Obsidian Security is a technology company working at the intersection of artificial intelligence, cybersecurity, and hybrid-cloud environments. On a mission to
Staff Software Engineer
Location
United States
Posted
92 days ago
Salary
$176K - $196K / year
Seniority
Lead
No structured requirement data.
Job Description
Staff Software Engineer
Obsidian Security
Founded in 2017, Obsidian Security was created to close a critical gap: securing the SaaS applications where modern business happens—platforms like Microsoft 365, Salesforce, and hundreds more. Backed by top investors including Greylock, Norwest Venture Partners, and IVP, we’ve built a complete SaaS security platform to reduce risk, detect and respond to threats, and prevent breaches at the source. Our team includes leaders who helped define the categories of endpoint and identity security at CrowdStrike, Okta, Cylance, and Carbon Black. Now, we’re transforming how SaaS is secured—in the era of agentic AI. Today, Obsidian is trusted by global enterprises like Snowflake, T-Mobile, and Pure Storage. We protect more than 200 organizations across North America, Europe, the Middle East, Southeast Asia, Australia, and New Zealand—including many of the world’s largest Fortune 1000 and Global 2000 companies. With strong global momentum, a growing partner ecosystem including SentinelOne, Databricks, and Google Cloud, and a major fundraise on the horizon, we’re scaling quickly toward long-term growth and IPO readiness. Join us as we define the future of SaaS security! About Obsidian Security Obsidian helps companies figure out what’s happening in their SaaS applications - who’s accessing what, where data is going, and what looks suspicious. Role Description You’ll work across the full stack on the Threat product team: browser extension code that hooks into web applications, backend services processing millions of events, and data pipelines feeding our detection engine. One day you’re in TypeScript debugging why a content script isn’t capturing form submissions on some vendor’s weird SPA. The next you’re in Python fixing a Kafka consumer that’s falling behind. Sometimes you’re in Rust optimizing a hot path in the telemetry collector. Right now, a big focus is shadow AI - enterprises want to know when employees are pasting sensitive data into ChatGPT, Claude, or whatever new LLM chatbot showed up this week. You’ll build the systems that catch this. What you’ll do - Own features from “we need to detect X” through production, across extension, backend, and pipeline code - Write content scripts that interact with web pages and background scripts that coordinate everything - Build backend services: event ingestion, enrichment, alerting - Work with security researchers to turn threat intel into working detections - Help the team get better through code review and design discussions What we’re looking for - 8+ years building software, ideally touching a few different areas (not just one stack forever) - You actually understand how browsers work. DOM APIs, the event loop, how SPAs route, why CORS exists. Not just “I used React.” - You’ve built browser extensions before. You know the content script/background script split, message passing, manifest v3 limitations. - Strong TypeScript. Comfortable in Python. Willing to write Rust (or already do). - You’ve dealt with data at scale: event streaming, pipelines, high-throughput ingestion. - Backend basics: APIs, Postgres, Elasticsearch, Kafka or similar. - Can work without someone telling you what to do next. Bonus points - You’ve thought about AI security - prompt injection, data exfiltration, that kind of thing - Background in detection engineering, SIEM, or security ops - You’ve built or contributed to security tools Employee Benefits Our competitive benefits packages are designed to support our employees' well-being, both at work and at home. Our US based employees enjoy: - Competitive compensation with equity and 401k - Comprehensive healthcare with dental and vision coverage - Flexible paid time off and paid holiday time off - 12 weeks of new parent or family leave - Personal and professional development resources For more details on our US benefits, or for information on our international benefits, please see here. Pay Transparancy Please note that the base pay range is a guideline and for candidates who receive an offer, the base pay will vary based on factors such as work location, as well as the knowledge, skills and experience of the candidate. In addition to a competitive base salary, this position is eligible for equity awards and may be eligible for sales commission or incentive compensation based on the role or function within the company. At Obsidian, we are proud to be an equal-opportunity employer. We value diversity and hire for talent, passion, and compassion. In compliance with federal law, all persons hired will be required to submit satisfactory proof of identity and legal authorization. If you have a need that requires accommodation, please contact accommodations@obsidiansecurity.com Information collected and processed as part of any job applications you choose to submit is subject to Obsidian’s Applicant Privacy Policy. Base Salary Range $176,000—$196,000 USD
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cyber Security Red Team Researcher
Ford Motor CompanyFord Pro is a global business within Ford Motor Company committed to improving productivity for our commercial customers. Ford Pro delivers purpose-built commercial vehicles, products, and services for virtually every vocation, engineered for uptime and backed by a suite of technology.
We are the movers of the world and the makers of the future. We get up every day, roll up our sleeves and build a better world -- together. At Ford, we’re all a part of something bigger than ourselves. Are you ready to change the way the world moves? As Ford Motor Company continues to advance the revolution in mobility, electrification and AI, traditional security practices need to evolve, and the Ford Red Team is growing in lockstep. Ford RT is an organization of passionate, technical security experts who actively test applications and systems for weaknesses and advise on resolution. As a Red Team Researcher, you will be responsible for identifying and exploiting vulnerabilities in Ford's applications, cloud implementations, APIs, infrastructure, and in-vehicle systems to improve our overall security posture. Ford RT is nimble, and we win as ONE by collaborating throughout all phases of an engagement: from identification to initial access, to establishing persistence and consulting on remediation.
• Architect and lead the end-to-end vulnerability management lifecycle, ensuring alignment with global security frameworks such as NIST, ISO 27001/2, and CIS Top 20 • Lead high-level risk discussions with business and technical stakeholders to transform raw vulnerability data into prioritized, actionable remediation roadmaps • Serve as a trusted security advisor to infrastructure and application teams, fostering a culture of shared accountability for security debt and remediation • Design and maintain a comprehensive security metrics program using BI tools (e.g., Tableau) to communicate program effectiveness and residual risk to executive leadership • Drive the strategic selection, integration, and optimization of advanced security technologies to ensure a future-ready defense against emerging threats • Spearhead the use of Python, PowerShell, and API integrations (with tools like CrowdStrike) to automate repetitive workflows and improve the Mean Time to Remediate (MTTR) • Own the development and continuous improvement of cybersecurity policies and standards, ensuring they reflect current global threat intelligence and regulatory requirements • Perform complex, risk-based assessments of both on-premises and cloud-native services to ensure consistent security controls across a hybrid environment • Build and present compelling technical and business cases for security investments, securing buy-in for initiatives that mitigate critical enterprise vulnerabilities
Information System Security Manager – ISSM
TSCProviding engineering services through Systems Engineering, Mission Support, and RF Sensors & Defense Electronics
• Implement, maintain, review, and enforce security policies on classified information systems • Collaborate with Information Assurance professionals, Security professionals, System Administrators, and engineering community • Responsible for the cybersecurity posture of Unmanned Air Vehicles and Ground Control Systems • Design and implement technical security controls, identify and remediate vulnerabilities
Staff Cybersecurity Architect – Security Controls
Reinsurance Group of America, IncorporatedTrusted Partner. Proven Results.
• Design, develop, and implement the technical direction for enterprise security control architectures • Champion secure by default guardrails over gates • Define processes to enable control threat modeling and risk analyses • Ensure controls are operationalized and continuously validated • Author and maintain enterprise control standards and reference architectures • Partner with various teams to embed controls into SDLC and change management • Convert business risks into testable technical controls • Evaluate and standardize strategic platforms for control efficacy • Define and enforce scalable identity and access guardrails • Contribute to incident response planning and post incident reviews • Provide technical leadership and coaching on automation first practices • Continuously assess and improve control posture through reporting • Design, implement, and continuously improve telemetry architectures



