Senior Security Engineer - Threat Modeling

Samsara Samsara · Enterprise · CA · Remote · IT Security

Senior Security Engineer focused on threat modeling and vulnerability management within an enterprise environment. The role involves leading threat modeling programs, identifying and recommending mitigation for security risks, collaborating with engineering teams on vulnerability remediation, and participating in security incident investigations. Requires experience with security frameworks like OWASP, STRIDE, and MITRE ATT&CK, and coding skills in Python or GoLang. Experience with FedRAMP and security certifications are ideal.

What you'd actually do

  1. Lead and own ongoing operation and maintenance of Samsara’s threat modeling program, ensuring consistent execution of processes.
  2. Assist in detecting, raising risks found within the Samsara ecosystem, and recommending best next steps while balancing business needs.
  3. Work closely with the Vulnerability Technical Program Manager to generate and distribute monthly and quarterly compliance reports.
  4. Collaborate with engineering teams to track and support the remediation of identified vulnerabilities, providing guidance on best practices.
  5. Participate in security incident investigations related to high-profile vulnerabilities, helping gather data and assess potential impact on Samsara infrastructure.

Skills

Required

  • 6+ years of relevant experience with demonstrated impact for application or product security and threat modeling in an enterprise environment.
  • Deep familiarity with OWASP Top Ten, the STRIDE threat modeling framework (or equal such as PASTA or DREAD), MITRE ATT&CK.
  • Defining and driving SDLC adoption with business focused engineers.
  • Experience managing Bug Bounty programs such as Bug Crowd.
  • Strong familiarity with common security vulnerabilities and the ability to judge their severity and impact on the business.
  • Experience coding with Python or GoLang.

Nice to have

  • Security certifications such as CISSP, AWS Certified Security Specialty, or equal.
  • Experience and knowledge of FedRAMP and other regulatory security requirements.
  • Experience with Semgrep or Wiz.

What the JD emphasized

  • threat modeling
  • security
  • vulnerabilities
  • OWASP Top Ten
  • STRIDE threat modeling framework
  • MITRE ATT&CK
  • Python or GoLang
  • FedRAMP