4 hours ago
Base Salary
$165k - $295k/yr
Responsibilities
- Lead the strategy, operation, and continuous improvement of vulnerability management and other application security programs.
- Own efforts to reduce mean time to remediate across the vulnerability backlog as service-level requirements tighten.
- Build and champion automation and tooling for vulnerability detection and response across cloud, firmware/IoT, and corporate systems.
- Set technical and architectural direction and translate strategic priorities into execution plans.
- Drive remediation by partnering with engineering teams and providing actionable security guidance.
- Mentor engineers and serve as a technical authority on secure design and remediation practices.
- Communicate security risks and remediation tradeoffs to engineering leadership.
- Participate in investigations of high-profile vulnerabilities and assess infrastructure impact.
- Participate in regular on-call support for critical vulnerability response.
Requirements
- 10+ years of relevant experience as a cloud engineer or security engineer, including hands-on vulnerability management across a broad, multi-product enterprise environment.
- Proficiency in Go, Python, and JavaScript.
- Ability to independently set technical and architectural direction for a security program and drive remediation across teams without direct authority.
- Significant experience with vulnerability management tooling such as Wiz and Semgrep.
- Deep familiarity with CVSS and EPSS vulnerability scoring frameworks.
- Strong background with AWS cloud services.
- Deep understanding of Static Application Security Testing, Dynamic Application Security Testing, and Software Composition Analysis.
- Hands-on use of AI/LLM tooling for security workflows and the ability to discuss AI’s impact on the threat landscape.
- Preferred experience with C/C++, firmware and embedded systems, cloud-native or AI-forward companies, Tines, AWS Lambda, vulnerability management in CI/CD pipelines, SaaS and corporate IT security, FedRAMP-certified environments, and AI security copilots or agents.
Benefits
- Remote position open to candidates residing in the US.
- Flexible employee-led remote model with offices available for employees who prefer in-person work.
- Professional development stipend.
- Comprehensive health and parental leave plans.
- Initial RSU grant with no vesting cliff and ongoing performance-based refresh opportunities.
- Performance-based bonus or variable pay and equity eligibility may be available.
- Employment is contingent on maintaining the legal right to work at the company and in the specified work location.
About Samsara
Samsara builds a Connected Operations Cloud that uses IoT hardware and software to help fleets and other physical-operations organizations monitor vehicles, assets, and worksites. Its platform spans video-based driver safety, vehicle telematics, equipment monitoring, and mobile workflows, sold as subscriptions with accompanying devices. Founded in 2015 and headquartered in San Francisco, Samsara is a public company on the NYSE (ticker: IOT) serving transportation, construction, manufacturing, field services, and government.
