Staff Offensive Security Engineer

NextGenEnergyJobs

Northern (KY)

Hybrid

USD 165,000 - 266,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Samsara is seeking a Staff Application Security Engineer to own the vulnerability management program across cloud, firmware/IoT, and corporate systems. You will influence technical direction, drive MTTR improvements, and build scalable automation while collaborating with engineering and product teams.

The role is remote within the United States (excluding SF Bay Area, NYC, and DC metro areas) and requires strong expertise in SAST/DAST/SCA, CVSS/EPSS, and AI-enabled security workflows.

Qualifications

  • 10+ years in cloud/security engineering or vulnerability management across multi-product environments.
  • Ability to set technical direction for a security program without direct authority.
  • Experience with modern vulnerability tooling and CVSS/EPSS scoring.
  • Hands-on with SAST/DAST/SCA and AI-assisted security workflows.

Responsibilities

  • Lead the vulnerability management program and related security programs.
  • Drive MTTR reduction across vulnerability backlog and SLA adherence.
  • Build automation and tooling for scalable vulnerability detection and response.
  • Set architectural direction and translate priorities into execution plans.
  • Mentor engineers in secure design and remediation practices.
  • Communicate risk and remediation tradeoffs to leadership.

Skills

Cloud security
Vulnerability management
SAST/DAST/SCA
AI/LLM security
CI/CD security
C/C++ experience

Tools

Wiz
Semgrep
Tines
AWS Lambda

Job description

At Samsara, we embrace a flexible working model that caters to the diverse needs of our teams.

Key Responsibilities
  • Samsara sits at the center of hardware, software, AI, and the physical world, processing 25+ trillion data points annually across thousands of connected devices. The Samsara Application Security team protects this vast footprint end-to-end, spanning cloud services, internal systems, and firmware running on IoT hardware in the field.
  • As a Staff Application Security Engineer, you’ll drive the overarching technical direction for our application security and vulnerability management programs. This is a high-visibility role where you'll influence a broad surface area while retaining the flexibility to dive deep into critical domain focus areas as security priorities evolve.
  • This is a remote position, open to candidates residing in the US except the San Francisco Bay Metro Area, NYC Metro Area, and Washington, D.C. Metro Area., with working hours in the Central or Eastern time zone. Relocation assistance will not be provided for this role.
  • Lead the ongoing strategy, operation, and continuous improvement of Samsara's vulnerability management program, along with other core application security programs — not just execute against an existing process, but define what the process should be.
  • Own and drive down mean time to remediate (MTTR) across the vulnerability backlog, as SLAs tighten.
  • Build and champion automation and tooling that scale vulnerability detection and response across cloud, firmware/IoT, and corporate systems, rather than relying on manual, one-by-one review.
  • Set technical and architectural direction for the program, translating leadership's strategic priorities into a concrete execution plan for the team.
  • Drive remediation by building trust with engineering teams and providing clear, actionable guidance — partnering with technical program management on reporting rather than owning it directly.
  • Mentor and level up other engineers on secure design and remediation practices, and be a technical voice other teams look to when priorities are unclear.
  • Communicate risk and remediation tradeoffs to engineering leadership in terms they can act on, without owning the relationship end to end.
  • Participate in security incident investigations involving high-profile vulnerabilities, assessing potential impact on Samsara's infrastructure.
  • Be regularly on call to support critical vulnerability response.
  • Champion, role model, and embed Samsara’s cultural principles (Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team) as we scale globally and across new offices
Requirements
  • 10+ years of relevant experience as a cloud engineer or security engineer, including hands-on vulnerability management across a broad, multi-product enterprise environment — not a single product or team's slice of it.
  • Demonstrated ability to independently set technical and architectural direction for a security program, and to drive remediation across a broad, multi-surface environment without direct authority over the teams doing the fixing.
  • Significant experience with modern vulnerability management tooling (e.g., Wiz, Semgrep) and deep familiarity with vulnerability scoring frameworks such as CVSS and EPSS.
  • Deep understanding of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
  • Hands-on use of AI/LLM tooling in your own security workflow — triage, detection logic, remediation drafting — plus credibility speaking to how AI is changing the threat landscape and the tooling available to address it.
  • Location: must be based in central or eastern timezones.
  • Experience with C/C++, relevant to firmware and embedded systems.
  • Background at a cloud-native, AI-forward company actively building agentic or AI-driven products.
  • Experience with security automation platforms (e.g., Tines) and serverless frameworks (e.g., AWS Lambda).
  • Experience integrating vulnerability management into modern CI/CD pipelines with a "shift-left" mentality.
  • Experience spanning SaaS, firmware, and corporate IT security programs — not just one product line.
  • Experience managing vulnerabilities within a FedRAMP-certified environment.
  • Experience building, extending, or wiring up AI copilots/agents for security workflows (e.g., automated triage, remediation drafting).
  • The range of annual base salary for full-time employees for this position is below. Please note that base pay offered may vary depending on factors including your city of residence, job-related knowledge, skills, and experience. This role is also eligible for an initial RSU grant with no vesting cliff, and ongoing refresh opportunities tied to performance, subject to plan terms and conditions. Learn more about our total rewards and benefits below.
  • $165,200
  • $265,500 USD
  • At Samsara, we build for the people who keep the global economy moving. We want owners, not passengers, which is why our rewards are designed to fuel high-impact builders. Our compensation program delivers above-market total compensation through a combination of base salary, performance-based bonus/variable pay, and equity (for eligible roles) in a high-growth public company. We meaningfully differentiate pay for our top performers, who have the opportunity to earn above-market compensation that can outpace the broader market over time.
  • Beyond compensation, we provide the foundations that enable long-term success: a flexible, employee-led remote model, a professional development stipend, comprehensive health and parental leave plans, and more. If you’re ready to build for the long term and own the outcome, your journey starts here.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Offensive Security Engineer
Staff Offensive Security Engineer

