Staff Software Engineer - Security

Skydio Skydio · Defense · San Mateo, CA +1 · R&D

Staff Software Engineer - Security role at Skydio, a US drone company focused on autonomous flight. The role involves designing, reviewing, and building systems to secure multi-tenant cloud and corporate environments, with a focus on architecture and hands-on engineering. Responsibilities include reviewing RFCs, shaping system design, building internal security tooling (e.g., WAFs, vulnerability risk management), hardening production software, partnering with Compliance on technical controls for regulations like FedRAMP and SOC 2, improving vulnerability management, and contributing to authentication/identity systems.

What you'd actually do

  1. Review RFCs and partner with engineering teams on architectural decisions that have security implications
  2. Design and build internal security systems end to end, including roadmap areas such as web application firewalls and vulnerability risk management tooling
  3. Harden and improve security-related production software components as opportunities for better resilience and protection are identified
  4. Partner with Compliance to translate FedRAMP, SOC 2, Texas RAMP, ISO 27001, and CJIS requirements into practical technical controls
  5. Improve how we monitor, prioritize, patch, and respond to vulnerabilities across our cloud footprint

Skills

Required

  • 7+ years of experience in cloud security, platform security, infrastructure security, or a related security-focused engineering role
  • Strong experience working in AWS, ideally in multi-tenant cloud environments
  • Strong coding ability and comfort building and maintaining tooling in languages such as Python or Go
  • Experience reviewing system designs and RFCs and providing clear, actionable security guidance
  • Working knowledge of SIEM, vulnerability management, and related security tooling
  • Comfort operating across both technical design and hands-on implementation in a role that spans both strategy and execution

Nice to have

  • Experience working in FedRAMP, SOC 2, ISO 27001, Texas RAMP, or CJIS-aligned environments
  • Experience building or deeply integrating authentication and identity systems, including SSO, SCIM, and front-door authentication
  • Experience with Kubernetes debugging, operations, or automation
  • Background supporting government, defense, or other highly regulated customers

What the JD emphasized

  • security
  • cloud security
  • platform security
  • infrastructure security
  • AWS
  • multi-tenant cloud environments
  • Python
  • Go
  • SIEM
  • vulnerability management
  • FedRAMP
  • SOC 2
  • Texas RAMP
  • ISO 27001
  • CJIS