Job Closed
This listing is no longer active.
Samsara Inc. is on a mission to increase the sustainability of the operations that power the global economy. The company pioneers the Connected Operations Cloud, which allows busin
Senior Security Engineer - Threat Modeling
Location
United States
Posted
56 days ago
Salary
$157.7K - $265K / year
Seniority
Senior
Job Description
Senior Security Engineer - Threat Modeling
Samsara
Who we are Samsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, which is a platform that enables organizations that depend on physical operations to harness Internet of Things (IoT) data to develop actionable insights and improve their operations. At Samsara, we are helping improve the safety, efficiency and sustainability of the physical operations that power our global economy. Representing more than 40% of global GDP, these industries are the infrastructure of our planet, including agriculture, construction, field services, transportation, and manufacturing — and we are excited to help digitally transform their operations at scale. Working at Samsara means you’ll help define the future of physical operations and be on a team that’s shaping an exciting array of product solutions, including Video-Based Safety, Vehicle Telematics, Apps and Driver Workflows, and Equipment Monitoring. As part of a recently public company, you’ll have the autonomy and support to make an impact as we build for the long term. About the role: We’re seeking a talented Senior Security Engineer with hands-on experience deploying, managing, leading and performing Threat Models In this role, you’ll work alongside technical product managers and engineers across the company to maintain Samsara’s security and de-risk software security concerns to better protect our customers. We seek someone who is passionate about leveraging automation to enhance efficiency, is enthusiastic about working with infrastructure-as-code, and has a wealth of experience collaborating with teams to reduce software vulnerabilities. Your contributions will be critical to shaping our overall security and compliance strategy. At Samsara, we value working backwards from winning as an operating principle. Your ability to define success and work with cross-functional stakeholders by working backwards to reach that success is pivotal. This is a remote position open to candidates residing in the US except the San Francisco Bay Metro Area, NYC Metro Area, and Washington, D.C. Metro Area. You will be regularly working with UK and India team employees who are also on your team via Zoom during United States standard working hours. You should apply if: - You want to impact the industries that run our world: Your efforts will result in real-world impact—helping to keep the lights on, get food into grocery stores, reduce emissions, and most importantly, ensure workers return home safely. - You are the architect of your own career: If you put in the work, this role won’t be your last at Samsara. We set up our employees for success and have built a culture that encourages rapid career development, and countless opportunities to experiment and master your craft in a hyper-growth environment. - You’re energized by our opportunity: The vision we have to digitize large sectors of the global economy requires your full focus and best efforts to bring forth creative, ambitious ideas for our customers. - You want to be with the best: At Samsara, we win together, celebrate together and support each other. You will be surrounded by a high-caliber team that will encourage you to do your best. In this role, you will: - Lead and own ongoing operation and maintenance of Samsara’s threat modeling program, ensuring consistent execution of processes. - Assist in detecting, raising risks found within the Samsara ecosystem, and recommending best next steps while balancing business needs. - Work closely with the Vulnerability Technical Program Manager to generate and distribute monthly and quarterly compliance reports. - Collaborate with engineering teams to track and support the remediation of identified vulnerabilities, providing guidance on best practices. - Participate in security incident investigations related to high-profile vulnerabilities, helping gather data and assess potential impact on Samsara infrastructure. - Contribute to documentation and process improvements to streamline risk management workflows. - Champion Samsara’s cultural principles (Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team) in daily work. - Be regularly on call to support. Minimum requirements for the role: - 6+ years of relevant experience with demonstrated impact for application or product security and threat modeling in an enterprise environment. - Deep familiarity with OWASP Top Ten, the STRIDE threat modeling framework (or equal such as PASTA or DREAD), MITRE ATT&CK. - Defining and driving SDLC adoption with business focused engineers. - Experience managing Bug Bounty programs such as Bug Crowd. - Strong familiarity with common security vulnerabilities and the ability to judge their severity and impact on the business. - Experience coding with Python or GoLang. An ideal candidate also has: - Security certifications such as CISSP, AWS Certified Security Specialty, or equal. - Experience and knowledge of FedRAMP and other regulatory security requirements. - Experience with Semgrep or Wiz. The range of annual base salary for full-time employees for this position is below. Please note that base pay offered may vary depending on factors including your city of residence, job-related knowledge, skills, and experience. Learn more about our total rewards and benefits below. Annual Base Salary $157,675—$265,000 USD Total Rewards At Samsara, we build for the people who keep the global economy