Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Security Engineer - Product Security

$230k - $275k

Zipline

Job Description

Job Description

About Zipline

Zipline is the world's largest and most experienced drone delivery service. We are on a mission to serve all humans equally by ensuring access to food, medicine and essential goods anytime, anywhere. We design, build, and operate the world's largest autonomous logistics system, delivering critical supplies quickly and reliably. Today, Zipline operates on four continents, makes a delivery somewhere in the world every 30 seconds, and has completed millions of deliveries to date, including blood, vaccines, medical supplies, food, and retail products.

Our customers include the world's largest and most prominent healthcare systems, governments, retailers, restaurants and global businesses who rely on us to save lives, reduce emissions, increase economic opportunity, and provide delivery from point A to point B as fast as possible. The drone is only 15% of what we've built to enable seamless, reliable, global operations.

Our system strengthens supply chains, reduces congestion, and gives people time back. With more than 140 million commercial autonomous miles safely flown, Zipline is redefining access to healthcare, consumer products, and food across the globe.

We operate at a global scale and are looking for practical problem solvers who thrive on real-world challenges and rapid growth. Our team is motivated by building systems that have a direct, meaningful impact on people's lives and by scaling the future of logistics. We are seeking people who sculpt from first principles, enjoy facing adversity, and can do the impossible at record breaking speeds.

About You and The Role

Zipline builds and operates fleets of delivery drones to get medicine to those who need it, fast, regardless of where they live. To power this, the software team is building out the long term scalable solutions to expand rapidly while empowering our world class distribution centers to serve their customers as fast as possible.

Zipline's security problems aren't "website got pwned" problems (though those exist too). They're "real-world autonomy + robotics + global operations + cloud software + regulated/health-adjacent workflows" problems. You'll partner deeply with software, infrastructure, and (where relevant) embedded/autonomy teams to reduce real risk in real systems. We have a large attack surface

Our ideal candidate works well in startup environments, wears many hats, and collaborates across engineering disciplines. You'll join a small, high-ownership security team with significant influence over how we scale.

A note on our modern reality and agentic tooling:

Engineering teams are increasingly adopting LLM copilots and agentic tools to move faster. That's useful, until an "assistant" becomes an unmonitored automation path to secrets, sensitive data, or privileged actions. (Think: "obedient intern with production credentials.") Industry guidance is converging on practical frameworks like the NIST AI Risk Management Framework (including a profile for generative AI) and the OWASP Top 10 for LLM Applications, which explicitly calls out risks like prompt injection, insecure plugin design, and excessive agency.

In this role, you'll help Zipline safely leverage these tools while containing them so they don't quietly "rewrite the threat model".

This is a Hybrid onsite role - you will frequently have conversations in person at our HQ in South San Francisco.

What You'll Do
  • Own security outcomes for critical parts of Zipline's application and cloud ecosystem (not by writing policy docs that no one reads, but by shipping controls and enabling teams).
  • Partner with engineering teams on secure architecture, threat modeling, and design reviews for services that must be correct, reliable, and defensible under real-world operational pressure.
  • Help us build and scale a pragmatic secure SDLC – CI/CD hardening, dependency/supply-chain controls, secrets management, and code review patterns that don't slow teams down.
  • Improve cloud security posture end-to-end: IAM and least privilege, network/service-to-service trust, key management, logging/telemetry, runtime detection, and incident-ready auditability.
  • Drive vulnerability management that actually closes risk: triage, exploitability analysis, remediation partnerships, and verification.
  • Help build and exercise incident response: playbooks, tabletop exercises, logging requirements, and "know it happened / know what changed" operational discipline.
  • Support data classification and access control models aligned to how Zipline operates (including partner/customer interfaces and global operations).
  • Support external penetration tests and turn results into durable improvements, not whack‑a‑mole patches.
  • Contribute to security compliance efforts (e.g., SOC 2 / ISO 27001) in a way that strengthens engineering
  • Secure AI-assisted and agentic engineering workflows (this is explicitly part of the job):
    • define safe patterns for copilots/LLM tools used in development and ops
    • implement guardrails for sensitive data exposure and output handling
    • prevent "agentic overreach" (over‑privileged tools, unsafe tool-calling, silent action-taking)
    • build monitoring/auditing around AI tool use where it matters

