Samsara2 дня назад

Staff Offensive Security Engineer

Зарплата не указана
РЫНОК
15 421медиана по профессии
CISO · 26 вакансий с указанной зарплатой
6 067половина предложений: 11 227–25 344785 375
Работодатель не указал зарплату — сравните с рынком сами.
Remote - US

Обязанности

  • 01Lead the ongoing strategy, operation, and continuous improvement of Samsara's vulnerability management program, along with other core application security programs
  • 02Own and drive down mean time to remediate (MTTR) across the vulnerability backlog, as SLAs tighten
  • 03Build and champion automation and tooling that scale vulnerability detection and response across cloud, firmware/IoT, and corporate systems
  • 04Set technical and architectural direction for the program, translating leadership's strategic priorities into a concrete execution plan for the team
  • 05Drive remediation by building trust with engineering teams and providing clear, actionable guidance
  • 06Mentor and level up other engineers on secure design and remediation practices
  • 07Communicate risk and remediation tradeoffs to engineering leadership in terms they can act on
  • 08Participate in security incident investigations involving high-profile vulnerabilities, assessing potential impact on Samsara's infrastructure
  • 09Be regularly on call to support critical vulnerability response
  • 10Champion, role model, and embed Samsara’s cultural principles as we scale globally and across new offices

Требования

  • 0110+ years of relevant experience as a cloud engineer or security engineer, including hands-on vulnerability management across a broad, multi-product enterprise environment
  • 02Proficiency in Go, Python, and JavaScript
  • 03Demonstrated ability to independently set technical and architectural direction for a security program, and to drive remediation across a broad, multi-surface environment without direct authority over the teams doing the fixing
  • 04Significant experience with modern vulnerability management tooling (e.g., Wiz, Semgrep) and deep familiarity with vulnerability scoring frameworks such as CVSS and EPSS
  • 05Strong AWS cloud services background
  • 06Deep understanding of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA)
  • 07Hands-on use of AI/LLM tooling in your own security workflow — triage, detection logic, remediation drafting — plus credibility speaking to how AI is changing the threat landscape and the tooling available to address it
  • 08Location: must be based in central or eastern timezones

Условия

  • 01This is a remote position, open to candidates residing in the US except the San Francisco Bay Metro Area, NYC Metro Area, and Washington, D.C. Metro Area., with working hours in the Central or Eastern time zone
  • 02Relocation assistance will not be provided for this role