moving. We want owners, not passengers, which is why our rewards are designed to fuel high-impact builders. Our compensation program delivers above-market total compensation through a combination of base salary, performance-based bonus/variable pay, and equity (for eligible roles) in a high-growth public company. We meaningfully differentiate pay for our top performers, who have the opportunity to earn above-market compensation that can outpace the broader market over time. Beyond compensation, we provide the foundations that enable long-term success: a flexible, employee-led remote model, a professional development stipend, comprehensive health and parental leave plans, and more. If you’re ready to build for the long term and own the outcome, your journey starts here. Flexible Working At Samsara, we embrace a flexible working model that caters to the diverse needs of our teams. Our offices are open for those who prefer to work in-person and we also support remote work where it aligns with our operational requirements. For certain positions, being close to one of our offices or within a specific geographic area is important to facilitate collaboration, access to resources, or alignment with our service regions. In these cases, the job description will clearly indicate any working location requirements. Our goal is to ensure that all members of our team can contribute effectively, whether they are working on-site, in a hybrid model, or fully remotely. All offers of employment are contingent upon an individual’s ability to secure and maintain the legal right to work at the company and in the specified work location, if applicable. Belonging at Samsara At Samsara, we welcome everyone regardless of their background. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, gender, gender identity, sexual orientation, protected veteran status, disability, age, and other characteristics protected by law. We depend on the unique approaches of our team members to help us solve complex problems and want to ensure that Samsara is a place where people from all backgrounds can make an impact. Accommodations Samsara is an inclusive work environment, and we are committed to ensuring equal opportunity in employment for qualified persons with disabilities. Please email accessibleinterviewing@samsara.com or click here if you require any reasonable accommodations throughout the recruiting process. Our Commitment to Authenticity We use Tofu, a fraud detection tool, to validate the authenticity of applications and protect against identity fraud. This ensures we are connecting with real people and allows us to prioritize genuine candidates. Please see Samsara’s Candidate Privacy Notice for more information. Fraudulent Employment Offers Samsara is aware of scams involving fake job interviews and offers. Please know we do not charge fees to applicants at any stage of the hiring process. Official communication about your application will only come from emails ending in @samsara.com, @us-greenhouse-mail.io or @mail3.guide.co. For more information regarding fraudulent employment offers, please visit our blog post here.
Benefits
- 401(K), 401(K) matching, Adoption Assistance, Childcare benefits, Commuter benefits, Company equity, Company-sponsored outings, Continuing education stipend, Customized development tracks, Dedicated diversity and inclusion staff, Dental insurance, Disability insurance, Diversity manifesto, Documented equal pay policy, Employee stock purchase plan, Family medical leave, Fitness stipend, Flexible Spending Account (FSA), Free daily meals, Generous parental leave, Generous PTO, Company-sponsored happy hours, Health insurance, Job training & conferences, Life insurance, Charitable contribution matching, Mean gender pay gap below 10%, Mentorship program, Online course subscriptions available, Open office floor plan, Paid holidays, Pair programming, Paid sick days, Partners with nonprofits, Performance bonus, Pet friendly, Promote from within, Recreational clubs, Relocation assistance, Remote work program, Sabbatical, Free snacks and drinks, Team based strategic planning, OKR operational model, Mandated unconscious bias training, Unlimited vacation policy, Vision insurance, Wellness programs, Some meals provided, Mental health benefits, Home-office stipend for remote employees, Diversity employee resource groups, Hiring practices that promote diversity, Employee resource groups, Employee-led culture committees, Hybrid work model, President's club, Wellness days, Flexible time off, Floating holidays
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Security Engineer
LiftoffLiftoff is a leading AI-powered performance marketing platform for the mobile app economy. Our end-to-end technology stack helps app marketers acquire and retain high-value users, while enabling publishers to maximize revenue across programmatic and direct demand. Liftoff’s solutions, including Accelerate, Direct, Monetize, Intelligence, and Vungle Exchange, support over 6,600 mobile businesses across 74 countries in sectors such as gaming, social, finance, ecommerce, and entertainment. Founded in 2012 and headquartered in Redwood City, CA, Liftoff has a diverse, global presence. Come join the rocket ship! 🚀
