Staff Security Engineer - Product Security
$230k - $275kNamely
ABOUT ZIPLINE Zipline is at the forefront of a logistics revolution: We design, manufacture, and operate our own fleet of autonomous drones, and all ground-based equipment that supports flight, to deliver critical and lifesaving medicine to thousands of hospitals serving millions of people on multiple continents. Our mission is to provide every human on Earth with instant access to vital medical supplies. Do you want to change the world? Join Zipline and help us make this a reality for billions of people. ABOUT YOU AND THE ROLE Zipline builds and operates fleets of delivery drones to get medicine to those who need it, fast, regardless of where they live. To power this, the software team is building out the long term scalable solutions to expand rapidly while empowering our world class distribution centers to serve their customers as fast as possible. Zipline’s security problems aren’t “website got pwned” problems (though those exist too). They’re “real-world autonomy + robotics + global operations + cloud software + regulated/health-adjacent workflows” problems. You’ll partner deeply with software, infrastructure, and (where relevant) embedded/autonomy teams to reduce real risk in real systems. We have a large attack surface Our ideal candidate works well in startup environments, wears many hats, and collaborates across engineering disciplines. You’ll join a small, high-ownership security team with significant influence over how we scale. A note on our modern reality and agentic tooling: Engineering teams are increasingly adopting LLM copilots and agentic tools to move faster. That’s useful, until an “assistant” becomes an unmonitored automation path to secrets, sensitive data, or privileged actions. (Think: “obedient intern with production credentials.”) Industry guidance is converging on practical frameworks like the NIST AI Risk Management Framework (including a profile for generative AI) and the OWASP Top 10 for LLM Applications, which explicitly calls out risks like prompt injection, insecure plugin design, and excessive agency. In this role, you’ll help Zipline safely leverage these tools while containing them so they don’t quietly “rewrite the threat model”. This is a Hybrid onsite role - you will frequently have conversations in person at our HQ in South San Francisco. WHAT YOU’LL DO Own security outcomes for critical parts of Zipline’s application and cloud ecosystem (not by writing policy docs that no one reads, but by shipping controls and enabling teams). Partner with engineering teams on secure architecture, threat modeling, and design reviews for services that must be correct, reliable, and defensible under real-world operational pressure. Help us build and scale a pragmatic secure SDLC – CI/CD hardening, dependency/supply-chain controls, secrets management, and code review patterns that don’t slow teams down. Improve cloud security posture end-to-end: IAM and least privilege, network/service-to-service trust, key management, logging/telemetry, runtime detection, and incident-ready auditability. Drive vulnerability management that actually closes risk: triage, exploitability analysis, remediation partnerships, and verification. Help build and exercise incident response: playbooks, tabletop exercises, logging requirements, and “know it happened / know what changed” operational discipline. Support data classification and access control models aligned to how Zipline operates (including partner/customer interfaces and global operations). Support external penetration tests and turn results into durable improvements, not whack‑a‑mole patches. Contribute to security compliance efforts (e.g., SOC 2 / ISO 27001) in a way that strengthens engineering Secure AI-assisted and agentic engineering workflows (this is explicitly part of the job): define safe patterns for copilots/LLM tools used in development and ops implement guardrails for sensitive data exposure and output handling prevent “agentic overreach” (over‑privileged tools, unsafe tool-calling, silent action-taking) build monitoring/auditing around AI tool use where it matters WHAT YOU’LL BRING 8+ years of experience designing, building, and operating security controls for large-scale production systems (application, cloud, and infrastructure security). Strong security engineering chops with evidence you can reduce risk in production systems (not just talk about it). Hands-on ability to write and ship code/tools in Python, Go, or similar (you’re expected to build, not just review). Practical experience securing microservice architectures and modern cloud stacks (containers/Kubernetes, IAM, CI/CD, secrets, logging). Comfort operating as a technical leader without authority: you can persuade, teach, and unblock - not police. A skeptical mindset: you naturally ask “what’s the failure mode?” and “how will this be abused?” before shipping changes. Familiarity with the security failure modes of LLM-enabled systems (or the willingness to learn fast), including risks called out by OWASP such as prompt injection, insecure output handling, insecure plugin design, and excessive agency. NICE TO HAVES Experience spanning multiple engineering domains (web app + cloud infra + embedded/robotics/autonomy). Experience