- Job type
- Not listed
- Work mode
- Remote
- Level
- Staff
- Department
- Information Technology
- Experience
- 10+ years experience
- Posted
- Sep 15, 2026
About the role
About the role:
Samsara sits at the center of hardware, software, AI, and the physical world, processing 25+ trillion data points annually across thousands of connected devices. The Samsara Application Security team protects this vast footprint end-to-end, spanning cloud services, internal systems, and firmware running on IoT hardware in the field.
As a Staff Application Security Engineer, you’ll drive the overarching technical direction for our application security and vulnerability management programs. This is a high-visibility role where you'll influence a broad surface area while retaining the flexibility to dive deep into critical domain focus areas as security priorities evolve.
In this role, you will:
- Lead the ongoing strategy, operation, and continuous improvement of Samsara's vulnerability management program, along with other core application security programs — not just execute against an existing process, but define what the process should be.
- Own and drive down mean time to remediate (MTTR) across the vulnerability backlog, as SLAs tighten.
- Build and champion automation and tooling that scale vulnerability detection and response across cloud, firmware/IoT, and corporate systems, rather than relying on manual, one-by-one review.
- Set technical and architectural direction for the program, translating leadership's strategic priorities into a concrete execution plan for the team.
- Drive remediation by building trust with engineering teams and providing clear, actionable guidance — partnering with technical program management on reporting rather than owning it directly.
- Mentor and level up other engineers on secure design and remediation practices, and be a technical voice other teams look to when priorities are unclear.
- Communicate risk and remediation tradeoffs to engineering leadership in terms they can act on, without owning the relationship end to end.
- Participate in security incident investigations involving high-profile vulnerabilities, assessing potential impact on Samsara's infrastructure.
- Be regularly on call to support critical vulnerability response.
Minimum requirements for the role:
- 10+ years of relevant experience as a cloud engineer or security engineer, including hands-on vulnerability management across a broad, multi-product enterprise environment — not a single product or team's slice of it.
- Proficiency in Go, Python, and JavaScript.
- Demonstrated ability to independently set technical and architectural direction for a security program, and to drive remediation across a broad, multi-surface environment without direct authority over the teams doing the fixing.
- Significant experience with modern vulnerability management tooling (e.g., Wiz, Semgrep) and deep familiarity with vulnerability scoring frameworks such as CVSS and EPSS.
- Strong AWS cloud services background.
- Deep understanding of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
- Hands-on use of AI/LLM tooling in your own security workflow — triage, detection logic, remediation drafting — plus credibility speaking to how AI is changing the threat landscape and the tooling available to address it.
An ideal candidate also has:
- Experience with C/C++, relevant to firmware and embedded systems.
- Background at a cloud-native, AI-forward company actively building agentic or AI-driven products.
- Experience with security automation platforms (e.g., Tines) and serverless frameworks (e.g., AWS Lambda).
- Experience integrating vulnerability management into modern CI/CD pipelines with a "shift-left" mentality.
- Experience spanning SaaS, firmware, and corporate IT security programs — not just one product line.
- Experience managing vulnerabilities within a FedRAMP-certified environment.
- Experience building, extending, or wiring up AI copilots/agents for security workflows (e.g., automated triage, remediation drafting).