Samsara Logo

Samsara

Staff Offensive Security Engineer

Posted 50 Minutes Ago
Be an Early Applicant
Easy Apply
Remote or Hybrid
Hiring Remotely in United States
165K-266K Annually
Expert/Leader
Easy Apply
Remote or Hybrid
Hiring Remotely in United States
165K-266K Annually
Expert/Leader
Leads Samsara’s application security and vulnerability management programs across cloud, firmware, IoT, and corporate systems. Responsibilities include setting technical strategy, reducing remediation time, developing automation, guiding engineering teams, mentoring security engineers, assessing high-profile vulnerabilities, supporting incident investigations, and participating in on-call response. The role requires extensive security experience, programming proficiency, AWS expertise, vulnerability management knowledge, and practical use of AI/LLM tooling.
The summary above was generated by AI

Who we are

Samsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, which is a platform that enables organizations that depend on physical operations to harness Internet of Things (IoT) data to develop actionable insights and improve their operations. At Samsara, we are helping improve the safety, efficiency and sustainability of the physical operations that power our global economy. Representing more than 40% of global GDP, these industries are the infrastructure of our planet, including agriculture, construction, field services, transportation, and manufacturing — and we are excited to help digitally transform their operations at scale.

Working at Samsara means you’ll help define the future of physical operations and be on a team that’s shaping an exciting array of product solutions, including Video-Based Safety, Vehicle Telematics, Apps and Driver Workflows, and Equipment Monitoring. As part of a recently public company, you’ll have the autonomy and support to make an impact as we build for the long term.

About the role:

Samsara sits at the center of hardware, software, AI, and the physical world, processing 25+ trillion data points annually across thousands of connected devices. The Samsara Application Security team protects this vast footprint end-to-end, spanning cloud services, internal systems, and firmware running on IoT hardware in the field.

As a Staff Application Security Engineer, you’ll drive the overarching technical direction for our application security and vulnerability management programs. This is a high-visibility role where you'll influence a broad surface area while retaining the flexibility to dive deep into critical domain focus areas as security priorities evolve.

This is a remote position, open to candidates residing in the US except the San Francisco Bay Metro Area, NYC Metro Area, and Washington, D.C. Metro Area., with working hours in the Central or Eastern time zone. Relocation assistance will not be provided for this role.

You should apply if: 
  • You want to impact the industries that run our world: Your efforts will result in real-world impact—helping to keep the lights on, get food into grocery stores, reduce emissions, and most importantly, ensure workers return home safely.
  • You are the architect of your own career: If you put in the work, this role won't be your last at Samsara. We set up our employees for success and have built a culture that encourages rapid career development, and countless opportunities to experiment and master your craft in a hyper-growth environment.
  • You're energized by our opportunity: The vision we have to digitize large sectors of the global economy requires your full focus and best efforts to bring forth creative, ambitious ideas for our customers.
  • You want to be with the best: At Samsara, we win together, celebrate together and support each other. You will be surrounded by a high-caliber team that will encourage you to do your best.
In this role, you will: 
  • Lead the ongoing strategy, operation, and continuous improvement of Samsara's vulnerability management program, along with other core application security programs — not just execute against an existing process, but define what the process should be.
  • Own and drive down mean time to remediate (MTTR) across the vulnerability backlog, as SLAs tighten.
  • Build and champion automation and tooling that scale vulnerability detection and response across cloud, firmware/IoT, and corporate systems, rather than relying on manual, one-by-one review.
  • Set technical and architectural direction for the program, translating leadership's strategic priorities into a concrete execution plan for the team.
  • Drive remediation by building trust with engineering teams and providing clear, actionable guidance — partnering with technical program management on reporting rather than owning it directly.
  • Mentor and level up other engineers on secure design and remediation practices, and be a technical voice other teams look to when priorities are unclear.
  • Communicate risk and remediation tradeoffs to engineering leadership in terms they can act on, without owning the relationship end to end.
  • Participate in security incident investigations involving high-profile vulnerabilities, assessing potential impact on Samsara's infrastructure.
  • Be regularly on call to support critical vulnerability response.
  • Champion, role model, and embed Samsara’s cultural principles (Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team) as we scale globally and across new offices

Minimum requirements for the role:

  • 10+ years of relevant experience as a cloud engineer or security engineer, including hands-on vulnerability management across a broad, multi-product enterprise environment  — not a single product or team's slice of it.
  • Proficiency in Go, Python, and JavaScript.
  • Demonstrated ability to independently set technical and architectural direction for a security program, and to drive remediation across a broad, multi-surface environment without direct authority over the teams doing the fixing.
  • Significant experience with modern vulnerability management tooling (e.g., Wiz, Semgrep) and deep familiarity with vulnerability scoring frameworks such as CVSS and EPSS.
  • Strong AWS cloud services background.
  • Deep understanding of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
  • Hands-on use of AI/LLM tooling in your own security workflow — triage, detection logic, remediation drafting — plus credibility speaking to how AI is changing the threat landscape and the tooling available to address it.
  • Location: must be based in central or eastern timezones.