building developer-friendly security platforms (internal libraries, paved roads, CI integrations, Public Key Infrastructure). Track record of being an effective security “evangelist” (i.e., enabling good behavior with good tools and defaults, not fear). Experience designing guardrails for internal AI/agent usage (policy + technical controls + auditing), especially in environments where safety and reliability are non-negotiable. Deep understanding of distributed systems and how failures actually happen (partial outages, weird retries, cascading dependencies, misconfigurations, permissions drift). WHAT ELSE YOU NEED TO KNOW This will be an in-office or hybrid role based out of our South San Francisco HQs. The starting cash range for this role is $230,000 - $275,000; please note that this is a target, starting cash range for a candidate who meets the minimum qualifications for this role. We are always open to negotiation. The final cash pay for this role will depend on a variety of factors, including a specific candidate's experience, qualifications, skills, working location, and projected impact. The total compensation package for this role may also include: equity compensation; overtime pay; discretionary annual or performance bonuses; sales incentives; benefits such as medical, dental and vision insurance; paid time off; and more. Zipline is an equal opportunity employer and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws or our own sensibilities. We value diversity at Zipline and welcome applications from those who are traditionally underrepresented in tech. If you like the sound of this position but are not sure if you are the perfect fit, please apply. #J-18808-Ljbffr
- ...A leading logistics company in South San Francisco seeks an experienced Security Engineer to own security for their application and cloud ecosystem. The candidate will work with engineering teams to enhance secure architecture and manage vulnerabilities. You should have...Suggested
- ...Elea Ecuador is seeking a Senior Staff Software Engineer for Product Security in San Francisco, California. In this role, you will lead the security direction and collaborate with engineering teams to mitigate security risks. You will drive the design and implementation...Suggested
$237.6k - $297k
...We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the...SuggestedFull time- ...Offensive Security Engineer, Product Security at Zoox – Foster City, CA Zoox is seeking an experienced Offensive Security Engineer with deep technical expertise in reviewing and testing Internet of Things (IoT) devices, robots, or autonomous systems. This individual will...Suggested
- ...multi-year runway. About the Role We're looking for a Staff Security Engineer to be Sprinter's first dedicated security hire and help... ...HITRUST readiness, and partner closely with engineering, product, IT, legal, operations, and leadership to make security a core...SuggestedTemporary workWork at officeRemote workRelocation packageFlexible hours
- ...Role We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit... ...-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services-from intake to validation, remediation coordination...Full timeTemporary workWork at officeWorldwideMonday to FridayFlexible hours
$276k - $320k
...real human while preserving privacy. Our products make this possible: the Orb verifies... ...hardware, software, AI, cryptography, mobile engineering, and global operations. Our teams come... ...Unwrapped event. About The Team The Security team at Tools for Humanity operates at a...Flexible hours- ...Airwallex Pty Ltd. is looking for a Staff Product Security Engineer in San Francisco to join the Information Security team. This hands-on role involves designing and managing security controls to protect our infrastructure and systems against cybersecurity threats. The...
$217k - $303.9k
...Tensec is seeking a Staff Product Security Engineer in San Francisco, California. The role involves leading the design of secure frameworks and integrating security into engineering workflows. Candidates should have over 8 years of experience in software or application...Remote work$50 per hour
...computational biology. About This Role Crusoe Security & Compliance is hiring a Senior/Staff Application Security Engineer to play a critical role in ensuring the security... ...of our security posture, making our products safer and our customers' data more secure. A Day...Temporary work- ...collaborative; turn zerotoone ideas into real products, and you "get stuff done" end-to-... ...team Airwallex's Information Security team partners closely with engineering, IT, and other stakeholders to... ...a blocker. Your role As a Staff Product Security Engineer at...Worldwide
$200k - $275k
A leading financial technology company is looking for a security engineer to enhance product security and automate processes. Responsibilities include collaborating with product teams on security measures, conducting threat modeling and analysis, as well as reviewing source...Remote work- ...the team Airwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect... ...across the company—from secure product and infrastructure design to risk... ...treated as a blocker. Your role As a Staff Product Security Engineer at...
