Samsara2 дня назад
Staff Offensive Security Engineer
Зарплата не указана
РЫНОК
15 421 ₽медиана по профессии
CISO · 26 вакансий с указанной зарплатой
6 067половина предложений: 11 227–25 344785 375
Работодатель не указал зарплату — сравните с рынком сами.
Remote - UK
Обязанности
- 01Lead the ongoing strategy, operation, and continuous improvement of Samsara's vulnerability management program, along with other core application security programs — not just execute against an existing process, but define what the process should be.
- 02Own and drive down mean time to remediate (MTTR) across the vulnerability backlog, as SLAs tighten.
- 03Build and champion automation and tooling that scale vulnerability detection and response across cloud, firmware/IoT, and corporate systems, rather than relying on manual, one‑by‑one review.
- 04Set technical and architectural direction for the program, translating leadership's strategic priorities into a concrete execution plan for the team.
- 05Drive remediation by building trust with engineering teams and providing clear, actionable guidance — partnering with technical program management on reporting rather than owning it directly.
- 06Mentor and level up other engineers on secure design and remediation practices, and be a technical voice other teams look to when priorities are unclear.
- 07Communicate risk and remediation tradeoffs to engineering leadership in terms they can act on, without owning the relationship end to end.
- 08Participate in security incident investigations involving high‑profile vulnerabilities, assessing potential impact on Samsara's infrastructure.
- 09Be regularly on call to support critical vulnerability response.
- 10Champion, role model, and embed Samsara’s cultural principles (Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team) as we scale globally and across new offices
Требования
- 0110+ years of relevant experience as a cloud engineer or security engineer, including hands-on vulnerability management across a broad, multi-product enterprise environment — not a single product or team's slice of it.
- 02Proficiency in Go, Python, and JavaScript.
- 03Demonstrated ability to independently set technical and architectural direction for a security program, and to drive remediation across a broad, multi-surface environment without direct authority over the teams doing the fixing.
- 04Significant experience with modern vulnerability management tooling (e.g., Wiz, Semgrep) and deep familiarity with vulnerability scoring frameworks such as CVSS and EPSS.
- 05Strong AWS cloud services background.
- 06Deep understanding of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
- 07Hands-on use of AI/LLM tooling in your own security workflow — triage, detection logic, remediation drafting — plus credibility speaking to how AI is changing the threat landscape and the tooling available to address it.
- 08Experience with C/C++, relevant to firmware and embedded systems.
- 09Background at a cloud-native, AI-forward company actively building agentic or AI-driven products.
- 10Experience with security automation platforms (e.g., Tines) and serverless frameworks (e.g., AWS Lambda).
- 11Experience integrating vulnerability management into modern CI/CD pipelines with a "shift-left" mindset
Условия
- 01Remote position
- 02Open to candidates residing in the UK
- 03No relocation assistance provided
- 04Must be based in central or eastern time zones