Socket.dev • Northern (KY)

Hybrid
USD 165,000 - 266,000
Remote-friendly work model
Total rewards and benefits
Professional development stipend
Staff Offensive Security Engineer
Staff Offensive Security Engineer

Samsara • Northern (KY)

Hybrid
USD 165,000 - 265,000
Senior Security Operations Engineer I
Senior Security Operations Engineer I

Samsara • United States

Hybrid
USD 135,000 - 183,000
Flexible working model
Professional development stipend
Comprehensive health benefits
Sr. Security Engineer - Enterprise Security
Sr. Security Engineer - Enterprise Security

Samsara • Austin (CO)

On-site
USD 135,000 - 205,000
Flexible working model
Professional development stipend
Comprehensive health benefits
Sr. Security Engineer I - Enterprise Security
Sr. Security Engineer I - Enterprise Security

Samsara • San Francisco (CA)

Remote
USD 135,000 - 205,000
Flexible working model
Professional development stipend
Comprehensive health plans
Staff Software Engineer
Staff Software Engineer

NextGenEnergyJobs • Northern (KY)

On-site
USD 162,000 - 290,000
Equity (RSU)
Remote-friendly
Health benefits
+2
Sr. Software Engineer II - IAM
Sr. Software Engineer II - IAM

Samsara • San Francisco (CA), Northern (KY)

On-site
USD 155,000 - 260,000
Senior Software Engineer
Senior Software Engineer

NextGenEnergyJobs • Northern (KY)

On-site
USD 143,000 - 185,000
Samsara: Staff Software Engineer
Samsara: Staff Software Engineer

Mosaec • Northern (KY)

Hybrid
USD 162,000 - 290,000
Remote work
Professional development stipend
Health plan and parental leave
Staff Software Engineer
Staff Software Engineer

Samsara • San Francisco (CA)

Remote
USD 162,400 - 290,000
Health benefits
Flexible working hours
Competitive compensation package