2 hours ago
Base Salary
$165k - $266k/yr
Responsibilities
- Lead the strategy, operation, and continuous improvement of vulnerability management and other application security programs.
- Own efforts to reduce mean time to remediate across the vulnerability backlog.
- Build automation and tooling for vulnerability detection and response across cloud, firmware/IoT, and corporate systems.
- Set technical and architectural direction and translate strategic priorities into execution plans.
- Drive remediation by partnering with engineering teams and providing actionable security guidance.
- Mentor engineers and serve as a technical authority on secure design and remediation practices.
- Communicate security risks and remediation tradeoffs to engineering leadership.
- Participate in investigations involving high-profile vulnerabilities and assess infrastructure impact.
- Participate in regular on-call support for critical vulnerability response.
Requirements
- 10+ years of relevant experience as a cloud engineer or security engineer, including hands-on vulnerability management across a broad enterprise environment.
- Proficiency in Go, Python, and JavaScript.
- Ability to independently set technical and architectural direction for security programs and drive remediation without direct authority.
- Significant experience with vulnerability management tooling such as Wiz and Semgrep.
- Deep familiarity with CVSS and EPSS vulnerability scoring frameworks.
- Strong AWS cloud services experience.
- Deep understanding of Static Application Security Testing, Dynamic Application Security Testing, and Software Composition Analysis.
- Hands-on use of AI/LLM tooling for security workflows and knowledge of AI’s impact on the threat landscape.
- Experience with C/C++ and firmware or embedded systems is preferred.
- Experience with security automation platforms such as Tines and serverless frameworks such as AWS Lambda is preferred.
- Experience integrating vulnerability management into CI/CD pipelines is preferred.
- Experience spanning SaaS, firmware, and corporate IT security programs is preferred.
- Experience managing vulnerabilities in a FedRAMP-certified environment is preferred.
- Experience building or integrating AI copilots or agents for security workflows is preferred.
- Must reside in a U.S. Central or Eastern time zone.
Benefits
- Annual base salary is $165,200—$265,500 USD, with eligibility for an initial RSU grant, ongoing refresh opportunities, and performance-based bonus or variable pay.
- Flexible, employee-led remote work model; this role is remote for eligible U.S. candidates outside the specified San Francisco Bay, New York City, and Washington, D.C. metro areas.
- Professional development stipend.
- Comprehensive health and parental leave plans.
- No relocation assistance is provided.
- Regular on-call participation is part of the role.
About Samsara
Samsara (NYSE: IOT) builds with the operators who keep the world moving. Working alongside the drivers, mechanics, dispatchers, and crews behind the world's most complex operations, Samsara turns what they know into technology that makes their work safer and more efficient. Tens of thousands of organizations rely on Samsara across transportation, construction, logistics, manufacturing, field services, government, and more. Built with operators, for operators.
