Senior Application Security Engineer (ai & Vulnerability)

Samsara Samsara · Enterprise · United Kingdom · Remote · IT Security

Senior Security Engineer role focused on operating and maintaining vulnerability management platforms, refining detection, collaborating with engineering teams on remediation, and analyzing/triaging vulnerabilities. Requires experience with vulnerability tooling (Wiz, Semgrep), security engineering best practices, Python/GoLang, DevOps/DevSecOps/SRE, AWS, Terraform, and SAST/DAST/SCA. Experience in FedRAMP environments is ideal.

What you'd actually do

  1. Lead and own ongoing operation and maintenance of Samsara’s vulnerability management program, ensuring consistent execution of processes.
  2. Assist in managing vulnerability scanning tools and help refine detection capabilities to improve accuracy and reduce false positives.
  3. Work closely with the Vulnerability Technical Program Manager to generate and distribute monthly and quarterly compliance reports.
  4. Collaborate with engineering teams to track and support the remediation of identified vulnerabilities, providing guidance on best practices.
  5. Assist in analyzing and triaging vulnerabilities, escalating critical issues to senior security engineers or Security Operations as needed.

Skills

Required

  • 6+ years of relevant experience with demonstrated impact for security engineering and vulnerability management in an enterprise environment.
  • Significant experience with vulnerability management tooling, in particular modern toolsets such as Wiz, or Semgrep.
  • Deep subject matter expertise with security engineering best practices for subjects such as CVSS, EPSS.
  • Strong familiarity with common security vulnerabilities and the ability to judge their severity and impact on the business.
  • Excellent development background with experience in Python or GoLang.
  • Strong DevOps, DevSecOps, or SRE background with experience in AWS cloud services, and Terraform
  • Experience using security automation platforms such as Tines and serverless frameworks such as AWS Lambda.
  • Deep understanding of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), or Software Composition Analysis (SCA)

Nice to have

  • Practical experience managing vulnerabilities within a FedRAMP-certified environment.
  • Experience integrating vulnerability management into modern CI/CD pipelines with a “shift-left” mentality.

What the JD emphasized

  • modern Vulnerability Management platforms
  • vulnerability management
  • software vulnerabilities
  • security and compliance strategy
  • vulnerability management program
  • vulnerability scanning tools
  • compliance reports
  • remediation of identified vulnerabilities
  • analyzing and triaging vulnerabilities
  • high-profile vulnerabilities
  • vulnerability management workflows
  • vulnerability management tooling
  • modern toolsets
  • security engineering best practices
  • common security vulnerabilities
  • security automation platforms
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Software Composition Analysis (SCA)
  • vulnerability management into modern CI/CD pipelines