Staff Security Engineer

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Redpanda Data

Redpanda Data

51 - 200 employees

Founded 2019

🏢 Enterprise

☁️ SaaS

🤝 B2B

💰 $100M Series D - Redpanda Data on 2025-04

Enterprise • SaaS • B2B

Redpanda Data is the company behind Redpanda, a high-performance streaming data platform compatible with the Apache Kafka API. Redpanda provides a single-binary, low-latency, high-throughput message streaming engine and managed cloud offerings designed as a drop-in replacement for Kafka to simplify real-time data pipelines, event-driven applications, logs, and metrics. The company focuses on delivering enterprise-grade streaming infrastructure for developer and operations teams via self-managed software and managed SaaS/cloud services.

📋 Description

• Own and scale application security across Redpanda’s C++ core streaming engine, Go cloud control plane, Console, and Rust/Go data-transform SDKs • Lead threat modeling and secure design reviews for new product features • Own and tune SAST, SCA/dependency scanning, secret scanning, and DAST across C++, Go, and Rust • Build coverage-guided and protocol-aware fuzzing harnesses for the core engine and integrate sanitizers • Conduct secure code reviews in systems languages and eradicate classes of vulnerabilities • Operate PSIRT and coordinated vulnerability disclosure, including triaging researcher reports, driving fixes, and publishing advisories and CVEs • Strengthen software supply-chain security through dependency hygiene, SBOMs, build provenance, and SLSA progress • Establish a security champions program and secure-by-default libraries, patterns, and guardrails • Define security requirements and shape security release gates • Advise on authentication, authorization/RBAC, encryption, audit logging, multi-tenant isolation, and the Agentic Data Plane • Raise security standards through training, pragmatic standards, hands-on engineering partnership, and AI-assisted development workflows • Partner with the Director of Information Security, infrastructure security engineer, platform engineering, and product engineering teams

🎯 Requirements

• 7+ years in application security, product security, or adjacent specialties • Track record of owning AppSec initiatives end-to-end and influencing engineering teams without direct authority • Ability to review and reason about code in a systems language; C++ or Rust strongly preferred and Go valuable • Strong understanding of memory safety, concurrency, use-after-free, buffer overflow, injection, and authorization flaws • Comfort with security risks of memory-unsafe code and willingness to fuzz it • Practical proficiency with SAST, SCA, secret scanning, and DAST • Experience leading threat modeling and secure design reviews for non-trivial systems • Working knowledge of dependencies, SBOMs, signing, SLSA, and secure CI/CD • Familiarity with AWS, GCP, or Azure and Kubernetes security at the application layer • Excellent written and verbal communication skills • Comfort working in a globally distributed, async environment • Fuzzing with libFuzzer, AFL++, or OSS-Fuzz and sanitizers such as ASan, UBSan, or MSan is a plus • Background securing distributed systems, databases, or data-infrastructure products is a plus • PSIRT, CNA, bug bounty, or coordinated disclosure experience is a plus • Exposure to SOC 2, ISO 27001, HIPAA, or FedRAMP compliance programs is a plus • Open-source security contributions or public repository vulnerability-handling experience is a plus

🏖️ Benefits

• Salary ranges determined by role, level, and location • Individual base salary consideration based on job-related skills, location, experience, relevant education or training • Latest AI tools and budget to use them • People-first organization • Culture based on trust, transparency, communication, and kindness • Diverse, global team

Apply Now

Similar Jobs

🔥 8 minutes ago

Brown Medicine

201 - 500

🏥 Healthcare

📚 Education

🔬 Science

Principal Security Architect securing Brown University Health’s hybrid and multi-cloud healthcare environments. Governing identity, data, network, AI, and enterprise security architecture.

🔥 2 hours ago

Trulieve

5001 - 10000

🏥 Healthcare

🍽️ Food & Beverage

⚕️ Healthcare Insurance

Director of Security protecting Trulieve’s cannabis operations across regional U.S. facilities. Leading security managers, risk programs, incident response, and safety strategy with up to 50% regional travel.

🔥 4 hours ago

Luna Physical Therapy

1001 - 5000

🏥 Healthcare

💼 Consulting

⚕️ Healthcare Insurance

Director leading Luna's cybersecurity, IT operations, and healthcare technology programs. Safeguarding sensitive patient information and scaling secure systems within a HIPAA-regulated physical therapy company.

🕒 2 days ago

Beshenich Muir & Associates

51 - 200

🎖️ Defense

🚀 Aerospace

🏛️ Government

R&D Cybersecurity Engineer supporting DLA Okta environments and government information systems. Administering secure infrastructure, automation, maintenance, networking, and technical support.

🕒 2 days ago

Optiv

1001 - 5000

Principal AI cybersecurity advisor designing scalable security solutions for Optiv, a company managing cyber risk. Driving AI security strategy, thought leadership, and services sales for enterprise clients.