> Markdown version of [/jobs/ext/2964799-security-engineer](https://www.wearedevelopers.com/jobs/ext/2964799-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Samsara Inc. - **Location:** Seattle, WA, United States (Remote available) - **Experience:** Expert - **Salary:** $165,200.0 - $295,000.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Artificial Intelligence, Amazon Web Services, C++ (Programming Language), Software as a Service, Cloud Engineering, Cyber Security, Firmware, Python (Programming Language), Cloud Services, Software Vulnerability Management, Large Language Models, Software Security, Mttr, AWS Lambda, Serverless Computing, Static Application Security Testing, Vulnerability Analysis, Golang, Dynamic Application Security Testing - **Published:** September 17, 2026 - **Apply:** https://startup.jobs/staff-application-security-engineer-samsara-10085991 ## About the Role * 10+ years of relevant experience as a cloud engineer or security engineer, including hands-on vulnerability management across a broad, multi-product enterprise environment - not a single product or team's slice of it. * Proficiency in Go, Python, and JavaScript. * Demonstrated ability to independently set technical and architectural direction for a security program, and to drive remediation across a broad, multi-surface environment without direct authority over the teams doing the fixing. * Significant experience with modern vulnerability management tooling (e.g., Wiz, Semgrep) and deep familiarity with vulnerability scoring frameworks such as CVSS and EPSS. * Strong AWS cloud services background. * Deep understanding of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA). * Hands-on use of AI/LLM tooling in your own security workflow - triage, detection logic, remediation drafting - plus credibility speaking to how AI is changing the threat landscape and the tooling available to address it. An ideal candidate also has: * Experience with C/C++, relevant to firmware and embedded systems. * Background at a cloud-native, AI-forward company actively building agentic or AI-driven products. * Experience with security automation platforms (e.g., Tines) and serverless frameworks (e.g., AWS Lambda). * Experience integrating vulnerability management into modern CI/CD pipelines with a "shift-left" mentality. * Experience spanning SaaS, firmware, and corporate IT security programs - not just one product line. * Experience managing vulnerabilities within a FedRAMP-certified environment. * Experience building, extending, or wiring up AI copilots/agents for security workflows (e.g., automated triage, remediation drafting). ## Description Samsara sits at the center of hardware, software, AI, and the physical world, processing 25+ trillion data points annually across thousands of connected devices. The Samsara Application Security team protects this vast footprint end-to-end, spanning cloud services, internal systems, and firmware running on IoT hardware in the field., * You want to impact the industries that run our world: Your efforts will result in real-world impact-helping to keep the lights on, get food into grocery stores, reduce emissions, and most importantly, ensure workers return home safely. * You are the architect of your own career: If you put in the work, this role won't be your last at Samsara. We set up our employees for success and have built a culture that encourages rapid career development, and countless opportunities to experiment and master your craft in a hyper-growth environment. * You're energized by our opportunity: The vision we have to digitize large sectors of the global economy requires your full focus and best efforts to bring forth creative, ambitious ideas for our customers. * You want to be with the best: At Samsara, we win together, celebrate together and support each other. You will be surrounded by a high-caliber team that will encourage you to do your best. In this role, you will: * Lead the ongoing strategy, operation, and continuous improvement of Samsara's vulnerability management program, along with other core application security programs - not just execute against an existing process, but define what the process should be. * Own and drive down mean time to remediate (MTTR) across the vulnerability backlog, as SLAs tighten. * Build and champion automation and tooling that scale vulnerability detection and response across cloud, firmware/IoT, and corporate systems, rather than relying on manual, one-by-one review. * Set technical and architectural direction for the program, translating leadership's strategic priorities into a concrete execution plan for the team. * Drive remediation by building trust with engineering teams and providing clear, actionable guidance - partnering with technical program management on reporting rather than owning it directly. * Mentor and level up other engineers on secure design and remediation practices, and be a technical voice other teams look to when priorities are unclear. * Communicate risk and remediation tradeoffs to engineering leadership in terms they can act on, without owning the relationship end to end. * Participate in security incident investigations involving high-profile vulnerabilities, assessing potential impact on Samsara's infrastructure. * Be regularly on call to support critical vulnerability response. * Champion, role model, and embed Samsara's cultural principles (Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team) as we scale globally and across new offices ## Related Videos - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)