What You'll Bring
  • 8+ years of experience designing, building, and operating security controls for large-scale production systems (application, cloud, and infrastructure security).
  • Strong security engineering chops with evidence you can reduce risk in production systems (not just talk about it).
  • Hands-on ability to write and ship code/tools in Python, Go, or similar (you're expected to build, not just review).
  • Practical experience securing microservice architectures and modern cloud stacks (containers/Kubernetes, IAM, CI/CD, secrets, logging).
  • Comfort operating as a technical leader without authority: you can persuade, teach, and unblock - not police.
  • A skeptical mindset: you naturally ask "what's the failure mode?" and "how will this be abused?" before shipping changes.
  • Familiarity with the security failure modes of LLM-enabled systems (or the willingness to learn fast), including risks called out by OWASP such as prompt injection, insecure output handling, insecure plugin design, and excessive agency.
Nice To Haves
  • Experience spanning multiple engineering domains (web app + cloud infra + embedded/robotics/autonomy).
  • Experience building developer-friendly security platforms (internal libraries, paved roads, CI integrations, Public Key Infrastructure).
  • Track record of being an effective security "evangelist" (i.e., enabling good behavior with good tools and defaults, not fear).
  • Experience designing guardrails for internal AI/agent usage (policy + technical controls + auditing), especially in environments where safety and reliability are non-negotiable.
  • Deep understanding of distributed systems and how failures actually happen (partial outages, weird retries, cascading dependencies, misconfigurations, permissions drift).
What Else to Know

This will be an in-office or hybrid role based out of our South San Francisco HQs.

The starting cash range for this role is $230,000 - $275,000; please note that this is a target, starting cash range for a candidate who meets the minimum qualifications for this role. We are always open to negotiation. The final cash pay for this role will depend on a variety of factors, including a specific candidate's experience, qualifications, skills, working location, and projected impact. The total compensation package for this role may also include: equity compensation; overtime pay; discretionary annual or performance bonuses; sales incentives; benefits such as medical, dental and vision insurance; paid time off; and more.

Zipline is an equal opportunity employer and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws or our own sensibilities.

We value diversity at Zipline and welcome applications from those who are traditionally underrepresented in tech. If you like the sound of this position but are not sure if you are the perfect fit, please apply.

Vacancy posted 22 days ago
Similar jobs that could be interesting for youBased on the Staff Security Engineer - Product Security in South San Francisco, CA vacancy
  • A leading logistics company in South San Francisco seeks an experienced Security Engineer to own security for their application and cloud ecosystem. The candidate will work with engineering teams to enhance secure architecture and manage vulnerabilities. You should have... 
    Suggested

    Zipline International Inc.

    South San Francisco, CA
    4 days ago
  • $237.6k - $297k

     ...We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the... 
    Suggested
    Full time

    Scale AI

    San Francisco, CA
    22 hours ago
  •  ...help them discover the best products from around the world to sell...  ...ours. Role Description Our Engineering organization owns the software...  ...marketplace work. Our Product Security team enables product engineering...  ...; and iterate. As a Senior Staff Software Engineer, Product... 
    Suggested
    Local area

    Elea Ecuador

    San Francisco, CA
    3 days ago
  • Elea Ecuador is seeking a Senior Staff Software Engineer for Product Security in San Francisco, California. In this role, you will lead the security direction and collaborate with engineering teams to mitigate security risks. You will drive the design and implementation... 
    Suggested

    Elea Ecuador

    San Francisco, CA
    3 days ago
  •  ...Role We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit...  ...-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services-from intake to validation, remediation coordination... 
    Suggested
    Full time
    Temporary work
    Work at office
    Worldwide
    Monday to Friday
    Flexible hours

    Replit

    Foster, CA
    22 hours ago
  • $250k - $285k

     ...high-performing team that believes in each other, come build with us at Crusoe. About This Role We’re seeking a Staff Product Security Engineer with deep AI/ML security expertise to strengthen Crusoe’s security posture across applications, infrastructure, and... 
    Temporary work

    Crusoe

    San Francisco, CA
    13 days ago
  • $180k - $247k

     ...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building...  ...building a world where Identity belongs to you. The Staff Product Security Engineer Opportunity The Security team's mission is to... 
    Local area
    Remote work
    Worldwide
    Flexible hours

    Okta, Inc.

