FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive experience in vulnerability management and application security, with a strong focus on automation, cloud services, and secure design practices. Capable of setting technical direction and driving remediation efforts across diverse environments while mentoring engineering teams.
Highest-signal resume keywords
Vulnerability ManagementCloud EngineeringGo ProgrammingAWS Cloud ServicesSecurity Automation
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Vulnerability ManagementGo ProgrammingPython ProgrammingJavaScript ProgrammingSASTDASTSCACI/CD IntegrationAI/LLM ToolingFirmware Development
Soft Skills
MentoringCommunicationCollaboration
Tools & Technologies
WizSemgrepTinesAWS Lambda
Certifications & Qualifications
FedRAMP Certification
Industry Keywords
Cloud SecurityApplication SecurityVulnerability ScoringCVSSEPSS
Tech Stack
Tools & technologiesAWSCloudIoTJavaScriptPythonC++Go
About the role
Key responsibilities & impact- Lead the strategy, operation, and continuous improvement of Samsara's vulnerability management and application security programs
- Drive down mean time to remediate across the vulnerability backlog
- Build and champion automation and tooling for vulnerability detection and response across cloud, firmware/IoT, and corporate systems
- Set technical and architectural direction and translate strategic priorities into execution plans
- Drive remediation by partnering with engineering teams and providing actionable guidance
- Partner with technical program management on reporting
- Mentor and develop engineers on secure design and remediation practices
- Communicate risk and remediation tradeoffs to engineering leadership
- Participate in security incident investigations involving high-profile vulnerabilities
- Be regularly on call for critical vulnerability response
- Champion and embed Samsara's cultural principles as the company scales globally
Requirements
What you’ll need- 10+ years of relevant experience as a cloud engineer or security engineer
- Hands-on vulnerability management across a broad, multi-product enterprise environment
- Proficiency in Go, Python, and JavaScript
- Ability to independently set technical and architectural direction for a security program
- Ability to drive remediation across a broad, multi-surface environment without direct authority over fixing teams
- Significant experience with vulnerability management tooling such as Wiz and Semgrep
- Deep familiarity with CVSS and EPSS vulnerability scoring frameworks
- Strong AWS cloud services background
- Deep understanding of SAST, DAST, and SCA
- Hands-on use of AI/LLM tooling in security workflows
- Experience with C/C++ relevant to firmware and embedded systems (ideal)
- Experience at a cloud-native, AI-forward company building agentic or AI-driven products (ideal)
- Experience with security automation platforms such as Tines and serverless frameworks such as AWS Lambda (ideal)
- Experience integrating vulnerability management into CI/CD pipelines with a shift-left mentality (ideal)
- Experience spanning SaaS, firmware, and corporate IT security programs (ideal)
- Experience managing vulnerabilities within a FedRAMP-certified environment (ideal)
- Experience building or extending AI copilots/agents for security workflows (ideal)
Benefits
Comp & perks- Initial RSU grant with no vesting cliff
- Ongoing equity refresh opportunities tied to performance
- Performance-based bonus/variable pay
- Equity for eligible roles
- Flexible, employee-led remote model
- Professional development stipend
- Comprehensive health plans
- Parental leave plans
- Flexible working model
- Remote work support where aligned with operational requirements
