Staff Security Engineer
Job Description
Remote (USA) Staff Security Engineer role focused on building and running product security incident response, coordinated vulnerability disclosure, and CVE CNA operations.
Responsibilities
- Own the operational model and execution of Flock’s Product Security Incident Response Team (PSIRT) for externally reported and internally discovered product vulnerabilities.
- Serve as operational lead for CVE Numbering Authority (CNA), managing vulnerability intake, triage SLAs, severity rubrics, and public CVE record publishing.
- Coordinate cross-functional remediation across Hardware, Firmware, Device SRE, Cloud SRE, Mobile, Legal, Communications, and Support to support timely patch delivery.
- Author public security advisories, internal postmortems, and executive summaries for technical, legal, and leadership audiences.
- Define metrics and operational reporting for PSIRT performance, including time-to-triage, time-to-fix, and time-to-disclose.
Requirements
- Demonstrated experience leading or running a PSIRT, product security, or coordinated vulnerability disclosure program, ideally in connected hardware or IoT environments.
- Deep operational experience as a CVE Numbering Authority (CNA) or implementing the FIRST PSIRT Services Framework across discovery, triage, remediation, and disclosure.
- Hands-on technical background in product security across embedded or firmware security, Linux or Android device security, AWS cloud security, or mobile application security.
- Expertise applying CVSS, CWE, EPSS, and SSVC to evaluate risk and set accurate vulnerability severities.
- Strong written communication skills with the ability to translate complex vulnerabilities into clear guidance for customers, engineers, and executives.
Technologies
- FIRST PSIRT Services Framework
- CVE Numbering Authority (CNA)
- CVD (Coordinated Vulnerability Disclosure)
- CVSS
- CWE
- EPSS
- SSVC
- Linux
- Android
- AWS
- Mobile application security
Compensation
- USD 185,000 - 230,000 per year
Benefits
- Flock Stock Options
Role scope notes
- This is an individual contributor position, focused on execution and policy adherence through cross-functional influence, not people management.
- This is not a corporate security or internal SOC role; the focus is on product security for field devices and embedded software platforms.
- This is not passive triage; you will actively guide remediation strategies and defend severity decisions with engineering leaders and external security researchers.