Liftoff is a leading AI-powered performance marketing platform for the mobile app economy. Our end-to-end technology stack helps app marketers acquire and retain high-value users, while enabling publishers to maximize revenue across programmatic and direct demand. Liftoff’s solutions, including Accelerate, Direct, Monetize, Intelligence, and Vungle Exchange, support over 6,600 mobile businesses across 74 countries in sectors such as gaming, social, finance, ecommerce, and entertainment. Founded in 2012 and headquartered in Redwood City, CA, Liftoff has a diverse, global presence. About Liftoff Security TeamThe Liftoff security team is dedicated to protecting Liftoff’s customers, users, and employees. Our team architects Liftoff’s security posture, designs and builds infrastructure and security improvements, consults with other teams as they develop and launch new products and features, and proactively plans for the unknown. Our work spans the entire company and technology stack, from infrastructure to web and mobile applications, as well as IT systems. We collaborate with key stakeholders to balance business needs while minimizing security risks. Our approach to security is deeply rooted in software engineering principles, emphasizing automation and the development of well-designed security tools. Responsibilities - Establish secure software development standards and integrate security-minded thinking into the development process. - Create frictionless paths for engineering teams to securely build and deploy software. - Perform security assessments of systems and services to ensure compliance with security best practices. - Partner with key stakeholders across the organization to build a culture of security-minded builders. - Assess vendors to ensure their internal security controls meet Liftoff’s security requirements and their products enable secure employee usage. - Triage incoming threat events and vulnerabilities and ensure timely remediation and resolution of the issues. - Conduct post-incident reviews, document findings, and implement necessary remediations. - Develop tooling and automation to detect and mitigate active security threats within our systems. Requirements - 5+ years of experience in security engineering or software engineering. - Experience collaborating with cross-functional teams to deliver impactful security initiatives. - Comfortable reading, writing, and maintaining code in multiple languages. - Strong understanding of application security best practices. - Ability to quickly understand complex engineering architectures and systems. - Demonstrated ability to prioritize security efforts using a risk-based approach. - Proficiency in Go, Python, Clojure, or JavaScript. - Experience working on or collaborating with high-velocity, high-performing software engineering teams. - Proven track record of scaling cloud infrastructure security. - Excellent written and verbal communication skills. Working at Liftoff is fast-paced, fun, and challenging, and we thrive on innovation. Come join our team and help shape the future of the mobile app ecosystem. If this role sounds interesting to you, we would love to hear from you! Locations: This role is eligible for full-time remote work in one of our entities/states and Canada: CA, CO, ID, IL, FL, GA, MA, MI, MN, MO, NJ, NV, NY, OR, PA, TX, UT, and WA. We are a remote-first company with US hubs in Redwood City, Los Angeles, and New York City. Travel Expectations: We offer several opportunities for in-person team gatherings, including but not limited to project meetings, regional meetups, and company-wide events. We expect our employees to attend these gatherings at least once per quarter. These gatherings provide essential opportunities for collaboration, communication, and team building. Compensation: Liftoff offers all employees a full compensation package that includes equity and health/vision/dental benefits associated with your country of residence. Base compensation will vary based on the candidate's location and experience. The following are our base salary ranges for this role: - SF Bay Area, Los Angeles/Orange County, NYC, Seattle: $220,000 - $240,000 - All other California and Washington state locations, Austin, Boston, Denver, Portland: $202,400 - $220,800 - All other cities and towns in our approved states: $189,200 - $206,400 #LI-EL1 We use Covey as part of our hiring and/or promotional process for jobs in NYC and certain features may qualify it as an AEDT. As part of the evaluation process, we provide Covey with job requirements and candidate-submitted applications. We began using Covey Scout for Inbound on January 22, 2024. Please see the independent bias audit report covering our use of Covey here. Liftoff offers a fast-paced, collaborative, and innovative work environment where employees are empowered to grow and make an impact. We’re shaping the future of the mobile app ecosystem—join us and help accelerate what’s next. Liftoff’s compensation strategy includes competitive salaries, equity, and benefits designed to support employee well-being and performance. We benchmark compensation based on role, level, and location to ensure fairness and market alignment. Benefits may include medical coverage, wellness stipends, and additional perks based on your country of residence. Liftoff is an equal opportunity employer. We are committed to creating an inclusive environment for all employees and applicants regardless of race, ethnicity, national origin, age, marital status, disability, sexual orientation, gender identity, religion, veteran status, or any other characteristic protected by applicable law. Agency and Third Party Recruiter Notice: Liftoff does not accept unsolicited resumes from individual recruiters or third-party recruiting agencies in response to job postings. No fee will be paid to third parties who submit unsolicited candidates directly to our hiring managers or Recruiting Team. All candidates must be submitted via our Applicant Tracking System by approved Liftoff vendors who have been expressly requested to make a submission by our Recruiting Team for a specific job opening. No placement fees will be paid to any firm unless such a request has been made by the Liftoff Recruiting Team and such a candidate was submitted to the Liftoff Recruiting Team via our Applicant Tracking System.