$180k - $247.5k
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building... ...'re building a world where Identity belongs to you. The Staff Product Security Engineer Opportunity The Security team's mission is to strengthen...Local areaWorldwideFlexible hours$225k - $275k
...hidden fees or compounding interest. Affirm values information security as a critical part of the company’s continued success. Our... ..., enabling the company to succeed in building honest financial products. The Security team posture increases security and reduces risk...Casual workWork at officeRemote workFlexible hours$250k - $285k
...Staff Product Security Engineer Crusoe is on a mission to accelerate the abundance of energy and intelligence. As the only vertically integrated AI infrastructure company built from the ground up, we own and operate each layer of the stack — from electrons to tokens...Temporary work$200k - $300k
...Staff+ Security Engineer, IT and Corporate Security San Mateo, CA United States Who We Are Verkada is transforming how organizations protect their people and places with an integrated, privacy-sensitive AI-powered platform that includes solutions for video security...Full timeWork visaFlexible hoursShift work- ...A leading identity verification company in San Francisco seeks a skilled Product Security Engineer. In this role, you'll drive the vulnerability lifecycle, design scalable security systems, and partner with engineers to ensure secure product development. Candidates should...Relocation package
$222k - $278k
...A code security company is looking for a Senior Security Engineer to enhance product security. This role involves collaborating with engineering teams to ensure secure application development and infrastructure management. Ideal candidates will have 7+ years of experience...Work at office- ...B Capital is looking for a Product Security Engineer to join our Salesforce product security advisors team. This role requires expertise in securing cloud platforms and deep technical knowledge of security practices. You will embed security controls throughout the SDLC...
- ...A tech-driven company in San Francisco seeks a Staff Software Engineer specializing in product security. This role requires 8+ years of experience and focuses on integrating security into AI platforms while collaborating across teams. The ideal candidate will drive security...
$210k - $230k
...process. About the Role: We're looking for a Senior Staff Security Engineer to lead Gusto's edge and network security strategy, owning... ...across the security org, partnering with infrastructure and product teams to make high-impact architectural decisions that compound...Full timeWork at officeLocal areaRemote work2 days per week3 days per week$127k - $249k
...We are hiring an experienced Security Software Engineer (Staff or Senior) for our Infrastructure Security team to design and build scalable security... ...and long‑term ownership Collaborate with SRE, platform and product engineering teams to define secure architectures for new...Work at officeLocal areaRemote workWorldwideFlexible hours- ...A leading tech company in San Francisco is seeking a Senior/Staff Application Security Engineer to ensure the security of its applications and infrastructure. The role involves integrating security into the software development lifecycle, conducting assessments, and mentoring...
$134.4k - $170.53k
...As the world's leading vendor of Cyber Security, facing the most sophisticated threats and... ...threats. As a Workspace Security Engineer, you'll be at the heart of our mission,... ...Responsibilities Responsible for delivery of product demonstrations Client Collaboration:...Temporary workLocal area- ...London offices. You’ll own application security at a company where the app layer is the... ...make the safe path the easy path for 50+ engineers Threat models for new features and architecture... ...found and fixed real vulnerabilities in production applications – not just run scanners...Remote workShift work
$180k - $250k
...Senior Offensive Security EngineerDescription -Who We AreHP IQ is HP’s new AI innovation lab. Combining startup agility... ....We’re assembling a diverse, world-class team—engineers, designers, researchers, and product minds—focused on creating an intelligent ecosystem across...Full timeTemporary workLocal areaRelocationFlexible hoursShift work$119.3k - $210k
...Full time Location Type Hybrid Department Engineering, product & design Compensation SF & NYC Base... ...with AI. About the role This is where security meets innovation at enterprise scale. As... ...platform) This role is open to Mid, Sr. and Staff level candidates Benefits & perks (US...Full timeWork at officeLocal areaFlexible hours$135k - $236.25k
...addresses. About The Role Rippling is looking for a hands‑on Security Engineer – Offensive Security to join our growing security team. In this... ...attacking and defending infrastructure with terraform Our Product Security Director talked about the Strategies to Scale Security...Work at office3 days per week$234.4k - $385k
...About the Team Security is at the foundation of OpenAI's mission to ensure that artificial... ...OpenAI's technology, people, and products. We are technical in what we build but are... ...About the Role As a Security Engineer, Application Security you will be responsible...Work at officeRemote workRelocation package
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Engineer - Product Security. Be the first to apply!
- assistant engineer South San Francisco, CA
- technology administrator South San Francisco, CA
- senior staff systems engineer South San Francisco, CA
- staff engineer South San Francisco, CA
- engineering aide South San Francisco, CA
- senior cloud security engineer South San Francisco, CA
- senior application security engineer South San Francisco, CA
- senior security operations engineer South San Francisco, CA
- aws cloud security engineer South San Francisco, CA
- graduate assistant engineering

