Remote job
Staff Security Engineer
Job details
About this role
Role overview
A hands-on Staff Security Engineer role on the Security Platform & Systems team, responsible for architecting and shipping the foundational security infrastructure that protects the organization and its customers. The role blends deep security engineering with strong software craftsmanship, focusing on building durable platforms rather than running point solutions, and acting as a force multiplier across the engineering organization.
Responsibilities
- Architect, build, and operate core security systems and platforms, including detection and response pipelines, authorization and identity infrastructure, secrets management, key management, and policy-as-code frameworks. - Design secure-by-default paved paths so the easiest way for engineers to build something is also the safest way. - Lead technical design for large, ambiguous, cross-team security initiatives, producing clear design docs and driving alignment across engineering. - Build automation and tooling that scales security coverage without scaling headcount, including automated vulnerability triage, CI/CD guardrails, drift detection, and self-service remediation. - Improve observability of security-relevant events across the stack so detections are high-signal and actionable. - Embed security controls directly into product and infrastructure systems rather than bolting them on afterward. - Set and raise engineering standards across the security organization, including code quality, reliability, testing, and on-call practices. - Mentor and grow engineers, and lead incident response and remediation, then build the systems that prevent the next incident.
Requirements
- Typically 8+ years building and operating production software systems, with substantial focus on security engineering or security-critical infrastructure. - Strong software engineering fundamentals, with the ability to own services end to end in a language such as Go, Rust, Python, or Java. - Proven track record of designing and shipping security systems or platforms that other engineers depend on, such as authn/authz, detection platforms, secrets or key management, or security tooling. - Solid grounding in security fundamentals, including threat modeling, cryptography basics, identity and access management, network security, and the systematic elimination of common vulnerability classes. - Experience operating in modern cloud environments such as AWS, GCP, or Azure, including containers, Kubernetes, and infrastructure-as-code. - Ability to lead ambiguous, cross-team technical projects and influence without authority, paired with strong written and verbal communication.
Nice to have
- Background in detection engineering, SIEM or large-scale log pipelines. - Familiarity with policy-as-code tooling such as OPA, supply-chain security, or SLSA-style build integrity practices. - Contributions to open-source security tooling, or published research, talks, or writing on security engineering. - Prior experience as a technical lead or Staff+ engineer in a security or platform organization.
Benefits and work setup
- Annual compensation for the role is posted at $245,000. - Remote-friendly environment with a startup-style pace and ownership model. - Opportunity to work at the intersection of frontier AI research and real-world enterprise deployment.