Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Engineer

Namely

About Zipline

Zipline is the world’s largest and most experienced drone delivery service. We are on a mission to serve all humans equally by ensuring access to food, medicine and essential goods anytime, anywhere. We design, build, and operate the world’s largest autonomous logistics system, delivering critical supplies quickly and reliably. Today, Zipline operates on four continents, makes a delivery somewhere in the world every 30 seconds, and has completed millions of deliveries to date, including blood, vaccines, medical supplies, food, and retail products.

Our customers include the world’s largest and most prominent healthcare systems, governments, retailers, restaurants and global businesses who rely on us to save lives, reduce emissions, increase economic opportunity, and provide delivery from point A to point B as fast as possible. The drone is only 15% of what we’ve built to enable seamless, reliable, global operations.

Our system strengthens supply chains, reduces congestion, and gives people time back. With more than 140 million commercial autonomous miles safely flown, Zipline is redefining access to healthcare, consumer products, and food across the globe.

We operate at a global scale and are looking for practical problem solvers who thrive on real‑world challenges and rapid growth. Our team is motivated by building systems that have a direct, meaningful impact on people’s lives and by scaling the future of logistics. We are seeking people who sculpt from first principles, enjoy facing adversity, and can do the impossible at record‑breaking speeds.

About You and The Role

Product security at Zipline protects systems that directly affect safety, regulatory compliance, and uninterrupted delivery of critical goods in real‑world operational environments. You will own security for production services and integrations that run our fleet orchestration, distribution center automation, telemetry/teleoperation, and developer/operator toolchains. This role is mission‑critical: your work will reduce attack surface that could cause service outages, unsafe drone behavior, data exposure of patient/partner data, or regulatory failure.

You will join a small, high‑ownership security team and partner deeply with software, infrastructure, autonomy/embedded, and field‑ops teams. Expect hands‑on engineering work, prioritized ownership of specific services, and a mandate to ship controls that measurably reduce risk in production systems under operational pressure. This is a hybrid onsite role: you will be at our South San Francisco HQ frequently and must be available for occasional travel to distribution centers and test sites.

What You’ll Do
  • Own security outcomes for 2–4 named production areas (examples: fleet orchestration APIs, DC orchestration/robotics control plane, telemetry and command channels, developer CI/CD and secrets platforms). Be the primary security owner for at least one area on hire.
  • Deliver measurable risk reduction: define baseline metrics (e.g., mean‑time‑to‑detect, mean‑time‑to‑remediate, number of exploitable findings) and be accountable to improving them by defined targets in 6 and 12 months (example targets: cut exploitable high‑risk findings by 50% in owned services; reduce MTTD for critical alerts to <30m).
  • Design and implement production controls: IAM/least‑privilege policies, service‑to‑service trust, key lifecycle and KMS integrations, runtime telemetry and alerting, secure OTA/update patterns for edge devices, and hardened CI/CD pipelines and build artifact provenance.
  • Threat model and perform secure design reviews for services that operate near the physical fleet, regulated workflows, or partner/customer interfaces; produce engineering‑tractable mitigations and drive their rollout to completion.
  • Lead vulnerability management end‑to‑end for owned services: vulnerability triage with exploitability analysis, prioritized remediation plans with engineering partners, staged verification, and verification metrics for closure and regression prevention.
  • Build and harden incident response for product incidents: author playbooks, run tabletop exercises with product and operations, validate logging/auditability so incidents are forensic‑ready, and participate in incident postmortems with corrective action tracking.
  • Secure AI/agent‑assisted development and ops: define allowed copilots and patterns, implement guardrails to prevent secret exposure and unauthorized actions, and add monitoring/auditing for risky agent behaviors where it intersects owned systems.
  • Integrate external pentest and red‑team results into durable engineering changes; turn test findings into tracked engineering tickets and measurable closure criteria.
  • Collaborate daily with SREs, platform engineers, autonomy/embedded teams, field ops, and compliance to translate regulatory/safety requirements (e.g., health‑adjacent data handling, auditability) into concrete technical controls.
What You’ll Bring

