SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 165,200 - 295,000 / annual
Samsara (NYSE: IOT) is the pioneer of the Connected Operations Cloud, a platform enabling organizations to harness IoT data for actionable insights across physical operations including agriculture, construction, field services, transportation, and manufacturing. The company processes 25+ trillion data points annually across thousands of connected devices.
As a Staff Application Security Engineer, you will drive the overarching technical direction for Samsara's application security and vulnerability management programs. This is a high-visibility individual contributor role where you'll influence a broad surface area while retaining flexibility to dive deep into critical domain focus areas as security priorities evolve.
Key responsibilities include:
- Lead strategy, operation, and continuous improvement of Samsara's vulnerability management program and other core application security programs—defining processes rather than just executing existing ones
- Own and drive down mean time to remediate (MTTR) across the vulnerability backlog as SLAs tighten
- Build and champion automation and tooling that scale vulnerability detection and response across cloud, firmware/IoT, and corporate systems
- Set technical and architectural direction for the program, translating leadership's strategic priorities into concrete execution plans
- Drive remediation by building trust with engineering teams and providing clear, actionable guidance
- Mentor and level up other engineers on secure design and remediation practices
- Communicate risk and remediation tradeoffs to engineering leadership in actionable terms
- Participate in security incident investigations involving high-profile vulnerabilities
- Be regularly on call to support critical vulnerability response
- Champion and embed Samsara's cultural principles as the company scales globally
The role spans cloud services, internal systems, and firmware running on IoT hardware in the field, requiring expertise across a broad, multi-product enterprise environment.
REQUIREMENTS:
Minimum:
- 10+ years of relevant experience as a cloud engineer or security engineer, including hands-on vulnerability management across a broad, multi-product enterprise environment (not a single product or team's slice)
- Proficiency in Go, Python, and JavaScript
- Demonstrated ability to independently set technical and architectural direction for a security program and drive remediation across a broad, multi-surface environment without direct authority
- Significant experience with modern vulnerability management tooling (e.g., Wiz, Semgrep)
- Deep familiarity with vulnerability scoring frameworks such as CVSS and EPSS
- Strong AWS cloud services background
- Deep understanding of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA)
- Hands-on use of AI/LLM tooling in security workflow (triage, detection logic, remediation drafting) plus credibility speaking to how AI is changing the threat landscape
Ideal to have:
- Experience with C/C++, relevant to firmware and embedded systems
- Background at a cloud-native, AI-forward company actively building agentic or AI-driven products
- Experience with security automation platforms (e.g., Tines) and serverless frameworks (e.g., AWS Lambda)
- Experience integrating vulnerability management into modern CI/CD pipelines with "shift-left" mentality
- Experience spanning SaaS, firmware, and corporate IT security programs
- Experience managing vulnerabilities within a FedRAMP-certified environment
- Experience building, extending, or wiring up AI copilots/agents for security workflows