SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Security Engineer

Flock Safety - Remote - Remote - posted 2026-07-30

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 185,000 - 230,000 / annual

Flock Safety is seeking a Staff Security Engineer to establish and operate the company's Product Security Incident Response Team (PSIRT). This is a high-impact individual contributor role focused on protecting Flock's connected hardware devices and cloud platforms used by law enforcement and public safety agencies. You will own the operational model and execution of PSIRT across all externally reported and internally discovered product vulnerabilities. Key responsibilities include serving as the operational lead for Flock's CVE Numbering Authority (CNA), managing vulnerability intake, triage SLAs, severity rubrics, and CVE record publishing. You'll drive cross-functional remediation efforts across Hardware, Firmware, Device SRE, Cloud SRE, Mobile, Legal, Communications, and Support to ensure timely patch delivery. You will author clear, accurate public security advisories, internal postmortems, and executive summaries tailored to technical, legal, and leadership audiences. You'll establish metrics and operational reporting for PSIRT performance, tracking time-to-triage, time-to-fix, and time-to-disclose. This is not a people management position—you drive execution and policy adherence through cross-functional influence. This is not a corporate security or internal SOC role; your sole focus centers on product security, field devices, and embedded software platforms. You will actively guide technical remediation strategies and defend severity decisions with engineering leaders and external security researchers. Required experience includes demonstrated leadership or operation of a PSIRT, product security, or coordinated vulnerability disclosure function, ideally within connected hardware or IoT environments. You need deep operational experience as a CVE Numbering Authority or implementing the FIRST PSIRT Services Framework. Hands-on technical background in product security across embedded/firmware security, Linux/Android device security, AWS cloud security, or mobile application security is essential. You must have expertise applying CVSS, CWE, EPSS, and SSVC frameworks to evaluate risk and assign accurate vulnerability severities. Strong written communication skills are critical to translate complex technical vulnerabilities into clear advisories.

Similar roles