Staff / Principal
Samsara- Base salary
- $165k–$295k Published base salary range
- Location
- Remote - US Remote eligibility
- Employment
- Full-time Staff / Principal
About the job
About Samsara
Samsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, a platform that enables organizations that depend on physical operations to harness IoT data for actionable insights. The company serves industries representing more than 40% of global GDP, including agriculture, construction, field services, transportation, and manufacturing.
About the Role
As a Staff Application Security Engineer, you will drive the overarching technical direction for Samsara's application security and vulnerability management programs. This is a high-visibility role where you'll influence a broad surface area while retaining flexibility to dive deep into critical domain focus areas as security priorities evolve. This is a remote position open to candidates residing in the US.
Responsibilities
- Lead the ongoing strategy, operation, and continuous improvement of Samsara's vulnerability management program and other core application security programs.
- Own and drive down mean time to remediate (MTTR) across the vulnerability backlog as SLAs tighten.
- Build and champion automation and tooling that scale vulnerability detection and response across cloud, firmware/IoT, and corporate systems.
- Set technical and architectural direction for the program, translating leadership's strategic priorities into a concrete execution plan.
- Drive remediation by building trust with engineering teams and providing clear, actionable guidance.
- Mentor and level up other engineers on secure design and remediation practices.
- Communicate risk and remediation tradeoffs to engineering leadership.
- Participate in security incident investigations involving high-profile vulnerabilities.
- Be regularly on call to support critical vulnerability response.
Minimum Requirements
- 10+ years of relevant experience as a cloud engineer or security engineer, including hands-on vulnerability management across a broad, multi-product enterprise environment.
- Proficiency in Go, Python, and JavaScript.
- Demonstrated ability to independently set technical and architectural direction for a security program.
- Significant experience with modern vulnerability management tooling (e.g., Wiz, Semgrep) and deep familiarity with vulnerability scoring frameworks such as CVSS and EPSS.
- Strong AWS cloud services background.
- Deep understanding of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
- Hands-on use of AI/LLM tooling in your own security workflow.
Ideal Candidate
- Experience with C/C++, relevant to firmware and embedded systems.
- Background at a cloud-native, AI-forward company actively building agentic or AI-driven products.
- Experience with security automation platforms (e.g., Tines) and serverless frameworks (e.g., AWS Lambda).
- Experience integrating vulnerability management into modern CI/CD pipelines with a 'shift-left' mentality.
- Experience spanning SaaS, firmware, and corporate IT security programs.
- Experience managing vulnerabilities within a FedRAMP-certified environment.
- Experience building, extending, or wiring up AI copilots/agents for security workflows.
Compensation & Benefits
Annual base salary range: $165,200—$295,000 USD. This role is also eligible for an initial RSU grant with no vesting cliff, and ongoing refresh opportunities tied to performance. Samsara offers a flexible, employee-led remote model, a professional development stipend, comprehensive health and parental leave plans, and more.
Application Instructions
Apply through the provided link. Samsara uses Tofu, a fraud detection tool, to validate the authenticity of applications. Official communication about your application will only come from emails ending in @samsara.com, @us-greenhouse-mail.io, or @mail3.guide.co.
Skills & tags
Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.