Senior Information Security Engineer
UnitedHealth GroupUnitedHealth Group is a healthcare and well-being company that’s dedicated to improving the health outcomes of millions around the world. We are comprised of
Title: Senior Information Security Engineer - Remote or Hybrid in MN or DC Location: Eden Prairie United States Job Description: Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by diversity and inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health equity on a global scale. Join us to start Caring. Connecting. Growing together. The Enterprise Information Security (EIS) team is responsible for cybersecurity across our organization. We support our business and members by reducing risk, rapidly responding to threats, focusing on business resiliency and securing new acquisitions. This function independently drives vulnerability remediation by coordinating with application and technical owners, tracking remediation timelines, and assisting teams with remediation where necessary. This position will work directly with Senior Engineers and system owners, auditors and members of the risk and compliance team. Participate in, and occasionally lead, tabletop testing of the cyber security DR and IR policies, as well as be responsible for updating these documents, and others. You will have the flexibility to work remotely* as you take on some tough challenges. This position follows a hybrid schedule with four in-office days per week. Primary Responsibilities: - Perform risk and control analysis to identify security risks and remediation plans - Drive vulnerability remediation with application and technical owners to meet agreed timelines - Prioritize vulnerabilities by risk, exploitability, and known exploited threats - Track remediation progress and maintain accurate vulnerability and risk metrics - Provide guidance on compensating controls and secure remediation approaches - Maintain and update security risk records and remediation plans - Develop and execute incident response and disaster recovery tabletop exercises - Create, maintain, and operationalize incident response plans and procedures - Support real-time security incident investigations, containment, and recovery - Evaluate and implement security controls across on‑prem and cloud environments - Serve as escalation point for complex identity, network, and security issues - Demonstrate understanding of discovery technologies to identify system vulnerabilities (e.g., scanning tools) - Document risks associated with approved exceptions, define mitigation controls and establish long-term remediation strategies - Create reports around findings, outstanding risk and advice on next steps of the remediation process - Define/implement security data management/reporting requirements - Demonstrate knowledge of applicable IT industry security standards (e.g., PCI-DSS, SSAE16, NIST800-53) - Maintain current knowledge on information security topics and their applicability program requirements You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear directions on what it takes to succeed in your role as well as provide development for other roles you may be interested in. Required Qualifications: - Bachelor's degree OR 5+ years of Technology experience - 3+ years of experience building relationships across multiple technical teams, stakeholders, and leadership - 2+ years of hands-on experience in technology and security audit - 2+ years of working experience with one or more compliance frameworks including NIST (800-53, 800-171), FedRAMP, MARS-e, and HITRUST - 1+ years of experience with an industry recognized vulnerability management tool, resolving findings and tracking of remediation plans - 1+ years of experience interacting with an executive audience Preferred Qualifications: - Holds an audit, networking or security certification (CISA, GIAC, ISC2) - Project Management / Project coordination experience - Experience with application and system security implementation and remediation - Broad knowledge of Optum Technology and UHG/Optum/UHC businesses - Proven excellent interpersonal, oral and written communication skills, including ability to deliver a clear overview of strategy, opportunity and risks - Proven analytical skills related to application and customer inquiries - Proven influence and motivate teams that are required to interact with auditors - All Telecommuters will be required to adhere to UnitedHealth Group's Telecommuter Policy. Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $91,700 to $163,700 annually based on full-time employment. We comply with all minimum wage laws as applicable. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants. At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location, and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups, and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission. UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment. #RPO #GREEN
Senior Director Analyst, Cybersecurity, Governance, Risk & Compliance
GartnerWe deliver actionable, objective insight that drives smarter decisions and stronger performance.
