Staff Application Security Engineer
Ai Security
Application Security
Dast Security
Dynamic Application Security Testing
Epss
Information Security
InfoSec
Risk Management
Security
Security Automation
Security Testing
Software Composition Analysis
Software Security
Static Analysis Security
Static Application Security Testing
Vulnerability Management
Job Description
Lead the technical direction for application security and vulnerability management programs in a remote US-based role.
Responsibilities
- Own the ongoing strategy, operations, and continuous improvement for vulnerability management and other application security programs, including defining what the process should be
- Drive down mean time to remediate (MTTR) across the vulnerability backlog as SLAs tighten
- Build and champion scalable automation and tooling for vulnerability detection and response across cloud, firmware/IoT, and corporate systems
- Set program technical and architectural direction by translating leadership priorities into an execution plan
- Drive remediation by partnering with engineering teams to provide clear, actionable guidance, and work with technical program management on reporting
- Mentor and level up engineers on secure design and remediation practices
- Serve as a technical voice when priorities are unclear across teams
- Communicate risk and remediation tradeoffs to engineering leadership in a way they can act on (without owning the relationship end to end)
- Participate in security incident investigations involving high-profile vulnerabilities and assess potential impact to Samsara infrastructure
- Be regularly on call to support critical vulnerability response
- Champion and embed Samsara cultural principles: Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team as the organization scales globally
Requirements
- 10+ years of relevant experience as a cloud engineer or security engineer, including hands-on vulnerability management across a broad, multi-product enterprise environment
- Proficiency in Go, Python, and JavaScript
- Demonstrated ability to independently set technical and architectural direction for a security program
- Proven track record driving remediation across a broad multi-surface environment without direct authority over fixing teams
- Significant experience with modern vulnerability management tooling, such as Wiz and Semgrep
- Deep familiarity with vulnerability scoring frameworks including CVSS and EPSS
- Strong background with AWS cloud services
- Deep understanding of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA)
- Hands-on use of AI/LLM tooling in your own security workflow (triage, detection logic, remediation drafting)
- Credibility speaking to how AI is changing the threat landscape and the tooling available to address it
- Ideal candidate experience also includes: C/C++ for firmware and embedded systems
Technologies
- Go, Python, JavaScript
- Wiz, Semgrep
- CVSS, EPSS
- AWS
- Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA)
- AI/LLM, AI copilots/agents
- C/C++
- Tines
- AWS Lambda
- CI/CD
- FedRAMP
- AI copilots/agents for security workflows
Benefits
- Compensation program delivers above-market total compensation via base salary, performance-based bonus/variable pay, and equity (for eligible roles)
- Flexible, employee-led remote model
- Professional development stipend
- Comprehensive health and parental leave plans
Flexible Working
- Flexible working model to match team needs
- Offices are open for those who prefer in-person work
- Remote work is supported where it aligns with operational requirements
- Some roles may require proximity to an office or specific geography for collaboration and resources
- Employment offers are contingent on ability to secure and maintain legal right to work in the specified location, if applicable
Belonging at Samsara
- Equal opportunity for qualified applicants regardless of race, color, religion, national origin, sex, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other protected characteristics
- Samsara welcomes applicants regardless of background
Accommodations
- Inclusive environment with commitment to equal opportunity for qualified persons with disabilities
- For reasonable accommodations during the recruiting process: [email protected] (or click the provided link)
Fraud Prevention and Interview Scams
- Samsara uses Tofu, a fraud detection tool, to validate application authenticity and protect against identity fraud
- Samsara is aware of scams involving fake job interviews and offers
- Samsara does not charge fees to applicants at any stage of the hiring process
- Official communication about your application will come only from emails ending in @samsara.com, @us-greenhouse-mail.io, or @mail3.guide.co