Talent.com
Staff Security Engineer - Product Security
Staff Security Engineer - Product SecurityZipline • South San Francisco, California, USA
Staff Security Engineer - Product Security

Staff Security Engineer - Product Security

Zipline • South San Francisco, California, USA
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

About You and The Role

Zipline builds and operates fleets of delivery drones to get medicine to those who need it, fast, regardless of where they live. To power this, the software team is building out the long term scalable solutions to expand rapidly while empowering our world class distribution centers to serve their customers as fast as possible. Zipline’s security problems aren’t “website got pwned” problems (though those exist too). They’re “real-world autonomy + robotics + global operations + cloud software + regulated/health-adjacent workflows” problems. You’ll partner deeply with software, infrastructure, and (where relevant) embedded/autonomy teams to reduce real risk in real systems. We have a large attack surface Our ideal candidate works well in startup environments, wears many hats, and collaborates across engineering disciplines. You’ll join a small, high-ownership security team with significant influence over how we scale. A note on our modern reality and agentic tooling: Engineering teams are increasingly adopting LLM copilots and agentic tools to move faster. That’s useful, until an “assistant” becomes an unmonitored automation path to secrets, sensitive data, or privileged actions. (Think: “obedient intern with production credentials.”) Industry guidance is converging on practical frameworks like the NIST AI Risk Management Framework (including a profile for generative AI) and the OWASP Top 10 for LLM Applications, which explicitly calls out risks like prompt injection, insecure plugin design, and excessive agency. In this role, you’ll help Zipline safely leverage these tools while containing them so they don’t quietly “rewrite the threat model”. This is a Hybrid onsite role - you will frequently have conversations in person at our HQ in South San Francisco. What You'll Do Own security outcomes for critical parts of Zipline’s application and cloud ecosystem (not by writing policy docs that no one reads, but by shipping controls and enabling teams). Partner with engineering teams on secure architecture, threat modeling, and design reviews for services that must be correct, reliable, and defensible under real-world operational pressure. Help us build and scale a pragmatic secure SDLC – CI/CD hardening, dependency/supply-chain controls, secrets management, and code review patterns that don’t slow teams down. Improve cloud security posture end-to-end: IAM and least privilege, network/service-to-service trust, key management, logging/telemetry, runtime detection, and incident-ready auditability. Drive vulnerability management that actually closes risk: triage, exploitability analysis, remediation partnerships, and verification. Help build and exercise incident response: playbooks, tabletop exercises, logging requirements, and “know it happened / know what changed” operational discipline. Support data classification and access control models aligned to how Zipline operates (including partner/customer interfaces and global operations). Support external penetration tests and turn results into durable improvements, not whack‑a‑mole patches. Contribute to security compliance efforts (e.g., SOC 2 / ISO 27001) in a way that strengthens engineering Secure AI-assisted and agentic engineering workflows (this is explicitly part of the job): define safe patterns for copilots/LLM tools used in development and ops implement guardrails for sensitive data exposure and output handling prevent “agentic overreach” (over‑privileged tools, unsafe tool-calling, silent action-taking) build monitoring/auditing around AI tool use where it matters What You'll Bring 8+ years of experience designing, building, and operating security controls for large-scale production systems (application, cloud, and infrastructure security). Strong security engineering chops with evidence you can reduce risk in production systems (not just talk about it). Hands-on ability to write and ship code/tools in Python, Go, or similar (you’re expected to build, not just review). Practical experience securing microservice architectures and modern cloud stacks (containers/Kubernetes, IAM, CI/CD, secrets, logging). Comfort operating as a technical leader without authority: you can persuade, teach, and unblock - not police. A skeptical mindset: you naturally ask “what’s the failure mode?” and “how will this be abused?” before shipping changes. Familiarity with the security failure modes of LLM-enabled systems (or the willingness to learn fast), including risks called out by OWASP such as prompt injection, insecure output handling, insecure plugin design, and excessive agency. Nice To Haves Experience spanning multiple engineering domains (web app + cloud infra + embedded/robotics/autonomy). Experience building developer-friendly security platforms (internal libraries, paved roads, CI integrations, Public Key Infrastructure). Track record of being an effective security “evangelist” (i.e., enabling good behavior with good tools and defaults, not fear). Experience designing guardrails for internal AI/agent usage (policy + technical controls + auditing), especially in environments where safety and reliability are non-negotiable. Deep understanding of distributed systems and how failures actually happen (partial outages, weird retries, cascading dependencies, misconfigurations, permissions drift). What Else to Know This will be an in-office or hybrid role based out of our South San Francisco HQs. The starting cash range for this role is $230,000 - $275,000; please note that this is a target, starting cash range for a candidate who meets the minimum qualifications for this role. We are always open to negotiation. The final cash pay for this role will depend on a variety of factors, including a specific candidate's experience, qualifications, skills, working location, and projected impact. The total compensation package for this role may also include: equity compensation; overtime pay; discretionary annual or performance bonuses; sales incentives; benefits such as medical, dental and vision insurance; paid time off; and more. Zipline is an equal opportunity employer and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws or our own sensibilities.
[job_alerts.create_a_job]