• Create innovative, thought provoking, and highly leveraged “must-have insights” content • Develop new insights and ideas through thought leadership and offer compelling, actionable approaches to client's needs and requests that accelerate the client's ability to act • Develop in-depth analysis to identify the root cause of a client’s barriers or overall needs and reframe thinking to drive strategy forward • Demonstrate thought leadership in establishing Insights positions across a team of analysts • Bring provocative, independent insights to Gartner leaders that can evolve the course of a research agenda • Research, analyze and predict market trends and shifts to provide clients and vendors with actionable insights • Provide clients and prospects with actionable advice aligned to their designated content area via virtual or face-to-face interactions • Create and deliver high value presentation materials on and off stage for Gartner events, industry and professional association conferences, and client briefings • Support BTI and Sales: Provide sales support serving as voice of the market to help Insights teams create content and to drive engagement with clients to make progress against their critical priorities to grow their business • Provide high quality and timely content peer review • Build credibility as an industry expert to represent Gartner insights, methodology and strategy • Actively participate in innovation, ideation, and research discussions and collaborate effectively with peers in the Insights community • Identify research process improvements or develop new processes that help the team and BTI provide excellent service delivery • Be a mentor and a coach by supporting more junior team members • Be client-centric while actively seeking to help clients engage regularly and often with Gartner insights and interactions
Senior Corporate Security Engineer
AirwallexAirwallex is a financial services company that has developed a “global financial platform for modern businesses.” As an employer, the company strives to cul
About Airwallex Airwallex is the only unified payments and financial platform for global businesses. Powered by our unique combination of proprietary infrastructure and software, we empower over 200,000 businesses worldwide - including Brex, Rippling, Navan, Qantas, SHEIN and many more - with fully integrated solutions to manage everything from business accounts, payments, spend management and treasury, to embedded finance at a global scale. Proudly founded in Melbourne, we have a team of over 2,000 of the brightest and most innovative people in tech across 26 offices around the globe. Valued at US$8 billion and backed by world-leading investors including T. Rowe Price, Visa, Mastercard, Robinhood Ventures, Sequoia, Salesforce Ventures, DST Global, and Lone Pine Capital, Airwallex is leading the charge in building the global payments and financial platform of the future. If you're ready to do the most ambitious work of your career, join us. Attributes We Value We hire successful builders with founder-like energy who want real impact, accelerated learning, and true ownership. You bring strong role-related expertise and sharp thinking, and you're motivated by our mission and operating principles. You move fast with good judgment, dig deep with curiosity, and make decisions from first principles, balancing speed and rigor. You're humble and collaborative; turn zero-to-one ideas into real products, and you "get stuff done" end-to-end. You use AI to work smarter and solve problems faster. Here, you'll tackle complex, high-visibility problems with exceptional teammates and grow your career as we build the future of global banking. If that sounds like you, let's build what's next. Your role As a Senior Corporate Security Engineer, you will be a critical part of defending Airwallex's enterprise systems and employees from threats such as malware, phishing and unauthorised access. This role is a highly technical opportunity to detect, investigate and prevent security issues across a modern corporate environment. You will work on digital forensics, incident response and tool development and deployment, protecting a range of corporate IT platforms from endpoints to identity providers. What you'll be doing - Contribute to incident response for malware, phishing, digital forensics. - Design, develop, test, and evaluate new corporate security controls for a rapidly growing business. - Perform incident response and hunt through log sources to identify new threats. - Design and implement security alerts and workflows to support the incident response lifecycle. - Secure corporate IT infrastructure and remediate issues across identity providers, endpoints, corporate networks and other platforms. - Deploy, configure and operate security tooling with a laser focus on impact. What you'll bring - A passion for solving the complex challenges of high-growth startups. - Self motivation and drive to learn new skills, or dive deeper into existing skills. - Bachelor's degree in Computer Science, Cybersecurity or similar. - 5+ years working in a security engineering or incident response role within a tech company. - Strong experience with Crowdstrike, Splunk or other common security monitoring tools. - In depth understanding of common attacker tools and techniques, how they can be detected and prevented, and ability to respond to incidents with high depth and quality of investigation. - Experience with GCP, Alibaba Cloud or other cloud platforms is preferred. - Experience with Okta, Google Workspace and cloud-based VPN services is preferred. - Experience securing endpoints, including with MDM tooling such as Kandji, Intune - Strong communication skills with the ability to explain technical security and software concepts to a non-technical audience. - Scripting experience such as with Python, Bash, Powershell. Applicant Safety Policy: Fraud and Third-Party Recruiters To protect you from recruitment scams, please be aware that Airwallex will not ask for bank details, sensitive ID numbers (i.e. passport), or any form of payment during the application or interview process. All official communication will come from an @airwallex.com email address. Please apply only through careers.airwallex.com or our official LinkedIn page. Airwallex does not accept unsolicited resumes from search firms/recruiters. Airwallex will not pay any fees to search firms/recruiters if a candidate is submitted by a search firm/recruiter unless an agreement has been entered into with respect to specific open position(s). Search firms/recruiters submitting resumes to Airwallex on an unsolicited basis shall be deemed to accept this condition, regardless of any other provision to the contrary. Equal opportunity Airwallex is proud to be an equal opportunity employer. We value diversity and anyone seeking employment at Airwallex is considered based on merit, qualifications, competence and talent. We don't regard color, religion, race, national origin, sexual orientation, ancestry, citizenship, sex, marital or family status, disability, gender, or any other legally protected status when making our hiring decisions. If you have a disability or special need that requires accommodation, please let us know. #BI-Hybrid



