> Markdown version of [/jobs/ext/1907168-telecommute-staff-security-engineer](https://www.wearedevelopers.com/jobs/ext/1907168-telecommute-staff-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # TELECOMMUTE Staff Security Engineer - **Company:** Flock Safety - **Location:** Atlanta, GA, United States (Remote available) - **Salary:** $185,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing, Linux, Embedded Software, Firmware, Mobile Application Software, EndPointSecurity, Cloud Platform System, Software Security - **Published:** August 3, 2026 - **Apply:** https://www.dice.com/job-detail/441ec5c3-de33-4f7a-9960-44c86b312776 ## About the Role * Demonstrated experience leading or running a PSIRT, product security, or coordinated vulnerability disclosure function, ideally within connected hardware or IoT environments. * Deep operational experience acting as a CVE Numbering Authority (CNA) or implementing the FIRST PSIRT Services Framework across discovery, triage, remediation, and disclosure. * Hands-on technical background in product security across embedded or firmware security, Linux or Android device security, AWS cloud security, or mobile application security. * Expertise applying CVSS, CWE, EPSS, and SSVC frameworks to evaluate risk and assign accurate vulnerability severities. * Strong written communication skills with the capability to translate complex technical vulnerabilities into clear advisories for customers, engineers, and executives. ## Description As Flock rapidly expands its fleet of connected hardware devices and cloud platforms, establishing a dedicated, centralized product security response program is critical to protecting our public safety network. Managing vulnerabilities across hardware, firmware, and cloud systems requires a single point of accountability to coordinate disclosures and drive fixes to closure. You will stand up our Product Security Incident Response Team (PSIRT), serve as the technical owner of our Coordinated Vulnerability Disclosure (CVD) program, and safeguard the products our customers depend on. What You'll Own * Own the operational model and execution of Flock's Product Security Incident Response Team (PSIRT) across every externally reported and internally discovered product vulnerability. * Serve as the operational lead for our CVE Numbering Authority (CNA), managing vulnerability intake, triage SLAs, severity rubrics, and public CVE record publishing. * Drive cross-functional remediation efforts across Hardware, Firmware, Device SRE, Cloud SRE, Mobile, Legal, Communications, and Support to ensure timely patch delivery. * Author clear, accurate public security advisories, internal postmortems, and executive summaries tailored to technical, legal, and leadership audiences. * Establish metrics and operational reporting for PSIRT performance, tracking time-to-triage, time-to-fix, and time-to-disclose. What This Role is Not * This isn't a people management position, you are an individual contributor who drives execution and policy adherence through cross-functional influence. * This is not a corporate security or internal SOC role, your sole focus centers on product security, field devices, and embedded software platforms. * This isn't a passive triage desk, you will actively guide technical remediation strategies and defend severity decisions with engineering leaders and external security researchers. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/972-webassembly-the-next-frontier-of-cloud-computing) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 188: CfP time, the risks of NPM and IKEA algorithms](https://www.wearedevelopers.com/magazine/635-dev-digest-188-cfp-time-the-risks-of-npm-and-ikea-algorithms)