Staff Application Security Engineer
Job Description
Samsara is building security programs that scale across cloud, internal systems, and firmware/IoT. In this remote Staff Application Security Engineer role (US residents), you will set technical direction for vulnerability management and application security initiatives, driving faster remediation and clearer guidance for engineering teams.
What you’ll do
- Lead the ongoing strategy, operation, and continuous improvement of Samsara’s vulnerability management program and other core application security programs, defining what the process should be rather than only executing against it.
- Own progress toward lower mean time to remediate (MTTR) across the vulnerability backlog as SLAs tighten.
- Build and champion automation and tooling that scale vulnerability detection and response across cloud, firmware/IoT, and corporate systems, reducing reliance on manual one-by-one review.
- Set technical and architectural direction for the program, translating leadership priorities into a concrete execution plan for the team.
- Drive remediation by establishing trust with engineering teams and providing clear, actionable guidance, partnering with technical program management on reporting rather than owning reporting end to end.
- Mentor other engineers on secure design and remediation practices, and serve as a technical voice when priorities are unclear.
- Communicate risk and remediation tradeoffs to engineering leadership in terms they can act on.
- Participate in security incident investigations involving high-profile vulnerabilities and assess potential impact to Samsara’s infrastructure.
- Be regularly on call to support critical vulnerability response.
- Champion and embed Samsara cultural principles including Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, and Win as a Team as the organization scales globally.
What you bring
- 10+ years of relevant experience as a cloud engineer or security engineer, including hands-on vulnerability management across a broad, multi-product enterprise environment.
- Proficiency in Go, Python, and JavaScript.
- Proven ability to independently set technical and architectural direction for a security program and drive remediation across a multi-surface environment without direct authority over fixing teams.
- Significant experience with modern vulnerability management tooling such as Wiz and Semgrep, plus deep familiarity with CVSS and EPSS.
- Strong AWS cloud services background.
- Deep understanding of SAST, DAST, and SCA.
- Hands-on use of AI/LLM tooling in security workflows including triage, detection logic, and remediation drafting, with credibility speaking to how AI changes the threat landscape and available tooling to address it.
Tools and technologies you’ll work with
Go, Python, JavaScript, Wiz, Semgrep, CVSS, EPSS, AWS, SAST, DAST, SCA, AI/LLM tooling, AI copilots/agents, C/C++, Tines, AWS Lambda, CI/CD pipelines, FedRAMP
Benefits
- Flexible, employee-led remote model
- Professional development stipend
- Comprehensive health and parental leave plans
- Base salary, performance-based bonus/variable pay, and equity (for eligible roles)
- Above-market total compensation for eligible roles
Flexible working and eligibility
Samsara offers a flexible working model to align with team needs. Offices are available for in-person work, and remote work is supported where it aligns with operational requirements. For some roles, being near an office or within a specific geographic area may be important for collaboration and access to resources. Employment offers are contingent on the ability to secure and maintain legal right to work in the specified location, if applicable.
Accessibility and recruiting integrity
Samsara is committed to inclusive hiring and equal opportunity for qualified persons with disabilities. If you require reasonable accommodations during the recruiting process, email [email protected].
Samsara uses Tofu to validate application authenticity and protect against identity fraud. To avoid scams, Samsara does not charge fees at any stage of the hiring process. Official communication about your application will come only from emails ending in @samsara.com, @us-greenhouse-mail.io, or @mail3.guide.co.