Hard requirements (must‑haves):

  • 8+ years building and operating security controls for large‑scale production systems across application and cloud infrastructure.
  • Demonstrable hands‑on engineering ability: you ship automation or tooling in Python, Go, or similar and can build integrations with AI tools and agentic security bots (not only write policies).
  • Deep practical experience with cloud‑native stacks and microservices (Kubernetes, containers, IAM, CI/CD, secrets management, logging/telemetry) and with designing least‑privilege service‑to‑service models.
  • Prior ownership of vulnerability management, incident response playbooks, and verification processes for production services.
  • Direct experience threat‑modeling and securing systems that interface with physical systems, regulated workflows, or third‑party partners (embedded, teleoperation, field ops, or healthcare‑adjacent data flows).
  • Ability to define and track quantitative success metrics (MTTD, MTTR, number of exploitable findings, compliance audit readiness) and be accountable for meeting targets within 6–12 months.

Non‑negotiable traits:

  • Operates as a technical owner: can persuade engineering teams, prioritize trade‑offs, and drive changes through to production without relying solely on policy enforcement.
  • Skeptical, adversarial mindset: anticipates failure modes and abuse cases for systems that interact with the physical fleet and partner workflows.

Additional strong qualifications (if present):

  • Experience securing LLM/agentic tools in engineering workflows and mitigating OWASP LLM risks (prompt injection, unsafe plugin/output handling, agentic privilege misuse).
  • Background across multiple domains (cloud infra, web services, and embedded/autonomy) and experience building developer‑friendly security platforms or paved‑road tooling.
What Else You Need To Know

This is a hybrid role based in South San Francisco; frequent HQ presence required and occasional travel to field sites. This role has production ownership and will participate in incident response; candidates must be prepared for on‑call participation when assigned.

Zipline is an equal opportunity employer and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws or our own sensibilities.

We value diversity at Zipline and welcome applications from those who are traditionally underrepresented in tech.

Voluntary Self‑Identification

For government reporting purposes, we ask candidates to respond to the below self‑identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Zipline ’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

#J-18808-Ljbffr
Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Security Engineer in South San Francisco, CA vacancy
  •  ...Modernisation, and Industry-Specific Software Solutions, DXC modernises, secures, and operates some of the world’s most complex technology...  ...and New Zealand market, we are enhancing the Security Engineering Team who work within the Secured Infrastructure capacity to deliver... 
    Suggested
    Full time
    Local area

    DXC Technology

    Brisbane, CA
    3 days ago
  •  ...impossible at record breaking speeds.About You and The Role Product security at Zipline protects systems that directly affect safety,...  ...infrastructure, autonomy/embedded, and field-ops teams. Expect hands-on engineering work, prioritized ownership of specific services, and a... 
    Suggested
    Local area

    Zipline

    South San Francisco, CA
    5 days ago
  • $237.6k - $297k

    We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the... 
    Suggested
    Full time

    Scale AI

    San Francisco, CA
    3 days ago
  • $146.3k - $257.7k

     ...scalers to join us on our journey to create a better future of work with AI. About the roleThis is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you'll be building the security foundations that protect the AI systems... 
    Suggested
    Full time
    Work at office
    Local area

    Writer

    San Francisco, CA
    1 day ago
  • $208k - $312k

     ...products that help builders move from idea to production with speed, security, and exceptional developer experience.Now, software is entering...  ...what comes next.About the Role:We are looking for a Security Engineer to join our Detection Response team. In this role, you will be... 
    Suggested
    Work at office
    Remote work
    Work from home
    Worldwide
    Monday to Friday
    Flexible hours
    Shift work

    Vercel

    San Francisco, CA
    1 day ago
  •  ...rely on our best-in-class platform.Our Winning Culture is the engine that drives our teams of innovators. We champion diversity of thought...  ...welcome; join us and let’s build what’s next - together!As a Security Engineer III embedded within the Security Operations team, you... 
    Work at office

