More jobs:
Staff Application Security Engineer
Job in
Washington, District of Columbia, 20022, USA
Listed on 2026-09-28
Listing for:
NextGenEnergyJobs
Full Time
position Listed on 2026-09-28
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
At Samsara, we embrace a flexible working model that caters to the diverse needs of our teams.
Key Responsibilities- Samsara sits at the center of hardware, software, AI, and the physical world, processing 25+ trillion data points annually across thousands of connected devices. The Samsara Application Security team protects this vast footprint end-to-end, spanning cloud services, internal systems, and firmware running on IoT hardware in the field.
- As a Staff Application Security Engineer, you’ll drive the overarching technical direction for our application security and vulnerability management programs. This is a high-visibility role where you'll influence a broad surface area while retaining the flexibility to dive deep into critical domain focus areas as security priorities evolve.
- Lead the ongoing strategy, operation, and continuous improvement of Samsara's vulnerability management program, along with other core application security programs — not just execute against an existing process, but define what the process should be.
- Own and drive down mean time to remediate (MTTR) across the vulnerability backlog, as SLAs tighten.
- Build and champion automation and tooling that scale vulnerability detection and response across cloud, firmware/IoT, and corporate systems, rather than relying on manual, one-by-one review.
- Set technical and architectural direction for the program, translating leadership's strategic priorities into a concrete execution plan for the team.
- Drive remediation by building trust with engineering teams and providing clear, actionable guidance — partnering with technical program management on reporting rather than owning it directly.
- Mentor and level up other engineers on secure design and remediation practices, and be a technical voice other teams look to when priorities are unclear.
- Communicate risk and remediation tradeoffs to engineering leadership in terms they can act on, without owning the relationship end to end.
- Participate in security incident investigations involving high-profile vulnerabilities, assessing potential impact on Samsara's infrastructure.
- Be regularly on call to support critical vulnerability response.
- Champion, role model, and embed Samsara’s cultural principles (Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team) as we scale globally and across new offices
- 10+ years of relevant experience as a cloud engineer or security engineer, including hands‑on vulnerability management across a broad, multi‑product enterprise environment — not a single product or team's slice of it.
- Demonstrated ability to independently set technical and architectural direction for a security program, and to drive remediation across a broad, multi‑surface environment without direct authority over the teams doing the fixing.
- Significant experience with modern vulnerability management tooling (e.g., Wiz, Semgrep) and deep familiarity with vulnerability scoring frameworks such as CVSS and EPSS.
- Deep understanding of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
- Hands‑on use of AI/LLM tooling in your own security workflow — triage, detection logic, remediation drafting — plus credibility speaking to how AI is changing the threat landscape and the tooling available to address it.
- Experience with C/C++, relevant to firmware and embedded systems.
- Background at a cloud‑native, AI‑forward company actively building agentic or AI‑driven products.
- Experience with security automation platforms (e.g., Tines) and serverless frameworks (e.g., AWS Lambda).
- Experience integrating vulnerability management into modern CI/CD pipelines with a "shift‑left"…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×