Staff Security Engineer - Product Security • South San Francisco, California, USA

[internal_linking.similar_jobs]
Staff+ Product Security Engineer

Staff+ Product Security Engineer

Verkada • San Mateo, CA, United States
[job_card.full_time]
Designed with simplicity in mind, Verkada's six product lines — video security cameras, access control, environmental sensors, alarms, workplace, and intercoms — provide unparalleled building secur...[show_more]
[last_updated.last_updated_30] • [promoted]
Staff Product Security Engineer

Staff Product Security Engineer

Code Red Partners • San Francisco, CA, United States
[job_card.full_time]
Code Red is partnered with a unicorn FinTech in SF to bring on a.Staff Product Security Engineer.This will be a foundational hire within a small, high‑impact security org that supports a global org...[show_more]
[last_updated.last_updated_30] • [promoted]
Senior Security Engineer

Senior Security Engineer

Qualified • San Francisco, CA, United States
[job_card.full_time]
Qualified is the Agentic Marketing Platform for B2B companies.With Piper the AI SDR Agent, Qualified offers a whole new way to grow inbound pipeline.Piper operates across both the website and email...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Security Engineer, Application Security

Security Engineer, Application Security

OpenAI • San Francisco, CA, United States
[job_card.full_time]
Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all of humanity.The Security team protects OpenAI's technology, people, and products.We are...[show_more]
[last_updated.last_updated_30] • [promoted]
Staff Offensive Security Engineer

Staff Offensive Security Engineer

Robinhood • Menlo Park, CA, United States
[job_card.full_time]
Join us in building the future of finance.Our mission is to democratize finance for all.An estimated $124 trillion of assets will be inherited by younger generations in the next two decades.The lar...[show_more]
[last_updated.last_updated_30] • [promoted]
Staff Software Engineer, Platform Security

Staff Software Engineer, Platform Security

Discord • San Francisco, CA, United States
[job_card.full_time]
Discord is used by over 200 million people every month for many different reasons, but there’s one thing that nearly everyone does on our platform:.Over 90% of our users play games, spending a comb...[show_more]
[last_updated.last_updated_30] • [promoted]
Product Security Engineer - AI

Product Security Engineer - AI

Crusoe Energy Systems LLC • San Francisco, CA, United States
[job_card.full_time]
Crusoe's mission is to accelerate the abundance of energy and intelligence.We’re crafting the engine that powers a world where people can create ambitiously with AI — without sacrificing scale, spe...[show_more]
[last_updated.last_updated_variable_hours] • [promoted] • [new]
Staff Product Security Engineer - Flexible Time Off