    San Francisco, CA
    2 days ago
  •  ...collaborative; turn zerotoone ideas into real products, and you "get stuff done" end-to-...  ...team Airwallex's Information Security team partners closely with engineering, IT, and other stakeholders to...  ...a blocker. Your role As a Staff Product Security Engineer at... 
    Worldwide

    Airwallex

    San Francisco, CA
    4 days ago
  • $276k - $320k

     ...hardware, software, AI, cryptography, mobile engineering, and global operations. Our teams come from OpenAI...  ...the Time AI 100. Learn more about the newest product launches from our Liftoff event. About the Team The Security team at Tools for Humanity operates at a... 
    Flexible hours

    Tools for Humanity

    San Francisco, CA
    2 days ago
  • $200k - $300k

     ...sensitive AI-powered platform that includes solutions for video security, access control, air quality sensors, alarms, intercoms,...  ...training and information sharing Partner closely with engineering and product teams to improve the security of Verkada’s products and exceed... 
    Full time
    Work at office
    Work visa
    Flexible hours
    Shift work

    Verkada

    San Mateo, CA
    2 days ago
  • $200k - $300k

     ...sensitive AI-powered platform that includes solutions for video security, access control, air quality sensors, alarms, intercoms, and...  ...security best practices across the organization Partner with IT, Engineering, and Security teams to secure internal systems, endpoints,... 
    Full time
    Work visa
    Flexible hours
    Shift work

    Verkada

    San Mateo, CA
    10 hours ago
  • $50 per hour

     ...computational biology. About This Role Crusoe Security & Compliance is hiring a Senior/Staff Application Security Engineer to play a critical role in ensuring the...  ...improvement of our security posture, making our products safer and our customers' data more secure. A... 
    Temporary work

    ProducePay

    San Francisco, CA
    3 days ago
  • Airwallex Pty Ltd. is looking for a Staff Product Security Engineer in San Francisco to join the Information Security team. This hands-on role involves designing and managing security controls to protect our infrastructure and systems against cybersecurity threats. The... 

    Airwallex Pty Ltd.

    San Francisco, CA
    3 days ago
  •  ...the team Airwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect...  ...across the company—from secure product and infrastructure design to risk...  ...treated as a blocker. Your role As a Staff Product Security Engineer at... 

    Airwallex-

    San Francisco, CA
    3 days ago
  • $225k - $275k

     ...hidden fees or compounding interest. Affirm values information security as a critical part of the company’s continued success. Our...  ..., enabling the company to succeed in building honest financial products. The Security team posture increases security and reduces risk... 
    Casual work
    Work at office
    Remote work
    Flexible hours

    Affirm

    San Francisco, CA
    1 day ago
  • $200k - $275k

    A leading financial technology company is looking for a security engineer to enhance product security and automate processes. Responsibilities include collaborating with product teams on security measures, conducting threat modeling and analysis, as well as reviewing source... 
    Remote job

    Affirm

    San Francisco, CA
    4 days ago
  • $217k - $303.9k

    Tensec is seeking a Staff Product Security Engineer in San Francisco, California. The role involves leading the design of secure frameworks and integrating security into engineering workflows. Candidates should have over 8 years of experience in software or application... 
    Remote job

    Tensec

    San Francisco, CA
    1 day ago
  • Airwallex is seeking a Staff Product Security Engineer to join its Information Security team in San Francisco. This role involves creating security controls, improving security practices, and responding to cybersecurity incidents. The ideal candidate will have over 8 years... 