    Anaplan

    San Francisco, CA
    5 days ago
  • $230k - $390k

     ...effort, Project Starline, and Google Lens. Before that, Clay led the product and design teams for Google Workspace. Security EngineerSecurity Engineering builds the foundations that let Sierra deliver powerful AI agents while protecting customer data and trust. We partner... 
    Full time
    Flexible hours

    Sierra

    San Francisco, CA
    4 days ago
  • $153k - $376k

     ...together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us!As a Security Engineer you will identify and drive impactful projects to improve the security of Figma’s product, platform, and IT systems. We are... 
    Minimum wage
    Full time
    Local area
    Remote work
    Flexible hours

    Figma

    San Francisco, CA
    4 days ago
  • $266k - $385k

     ...that artificial general intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people, and products. We are...  ...engaging a robust security culture.About the RoleAs a Security Engineer on Detection & Response, you’ll help protect OpenAI’s most... 
    Work at office
    Local area
    Remote work
    Flexible hours

    OpenAI

    San Francisco, CA
    4 days ago
  • $146.3k - $257.7k

     ...scalers to join us on our journey to create a better future of work with AI. About the roleJoin WRITER's security team as a staff detection and response engineer and help protect the AI infrastructure that's transforming how the world works. You'll build sophisticated... 
    Full time
    Work at office
    Local area

    Writer

    San Francisco, CA
    1 day ago
  • $200k - $220k

     ...employees, their laptops, their identities, and the SaaS apps they rely on every day.We are looking for a hands-on Corporate Security Engineer to own and improve the technical controls that keep our workforce and corporate environment safe. This is a security engineering... 
    Work at office
    Local area

    Notion Labs

    San Francisco, CA
    4 days ago
  • $10 per hour

     ...impact business, society, and the environment? Come join us.All security disciplines work under the umbrella of the combined PSI (...  ...Infrastructure) team: we build the paved path and tooling that hundreds of engineers around the world rely on every day to ship. Corporate Security... 
    Work at office
    Immediate start
    Relocation
    Relocation package
    Flexible hours

    Flexport

    San Francisco, CA
    23 hours ago
  • $180k - $258k

     ...today!Curious to learn more about our story? Check out this blog post written by our founders. The RoleWe're looking for a Senior Security Engineer who is ready to elevate the safety and security of our systems and networks. You will serve as our guardian, ensuring our... 
    Flexible hours

    Candid Health

    San Francisco, CA
    4 days ago
  • $266k

     ...artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are...  ...engaging a robust security culture. About the RoleAs a Security Engineer, Application Security you will be responsible for identifying and... 
    Work at office
    Remote work
    Relocation package
    Flexible hours

    OpenAI

    San Francisco, CA
    3 days ago
  • $165k - $200k

     ...single API, Merge Agent Handler, which empowers AI agents with secure access to thousands of third-party tools, and Merge Gateway,...  ...product development, unblock sales, reduce customer churn, and save engineering resources—allowing them to focus on their core product.Merge... 
    Full time
    Work at office
    Home office

    Merge API

    San Francisco, CA
    5 days ago
  •  ...offices in New York, Washington D.C., London and Amsterdam.The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s...  ..., and aligned with industry and regulatory expectations. GRC Engineering is how we make all of that scale — turning compliance into code... 
    Work experience placement
    Work at office
    Local area
    Shift work

    Plaid Financial

    San Francisco, CA
    2 days ago
  • $183k - $247.6k

     ...underserved communities around the world.We are a specialized security team that sits inside a global satellite communications business...  ...mitigation plans- Experience in threat hunting, detection engineering, or product/application security, including moving from a security... 
    Permanent employment
    Local area
    Immediate start
    Flexible hours
    Shift work

    Amazon

    San Francisco, CA
    1 day ago
  • Hi, we're Oscar. We're hiring a Senior Product Security Engineer 1 to join our Security Team.Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving our members. We started Oscar in 2012 to create the kind... 
    Full time
    Work experience placement
    Work at office
    Remote work

