Continuous equity refresh opportunities linked to performance.
• Performance-driven bonus/variable pay.
• Equity options for eligible roles.
• Flexible, employee-driven remote work model.
• Professional development stipend.
• Comprehensive health insurance plans.
• Parental leave benefits.
• Flexible working arrangements.
• Commitment to equal opportunity employment.
• Reasonable accommodations throughout the recruitment process.
Atos
Meridian Bioscience Inc.
Providence
Frontera
Get handpicked remote jobs straight to your inbox weekly.