CybersecurityJobs.io
← Back to all jobs

Job Description

Samsara is hiring a Staff Application Security Engineer to help shape and scale application security and vulnerability management programs across multiple surfaces. This remote role supports candidates residing in the US and centers on improving security outcomes through stronger strategy, automation, and architectural direction. You will also have opportunities to mentor engineers and contribute to incident investigations involving high-profile vulnerabilities, while embodying Samsara’s cultural principles as the company scales globally.

Location: Washington, DC (remote)

Compensation: USD 165,200 - 295,000 per yearly

Experience: 10+ years

What you’ll be responsible for

  • Lead the ongoing strategy, operations, and continuous improvement of Samsara’s vulnerability management program and other core application security programs, including defining what the process should be, not only executing against it.
  • Own and drive down mean time to remediate (MTTR) across the vulnerability backlog as SLAs tighten.
  • Build and champion automation and tooling to scale vulnerability detection and response across cloud, firmware/IoT, and corporate systems, reducing reliance on manual review.
  • Set technical and architectural direction for the program by translating leadership priorities into an actionable execution plan for the team.
  • Drive remediation by building trust with engineering teams and providing clear, actionable guidance, partnering with technical program management on reporting rather than owning it end to end.
  • Mentor engineers on secure design and remediation practices, serving as a technical voice when priorities are unclear.
  • Communicate risk and remediation tradeoffs to engineering leadership in a way teams can act on.
  • Participate in security incident investigations involving high-profile vulnerabilities, assessing potential impact to Samsara’s infrastructure.
  • Be regularly on call to support critical vulnerability response.
  • Champion and embed Samsara’s cultural principles: Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team.

What we’re looking for

  • 10+ years of relevant experience as a cloud engineer or security engineer, including hands-on vulnerability management across a broad, multi-product enterprise environment.
  • Proficiency in Go, Python, and JavaScript.
  • Ability to independently set technical and architectural direction for a security program and drive remediation across a multi-surface environment without direct authority over fixing teams.
  • Significant experience with modern vulnerability management tooling such as Wiz and Semgrep, plus deep familiarity with CVSS and EPSS.
  • Strong AWS cloud services background.
  • Deep understanding of SAST, DAST, and SCA.
  • Hands-on use of AI/LLM tooling in your own security workflow (triage, detection logic, remediation drafting), along with credibility discussing how AI is changing the threat landscape and available tooling to address it.

Technologies you’ll work with

  • Go, Python, JavaScript
  • Wiz, Semgrep
  • CVSS, EPSS
  • AWS
  • Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA)
  • AI/LLM, C/C++
  • Tines, AWS Lambda
  • CI/CD
  • FedRAMP
  • AI copilots/agents

Benefits

  • Compensation program delivering above-market total compensation through base salary, performance-based bonus/variable pay, and equity (for eligible roles) in a high-growth public company.
  • Flexible, employee-led remote model.
  • Professional development stipend.
  • Comprehensive health and parental leave plans.

Additional notes

  • Flexible working: offices are open for those who prefer in-person work, and remote work is supported where it aligns with operational requirements.
  • Offers are contingent upon the ability to secure and maintain the legal right to work at the company and in the specified work location, if applicable.
  • Equal opportunity: Samsara provides consideration for employment without regard to protected characteristics.
  • Accommodations: for reasonable accommodations during recruiting, email [email protected].

Security and application integrity

  • Samsara uses Tofu to validate the authenticity of applications and protect against identity fraud.
  • Samsara does not charge applicants any fees during the hiring process.
  • Official communication will come from emails ending in @samsara.com, @us-greenhouse-mail.io, or @mail3.guide.co.

Similar Jobs