Staff+ Security Engineer, Developer Tools

Verkada Verkada · Enterprise · Bayoffice · Security

Verkada is seeking a Staff+ Security Engineer to join their Developer Tools team. This role will focus on integrating security throughout the SDLC, performing threat modeling, security design reviews, and refining security tools. The engineer will also define the security roadmap and requirements for tools, AI agents, and systems, and will be responsible for creating and operating a bug bounty program. The role requires strong experience in security engineering, cloud providers, and various security practices, with the ability to write production code in Python/Go.

What you'd actually do

  1. Facilitate the security baked into our applications throughout the software development lifecycle
  2. Evangelize software security best practices through training and information sharing
  3. Partner closely with engineering and product teams to improve the security of Verkada’s products and exceed customers’ expectations
  4. Explore innovative solutions to enable Verkada business instead of “Security says No”
  5. Collaborate with other engineering leaders to define, communicate, and execute on goals, priorities and process

Skills

Required

  • Bachelor of Science in Computer Science degree or equivalent
  • Strong experience with AWS, GCP or other cloud service provider
  • 7+ years of experience as a security engineer, software engineer, site reliability engineer, or security consultant
  • Understanding of security weaknesses, exploits, attacks and mitigations
  • Coding ability. You will sometimes write production Python/Go code, security peer review code, build proofs of concept or implement automation scripts
  • Excellent collaborative skills
  • Outstanding written and verbal communication
  • Security Development Lifecycle
  • Threat Modeling
  • Architecture Analysis
  • Technical Design Review
  • Security Code Review
  • Open Policy Agent
  • SIEM

Nice to have

  • Experience and enthusiasm for learning about new security products, features, and strategies

What the JD emphasized

  • security throughout the SDLC
  • security roadmap
  • security tools
  • AI agents
  • security design reviews
  • threat modeling
  • security bugs
  • security program
  • security conferences
  • security reasoning
  • security engineer
  • security consultant
  • security weaknesses
  • security products
  • security peer review
  • Security Development Lifecycle
  • Threat Modeling
  • Architecture Analysis
  • Technical Design Review
  • Security Code Review
  • Open Policy Agent
  • SIEM