An ideal candidate also has:

  • Experience with C/C++, relevant to firmware and embedded systems.
  • Background at a cloud-native, AI-forward company actively building agentic or AI-driven products.
  • Experience with security automation platforms (e.g., Tines) and serverless frameworks (e.g., AWS Lambda).
  • Experience integrating vulnerability management into modern CI/CD pipelines with a "shift-left" mentality.
  • Experience spanning SaaS, firmware, and corporate IT security programs — not just one product line.
  • Experience managing vulnerabilities within a FedRAMP-certified environment.
  • Experience building, extending, or wiring up AI copilots/agents for security workflows (e.g., automated triage, remediation drafting).

The range of annual base salary for full-time employees for this position is below. Please note that base pay offered may vary depending on factors including your city of residence, job-related knowledge, skills, and experience. This role is also eligible for an initial RSU grant with no vesting cliff, and ongoing refresh opportunities tied to performance, subject to plan terms and conditions. Learn more about our total rewards and benefits below.

Annual Base Salary
$165,200$265,500 USD

Total Rewards

At Samsara, we build for the people who keep the global economy moving. We want owners, not passengers, which is why our rewards are designed to fuel high-impact builders. Our compensation program delivers above-market total compensation through a combination of base salary, performance-based bonus/variable pay, and equity (for eligible roles) in a high-growth public company. We meaningfully differentiate pay for our top performers, who have the opportunity to earn above-market compensation that can outpace the broader market over time.

Beyond compensation, we provide the foundations that enable long-term success: a flexible, employee-led remote model, a professional development stipend, comprehensive health and parental leave plans, and more. If you’re ready to build for the long term and own the outcome, your journey starts here.

Flexible Working 

At Samsara, we embrace a flexible working model that caters to the diverse needs of our teams. Our offices are open for those who prefer to work in-person and we also support remote work where it aligns with our operational requirements. For certain positions, being close to one of our offices or within a specific geographic area is important to facilitate collaboration, access to resources, or alignment with our service regions. In these cases, the job description will clearly indicate any working location requirements. Our goal is to ensure that all members of our team can contribute effectively, whether they are working on-site, in a hybrid model, or fully remotely. All offers of employment are contingent upon an individual’s ability to secure and maintain the legal right to work at the company and in the specified work location, if applicable.

Belonging at Samsara

At Samsara, we welcome everyone regardless of their background. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, gender, gender identity, sexual orientation, protected veteran status, disability, age, and other characteristics protected by law. We depend on the unique approaches of our team members to help us solve complex problems and want to ensure that Samsara is a place where people from all backgrounds can make an impact.

Accommodations 

Samsara is an inclusive work environment, and we are committed to ensuring equal opportunity in employment for qualified persons with disabilities. Please email [email protected] or click here if you require any reasonable accommodations throughout the recruiting process.

Our Commitment to Authenticity

We use Tofu, a fraud detection tool, to validate the authenticity of applications and protect against identity fraud. This ensures we are connecting with real people and allows us to prioritize genuine candidates. Please see Samsara’s Candidate Privacy Notice for more information.

Fraudulent Employment Offers

Samsara is aware of scams involving fake job interviews and offers. Please know we do not charge fees to applicants at any stage of the hiring process. Official communication about your application will only come from emails ending in @samsara.com, @us-greenhouse-mail.io or @mail3.guide.co. For more information regarding fraudulent employment offers, please visit our blog post here.

Similar Jobs at Samsara

49 Minutes Ago
Easy Apply
Remote or Hybrid
USA
Easy Apply
111K-150K Annually
Expert/Leader
111K-150K Annually
Expert/Leader
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Owns high-impact Core IT programs from problem definition through implementation across systems and business domains. Advises senior leadership on organizational design, systems architecture, process strategy, and operational excellence. Establishes requirements frameworks, coordinates stakeholders and resources, manages complex programs, improves scalable business processes, analyzes IT performance and financial metrics, supports compliance programs, and mentors analysts and engineers.
Top Skills: Google SheetsIotExcelSplunk
50 Minutes Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
86K-145K Annually
Mid level
86K-145K Annually
Mid level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Manage full-cycle recruiting for Samsara’s go-to-market teams, including sourcing, pipeline development, candidate engagement, interviews, offers, and negotiations. Partner with hiring leaders as a talent advisor, use recruiting data to identify insights, manage stakeholders, promote inclusive hiring practices, maintain accurate ATS records, and champion company culture. The role requires strategic sourcing, high-volume recruiting, strong communication, and experience working in a fast-paced environment.
Top Skills: Greenhouse
2 Hours Ago
Easy Apply
Remote or Hybrid
Easy Apply
116K-196K Annually
Senior level
116K-196K Annually
Senior level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Own account-based marketing strategy and execution for strategic enterprise accounts. Partner with enterprise sales to plan account campaigns, map buying committees, develop personalized messaging, coordinate digital, content, demand generation, field marketing, and product marketing efforts, and measure pipeline and closed-won impact. Manage account-level budgets, reporting, attribution, and optimization while influencing cross-functional stakeholders in a remote US role.
Top Skills: Ai ToolsInternet Of Things (Iot)SaaS

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account