Responsibilities
- Own security outcomes for two to four named production areas and serve as the primary security owner for at least one area.
- Define and improve quantitative security metrics such as MTTD, MTTR, exploitable findings, and compliance audit readiness.
- Design and implement IAM, least-privilege, service-to-service trust, KMS, runtime telemetry, alerting, secure OTA update, CI/CD, and artifact-provenance controls.
- Perform threat modeling and secure design reviews for fleet, regulated, physical-system, and partner-facing services, and drive mitigations through completion.
- Lead vulnerability triage, remediation planning, staged verification, and regression prevention for owned services.
- Build incident-response playbooks, run tabletop exercises, validate forensic logging and auditability, and participate in postmortems.
- Secure AI and agent-assisted development and operations through allowed-use patterns, guardrails, monitoring, and auditing.
- Integrate penetration-test and red-team findings into tracked engineering changes with measurable closure criteria.
- Collaborate with SRE, platform, autonomy/embedded, field-operations, and compliance teams, and participate in assigned on-call rotations.
Requirements
- 8+ years building and operating security controls for large-scale production systems across application and cloud infrastructure.
- Hands-on engineering ability with Python, Go, or similar, including automation, tooling, and integrations with AI tools and agentic security bots.
- Deep experience with cloud-native stacks, microservices, Kubernetes, containers, IAM, CI/CD, secrets management, logging, telemetry, and least-privilege service-to-service models.
- Prior ownership of vulnerability management, incident-response playbooks, and production verification processes.
- Experience threat-modeling and securing systems interfacing with physical systems, regulated workflows, or third-party partners, including embedded, teleoperation, field operations, or healthcare-adjacent data flows.
- Ability to define, track, and deliver quantitative security targets within six to twelve months.
- Technical ownership, prioritization, stakeholder influence, and ability to drive security changes into production.
- Preferred experience securing LLM or agentic tools, mitigating OWASP LLM risks, working across cloud infrastructure, web services, and embedded/autonomy, or building developer-friendly security platforms.
Benefits
- Hybrid role based in South San Francisco with frequent presence at the company headquarters.
- Occasional travel to distribution centers, field sites, and test sites is required.
- Participation in incident response and assigned on-call rotations is required.
Tech Stack
Categories
About Zipline
Zipline was founded to create the first logistics system that serves all humans equally. Our aim is to solve the world’s most urgent and complex access challenges. Leveraging expertise in robotics and autonomy, Zipline designs, manufactures and operates the world’s largest automated delivery system. Zipline serves tens of millions of people around the world and is making good on the promise of building an equitable and more resilient global supply chain. From powering Rwanda’s national blood delivery network and Ghana’s COVID-19 vaccine distribution, to providing on-demand home delivery for Walmart and enabling leading healthcare providers to bring care into the home in the United States, Zipline is transforming the way goods move. By transitioning to clean, electric, instant logistics, we can decarbonize delivery, decrease road congestion, and reduce fossil fuel consumption and air pollution, while providing equitable access for billions of people. The technology is complex but the idea is simple: a teleportation service that delivers what you need, when you need it. Zipline is inspiring people, governments, and businesses to imagine what is possible when goods can move as seamlessly as information. To join the team, check out our career page: https://flyzipline.com/careers/