Staff Product Security Engineer - Flexible Time Off

worldcoin.org • San Francisco, CA, United States
[job_card.full_time]
A tech company seeks a Product Security Engineer to safeguard products and services powering their innovative network.The role requires at least 12 years of experience in Product or Application Sec...[show_more]
[last_updated.last_updated_30] • [promoted]
Product Security Engineer

Product Security Engineer

Chime • San Francisco, CA, United States
[job_card.full_time]
We are looking for an early-career Security Engineer to join our Product Security team, someone who has a builder’s mindset, is eager to learn, and is excited to contribute to both planned initiati...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Staff Security Engineer — Hybrid, Security Architecture Leader

Staff Security Engineer — Hybrid, Security Architecture Leader

Forge • San Francisco, CA, United States
[job_card.full_time]
A leading technology firm in San Francisco is searching for a Staff Security Engineer to tackle complex security challenges and develop best-in-class solutions.This role demands exceptional communi...[show_more]
[last_updated.last_updated_30] • [promoted]
Lead Security Engineer

Lead Security Engineer

Anyscale • San Francisco, CA, United States
[job_card.full_time]
At Anyscale, we're on a mission to democratize distributed computing and make it accessible to software developers of all skill levels.We’re commercializing Ray, a popular open-source project that'...[show_more]
[last_updated.last_updated_30] • [promoted]
Senior/Staff Application Security Engineer

Senior/Staff Application Security Engineer

Abridge • San Francisco, CA, United States
[job_card.full_time]
Abridge was founded in 2018 with the mission of powering deeper understanding in healthcare.Our AI-powered platform was purpose-built for medical conversations, improving clinical documentation eff...[show_more]
[last_updated.last_updated_30] • [promoted]
Staff Engineer, Infrastructure Security

Staff Engineer, Infrastructure Security

Poshmark, Inc. • Redwood City, CA, United States
[job_card.full_time]
Confidence can sometimes hold us back from applying for a job.Here’s a secret: there's no such thing as a "perfect" candidate.Poshmark is looking for exceptional people who want to make a positive ...[show_more]
[last_updated.last_updated_30] • [promoted]
Staff Security Engineer, TDI Okta

Staff Security Engineer, TDI Okta

Isc2 Eastbay Chapter • San Francisco, CA, United States
[job_card.full_time]
Okta is The World’s Identity Company.We free everyone to safely use any technology, anywhere, on any device or app.Our flexible and neutral products, Okta Platform and Auth0 Platform, provide secur...[show_more]
[last_updated.last_updated_30] • [promoted]
Staff Security Engineer

Staff Security Engineer

Uber • San Francisco, CA, United States
[job_card.full_time]
As a Staff Security Engineer, you will be the lead architect for Uber's next-generation cloud security infrastructure.Operating at the intersection of Cloud Architecture and Applied AI, you will mo...[show_more]
[last_updated.last_updated_30] • [promoted]
Product Security Engineer - Lead Secure by Design

Product Security Engineer - Lead Secure by Design

Headway • San Francisco, CA, United States
[job_card.full_time]
A leading mental health technology company is seeking a Security Engineer to ensure the secure design and development of applications.The role involves partnering with product and engineering teams...[show_more]
[last_updated.last_updated_30] • [promoted]
Senior Anti-Abuse Security Engineer, Product Security

Senior Anti-Abuse Security Engineer, Product Security

Snowflake • Menlo Park, CA, United States
[job_card.full_time]
Senior Anti-Abuse Security Engineer, Product Security.Senior Anti-Abuse Security Engineer, Product Security.Snowflake is about empowering enterprises to achieve their full potential — and people to...[show_more]
[last_updated.last_updated_30] • [promoted]
Security Engineer for AI-Powered Platform

Security Engineer for AI-Powered Platform

Sierra Business Solution • San Francisco, CA, United States
[job_card.full_time]
A innovative tech company in San Francisco is seeking a Software Engineer, Security to build secure systems and enhance customer experiences powered by AI.The role involves designing trust framewor...[show_more]
[last_updated.last_updated_variable_days] • [promoted]