Skip to main content

Staff / Principal

Samsara
Remote - USUpdated 2d ago
Base salary
$165k–$295k
Published base salary range
Location
Remote - US
Remote eligibility
Employment
Full-time
Staff / Principal
Role family
Security
B2B SaaS
Apply on samsara.com
Job actionsApply now
Job actionsApply now

About the job

About Samsara

Samsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, a platform that enables organizations that depend on physical operations to harness IoT data for actionable insights. The company serves industries representing more than 40% of global GDP, including agriculture, construction, field services, transportation, and manufacturing.

About the Role

As a Staff Application Security Engineer, you will drive the overarching technical direction for Samsara's application security and vulnerability management programs. This is a high-visibility role where you'll influence a broad surface area while retaining flexibility to dive deep into critical domain focus areas as security priorities evolve. This is a remote position open to candidates residing in the US.

Responsibilities

  • Lead the ongoing strategy, operation, and continuous improvement of Samsara's vulnerability management program and other core application security programs.
  • Own and drive down mean time to remediate (MTTR) across the vulnerability backlog as SLAs tighten.
  • Build and champion automation and tooling that scale vulnerability detection and response across cloud, firmware/IoT, and corporate systems.
  • Set technical and architectural direction for the program, translating leadership's strategic priorities into a concrete execution plan.
  • Drive remediation by building trust with engineering teams and providing clear, actionable guidance.
  • Mentor and level up other engineers on secure design and remediation practices.
  • Communicate risk and remediation tradeoffs to engineering leadership.
  • Participate in security incident investigations involving high-profile vulnerabilities.
  • Be regularly on call to support critical vulnerability response.

Minimum Requirements

  • 10+ years of relevant experience as a cloud engineer or security engineer, including hands-on vulnerability management across a broad, multi-product enterprise environment.
  • Proficiency in Go, Python, and JavaScript.
  • Demonstrated ability to independently set technical and architectural direction for a security program.
  • Significant experience with modern vulnerability management tooling (e.g., Wiz, Semgrep) and deep familiarity with vulnerability scoring frameworks such as CVSS and EPSS.
  • Strong AWS cloud services background.
  • Deep understanding of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
  • Hands-on use of AI/LLM tooling in your own security workflow.

Ideal Candidate

  • Experience with C/C++, relevant to firmware and embedded systems.
  • Background at a cloud-native, AI-forward company actively building agentic or AI-driven products.
  • Experience with security automation platforms (e.g., Tines) and serverless frameworks (e.g., AWS Lambda).
  • Experience integrating vulnerability management into modern CI/CD pipelines with a 'shift-left' mentality.
  • Experience spanning SaaS, firmware, and corporate IT security programs.
  • Experience managing vulnerabilities within a FedRAMP-certified environment.
  • Experience building, extending, or wiring up AI copilots/agents for security workflows.

Compensation & Benefits

Annual base salary range: $165,200—$295,000 USD. This role is also eligible for an initial RSU grant with no vesting cliff, and ongoing refresh opportunities tied to performance. Samsara offers a flexible, employee-led remote model, a professional development stipend, comprehensive health and parental leave plans, and more.

Application Instructions

Apply through the provided link. Samsara uses Tofu, a fraud detection tool, to validate the authenticity of applications. Official communication about your application will only come from emails ending in @samsara.com, @us-greenhouse-mail.io, or @mail3.guide.co.

Skills & tags

What you can verify before applying

Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.