    Airwallex-

    San Francisco, CA
    4 days ago
  • A leading identity verification company in San Francisco seeks a skilled Product Security Engineer. In this role, you'll drive the vulnerability lifecycle, design scalable security systems, and partner with engineers to ensure secure product development. Candidates should... 
    Relocation package

    Persona

    San Francisco, CA
    22 hours ago
  • $200k - $300k

     ...sensitive AI-powered platform that includes solutions for video security, access control, air quality sensors, alarms, intercoms,...  ...training and information sharing Partner closely with engineering and product teams to improve the security of Verkada’s products and exceed... 
    Full time
    Work at office
    Work visa
    Flexible hours
    Shift work

    Verkada

    San Mateo, CA
    2 days ago
  • $222k - $278k

    A code security company is looking for a Senior Security Engineer to enhance product security. This role involves collaborating with engineering teams to ensure secure application development and infrastructure management. Ideal candidates will have 7+ years of experience... 
    Work at office

    Semgrep

    San Francisco, CA
    3 days ago
  • B Capital is looking for a Product Security Engineer to join our Salesforce product security advisors team. This role requires expertise in securing cloud platforms and deep technical knowledge of security practices. You will embed security controls throughout the SDLC,... 

    B Capital

    San Francisco, CA
    3 days ago
  • $127k - $249k

     ...We are hiring an experienced Security Software Engineer (Staff or Senior) for our Infrastructure Security team to design and build scalable security...  ...long-term ownership Collaborate with SRE, platform and product engineering teams to define secure architectures for new... 
    Work at office
    Local area
    Remote work
    Worldwide
    Flexible hours

    MongoDB

    San Francisco, CA
    1 day ago
  • $210k - $230k

     ...process. About the Role: We're looking for a Senior Staff Security Engineer to lead Gusto's edge and network security strategy, owning...  ...across the security org, partnering with infrastructure and product teams to make high-impact architectural decisions that compound... 
    Full time
    Work at office
    Local area
    Remote work
    2 days per week
    3 days per week

    gusto

    San Francisco, CA
    a month ago
  • $148.5k - $260.1k

     ...ensure you are not duplicating efforts. Job Category Product Job Details About Salesforce Salesforce is the #1...  ...of Salesforce. The Experience Salesforce Enterprise Security is hiring a Senior and Lead Security Engineer for our Secure AI team to help assess and maintain... 
    Full time

    Salesforce

    San Francisco, CA
    2 days ago
  • A tech-driven company in San Francisco seeks a Staff Software Engineer specializing in product security. This role requires 8+ years of experience and focuses on integrating security into AI platforms while collaborating across teams. The ideal candidate will drive security... 

    Harvey

    San Francisco, CA
    22 hours ago
  • A leading tech company in San Francisco is seeking a Senior/Staff Application Security Engineer to ensure the security of its applications and infrastructure. The role involves integrating security into the software development lifecycle, conducting assessments, and mentoring... 

    Epoch Biodesign

    San Francisco, CA
    22 hours ago
  •  ...Senior And Lead Security Engineer Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword — it's a way of life. The world of work as we know it is changing... 

    Salesforce

    San Francisco, CA
    1 day ago
  • $134.4k - $170.53k

     ...As the world's leading vendor of Cyber Security, facing the most sophisticated threats and...  ...threats. As a Workspace Security Engineer, you'll be at the heart of our mission,...  ...Responsibilities Responsible for delivery of product demonstrations Client Collaboration:... 
    Temporary work
    Local area

    Check Point Software Technologies

    San Francisco, CA
    3 days ago
  • $234.4k - $385k

     ...About the Team Security is at the foundation of OpenAI's mission to ensure that artificial...  ...OpenAI's technology, people, and products. We are technical in what we build but are...  ...About the Role As a Security Engineer, Application Security you will be responsible... 
    Work at office
    Remote work
    Relocation package

    OpenAI

    San Francisco, CA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Security Engineer - Product Security. Be the first to apply!