SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 165,200 - 295,000 / annual
Samsara (NYSE: IOT) is the pioneer of the Connected Operations Cloud, a platform enabling organizations to harness IoT data for actionable insights across physical operations including agriculture, construction, field services, transportation, and manufacturing. The company processes 25+ trillion data points annually across thousands of connected devices.
As a Staff Application Security Engineer, you will drive the overarching technical direction for Samsara's application security and vulnerability management programs. This is a high-visibility individual contributor role where you'll influence a broad surface area while retaining flexibility to dive deep into critical domain focus areas as security priorities evolve.
Key responsibilities include:
- Lead the strategy, operation, and continuous improvement of Samsara's vulnerability management program and other core application security programs—defining processes rather than just executing them
- Own and drive down mean time to remediate (MTTR) across the vulnerability backlog as SLAs tighten
- Build and champion automation and tooling that scale vulnerability detection and response across cloud, firmware/IoT, and corporate systems
- Set technical and architectural direction for the program, translating leadership's strategic priorities into concrete execution plans
- Drive remediation by building trust with engineering teams and providing clear, actionable guidance
- Mentor and level up other engineers on secure design and remediation practices
- Communicate risk and remediation tradeoffs to engineering leadership in actionable terms
- Participate in security incident investigations involving high-profile vulnerabilities
- Be regularly on call to support critical vulnerability response
- Champion and embed Samsara's cultural principles as the company scales globally
Requirements:
- 10+ years of relevant experience as a cloud engineer or security engineer, including hands-on vulnerability management across a broad, multi-product enterprise environment (not a single product or team's slice)
- Proficiency in Go, Python, and JavaScript
- Demonstrated ability to independently set technical and architectural direction for a security program and drive remediation across a broad, multi-surface environment without direct authority over the teams doing the fixing
- Significant experience with modern vulnerability management tooling (e.g., Wiz, Semgrep) and deep familiarity with vulnerability scoring frameworks such as CVSS and EPSS
- Strong AWS cloud services background
- Deep understanding of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA)
- Hands-on use of AI/LLM tooling in your own security workflow—triage, detection logic, remediation drafting—plus credibility speaking to how AI is changing the threat landscape and tooling available to address it
Ideal candidate also has:
- Experience with C/C++, relevant to firmware and embedded systems
- Background at a cloud-native, AI-forward company actively building agentic or AI-driven products
- Experience with security automation platforms (e.g., Tines) and serverless frameworks (e.g., AWS Lambda)
- Experience integrating vulnerability management into modern CI/CD pipelines with a "shift-left" mentality
- Experience spanning SaaS, firmware, and corporate IT security programs
- Experience managing vulnerabilities within a FedRAMP-certified environment
- Experience building, extending, or wiring up AI copilots/agents for security workflows (e.g., automated triage, remediation drafting)