Zipline logo

Senior/Staff Security Engineer

Zipline

RemoteFull timeMid levelPosted today
Apply with JobAssist

About the role

Who you are

  • 8+ years building and operating security controls for large-scale production systems across application and cloud infrastructure
  • Demonstrable hands-on engineering ability: you ship automation or tooling in Python, Go, or similar and can build integrations with AI tools and agentic security bots (not only write policies)
  • Deep practical experience with cloud-native stacks and microservices (Kubernetes, containers, IAM, CI/CD, secrets management, logging/telemetry) and with designing least-privilege service-to-service models
  • Prior ownership of vulnerability management, incident response playbooks, and verification processes for production services
  • Direct experience threat‑modeling and securing systems that interface with physical systems, regulated workflows, or third-party partners (embedded, teleoperation, field ops, or healthcare-adjacent data flows)
  • Ability to define and track quantitative success metrics (MTTD, MTTR, number of exploitable findings, compliance audit readiness) and be accountable for meeting targets within 6–12 months
  • Operates as a technical owner: can persuade engineering teams, prioritize trade-offs, and drive changes through to production without relying solely on policy enforcement
  • Skeptical, adversarial mindset: anticipates failure modes and abuse cases for systems that interact with the physical fleet and partner workflows
  • Experience securing LLM/agentic tools in engineering workflows and mitigating OWASP LLM risks (prompt injection, unsafe plugin/output handling, agentic privilege misuse)
  • Background across multiple domains (cloud infra, web services, and embedded/autonomy) and experience building developer-friendly security platforms or paved-road tooling

What the job involves

  • Product security at Zipline protects systems that directly affect safety, regulatory compliance, and uninterrupted delivery of critical goods in real-world operational environments
  • You will own security for production services and integrations that run our fleet orchestration, distribution center automation, telemetry/teleoperation, and developer/operator toolchains. This role is mission-critical: your work will reduce attack surface that could cause service outages, unsafe drone behavior, data exposure of patient/partner data, or regulatory failure
  • You will join a small, high-ownership security team and partner deeply with software, infrastructure, autonomy/embedded, and field-ops teams. Expect hands-on engineering work, prioritized ownership of specific services, and a mandate to ship controls that measurably reduce risk in production systems under operational pressure
  • Own security outcomes for 2-4 named production areas (examples: fleet orchestration APIs, DC orchestration/robotics control plane, telemetry and command channels, developer CI/CD and secrets platforms). Be the primary security owner for at least one area on hire
  • Deliver measurable risk reduction: define baseline metrics (e.g., mean-time-to-detect, mean-time-to-remediate, number of exploitable findings) and be accountable to improving them by defined targets in 6 and 12 months (example targets: cut exploitable high-risk findings by 50% in owned services; reduce MTTD for critical alerts to <30m)
  • Design and implement production controls: IAM/least-privilege policies, service-to-service trust, key lifecycle and KMS integrations, runtime telemetry and alerting, secure OTA/update patterns for edge devices, and hardened CI/CD pipelines and build artifact provenance
  • Threat model and perform secure design reviews for services that operate near the physical fleet, regulated workflows, or partner/customer interfaces; produce engineering-tractable mitigations and drive their rollout to completion
  • Lead vulnerability management end-to-end for owned services: vulnerability triage with exploitability analysis, prioritized remediation plans with engineering partners, staged verification, and verification metrics for closure and regression prevention
  • Build and harden incident response for product incidents: author playbooks, run tabletop exercises with product and operations, validate logging/auditability so incidents are forensic-ready, and participate in incident postmortems with corrective action tracking
  • Secure AI/agent-assisted development and ops: define allowed copilots and patterns, implement guardrails to prevent secret exposure and unauthorized actions, and add monitoring/auditing for risky agent behaviors where it intersects owned systems
  • Integrate external pentest and red-team results into durable engineering changes; turn test findings into tracked engineering tickets and measurable closure criteria
  • Collaborate daily with SREs, platform engineers, autonomy/embedded teams, field ops, and compliance to translate regulatory/safety requirements (e.g., health-adjacent data handling, auditability) into concrete technical controls

Millions of jobs, with real people getting hired every day

20,000+
New jobs added daily
7,000,000+
Verified job listings
500,000+
Tailored applications submitted
FAQ

Questions, answered

Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.

Yes. This role at Zipline was screened before publishing – we confirmed the employer before listing it.

The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.

This position can be done from anywhere, with no in-office requirement.

Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.