Senior Security Engineer - Threat Modeling

Samsara Samsara · Enterprise · CA · Remote · IT Security

Senior Security Engineer focused on threat modeling and vulnerability management within an enterprise environment. The role involves leading threat modeling operations, identifying and recommending mitigation for security risks, collaborating with engineering teams on vulnerability remediation, and participating in incident investigations. Requires experience with security frameworks like OWASP and STRIDE, SDLC adoption, bug bounty programs, and coding in Python or GoLang. Experience with FedRAMP and security certifications are ideal.

What you'd actually do

  1. Lead and own ongoing operation and maintenance of Samsara’s threat modeling program, ensuring consistent execution of processes.
  2. Assist in detecting, raising risks found within the Samsara ecosystem, and recommending best next steps while balancing business needs.
  3. Work closely with the Vulnerability Technical Program Manager to generate and distribute monthly and quarterly compliance reports.
  4. Collaborate with engineering teams to track and support the remediation of identified vulnerabilities, providing guidance on best practices.
  5. Participate in security incident investigations related to high-profile vulnerabilities, helping gather data and assess potential impact on Samsara infrastructure.

Skills

Required

  • Application security
  • Product security
  • Threat modeling
  • OWASP Top Ten
  • STRIDE threat modeling framework
  • MITRE ATT&CK
  • SDLC adoption
  • Bug Bounty programs
  • Python
  • GoLang

Nice to have

  • CISSP
  • AWS Certified Security Specialty
  • FedRAMP
  • Semgrep
  • Wiz

What the JD emphasized

  • threat modeling
  • OWASP Top Ten
  • STRIDE threat modeling framework
  • MITRE ATT&CK
  • common security vulnerabilities
  • FedRAMP