Staff Security Engineer, Psirt

Flock Safety Flock Safety · Enterprise · United States · Remote · Security

Staff Security Engineer, PSIRT Lead responsible for establishing and running Flock's Security Incident Response Team (PSIRT). This role will be the single point of accountability for all vulnerabilities, coordinating fixes across various engineering teams, and managing the Coordinated Vulnerability Disclosure (CVD) program. The role requires deep technical understanding across product security, with a focus on embedded/firmware security and Linux/Android device security, and strong operational experience with vulnerability management frameworks and disclosure processes. The position is an individual contributor role focused on influencing cross-functional teams and reducing risk for devices in the field and customers.

What you'd actually do

  1. Stand up and run Flock's Security Incident Response Team (PSIRT) as the single point of accountability for every externally-reported and internally-discovered vulnerability that touches a Flock product.
  2. Be the operational owner of our newly established CNA, the technical owner of our Coordinated Vulnerability Disclosure (CVD) program, and the cross-functional coordinator who drives fixes to closure across Hardware, Firmware, Device SRE, Cloud SRE, Mobile, ML, Legal, Comms, and Customer Support.
  3. Lead by influence across engineering, legal, communications, and support, setting the SLAs, the metrics, the playbooks, and the public security advisories that the rest of the company executes against.
  4. Manage response operations against established SLAs, tracking key metrics like time-to-triage, time-to-fix, and time-to-disclose, and deliver regular performance updates to leadership.

Skills

Required

  • Security Incident Response Team (PSIRT) leadership
  • Coordinated Vulnerability Disclosure (CVD) program management
  • CVE Numbering Authority (CNA) operations
  • Embedded/Firmware Security
  • Linux/Android Device Security
  • Cloud Security on AWS
  • Mobile/Web App Security
  • ML/CV Model Security
  • CVSS v3.1/v4.0, CWE, EPSS, SSVC frameworks
  • FIRST PSIRT Services Framework v1.1
  • ISO/IEC 29147, ISO/IEC 30111
  • CISA Binding Operational Directive 20-01
  • CJIS certification

Nice to have

  • Experience at a company that ships connected hardware (LPR/IP cameras, ICS/OT, automotive, medical, or networking gear)

What the JD emphasized

  • 7+ years in security engineering with at least 4 years directly running or leading a PSIRT, product security, or coordinated vulnerability disclosure function.
  • Experience at a company that ships connected hardware (LPR/IP cameras, ICS/OT, automotive, medical, or networking gear) is highly preferred.
  • Demonstrated end-to-end ownership of the FIRST PSIRT Services Framework v1.1 service areas (Stakeholder Ecosystem, Discovery, Triage, Remediation, Disclosure).
  • Hands-on operational experience acting as a CVE Numbering Authority (CNA) or leading the technical onboarding of one.
  • Deep knowledge of CNA Operational Rules v4.x, CVE scope definition, and root coordination (CISA ICS-CERT, MITRE).
  • Deep familiarity with ISO/IEC 29147 (disclosure), ISO/IEC 30111 (handling), the CERT/CC Guide to CVD, and CISA Binding Operational Directive 20-01.
  • Strong technical understanding across product security, with deep operational experience in at least three of the following (areas 1 and 2 are highly prioritized): Embedded/Firmware Security, Linux/Android Device Security, Cloud Security on AWS, Mobile/Web App Security, ML/CV Model Security.
  • Fluent with CVSS v3.1/v4.0, CWE classification, EPSS, and SSVC frameworks.
  • Ability to obtain and maintain CJIS certification as a condition of employment.