    Oscar Health Insurance

    San Francisco, CA
    2 days ago
  •  ...Responsibilities Own security outcomes for two to four named production areas and serve as the primary security owner for at least...  ...Integrate penetration-test and red-team findings into tracked engineering changes with measurable closure criteria. Collaborate with... 
    Full time

    Zipline

    South San Francisco, CA
    13 days ago
  • $155k - $400k

     ...is building its AI-native future. About The Role The Security Team is responsible for securing all things Sentry: our customers...  ...to tackle hard security problems with creativity and an engineering mindset. We work at a company with a strong developer culture,... 
    Hourly pay

    Sentry

    San Francisco, CA
    4 days ago
  • $232k - $290k

     ...your impact and unlock incredible career growth opportunities, join us, and build real world value.THE WORK:As a Senior Staff Security Engineer focused on AI Security, you will be Ripple's deepest technical expert at the intersection of artificial intelligence and security... 
    Full time
    Work at office
    Local area

    Ripple

    San Francisco, CA
    1 day ago
  • $260k - $300k

     ...agents. We're the makers of Devin, the first AI software engineer. Our team is extremely talent-dense. Among our founding...  ...on real-world tasks, apply to join us. About the Role Security Engineers at Cognition own one of the most interesting security... 

    Cognition Corp

    San Francisco, CA
    2 days ago
  • $200k - $330k

     ...Customers Want, Winner's Mindset, and The Polymath Principle - shape how we work and grow as a team. About the Team The Security Engineering team at Decagon protects the platform that powers the most advanced conversational AI agents for enterprise customers across... 
    Full time
    Work at office
    Local area

    Decagon

    San Francisco, CA
    3 days ago
  •  ...our voice superintelligence.To achieve this, we need more great engineers. The work affects millions of people every day and our...  ...with you, please apply! The Role We're looking for a security engineer to build the systems and practices that keep our platform... 

    Giga AI Inc

    San Francisco, CA
    3 days ago
  • $100k - $180k

     ...Security Engineer We are looking for a highly motivated individual with information security experience who is willing to collaborate with others to build the best in class security program. As a Security Engineer at Hive, you will work to protect sensitive company... 
    Work experience placement

    Hive

    San Francisco, CA
    2 days ago
  •  ...Fortune 500 companies, and startups. We've raised $16M from top VCs and were YC W25. About the role We're looking for a Security Engineer to own and build HUD's security program as our first full-time security hire. You will work closely with the rest engineering... 
    Full time
    Work at office
    Relocation
    Visa sponsorship

    Human Union Data, Inc

    San Francisco, CA
    5 days ago
  •  ...PCT partners with venture-backed technology companies looking for Security Engineers to help build secure products, infrastructure, and organizations as they scale. Security roles across our portfolio may focus on product security, application security, cloud and... 

    People Culture Talent

    San Francisco, CA
    3 days ago
  •  ...About the Role This is a founding security hire at an early-stage AI/ML infrastructure company, giving you the opportunity to build...  ...and alert through investigation, postmortem, and durable engineering improvements. Own the security roadmap spanning product security... 
    Visa sponsorship
    Relocation package

    Clera

    San Francisco, CA
    5 days ago
  •  ...Description Upwind is a next-generation Cloud Security Platform that leverages runtime context to identify and prioritize critical...  ...meaningful impact on our growth. We are looking for a Security Engineer to join our MDR team as the founding U.S. member of the... 
    Night shift
    Weekend work

    Upwind Security

    San Francisco, CA
    5 days ago
  •  ...captivate, and inspire audiences. Learn more at Visit our Mission and Culture doc here. Position Summary As a Security Engineer at HeyGen, you will own the security posture of one of the fastest-growing AI companies in the world. You will partner... 

    HeyGen

    San Francisco, CA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Engineer. Be the first to apply!