Talent.com
Zipline
Staff Security Engineer - Product SecurityZipline • South San Francisco, California, USA
Staff Security Engineer - Product Security

Staff Security Engineer - Product Security

Zipline • South San Francisco, California, USA
30+ days ago
Job type
  • Full-time
Job description

About You and The Role

Zipline builds and operates fleets of delivery drones to get medicine to those who need it, fast, regardless of where they live. To power this, the software team is building out the long term scalable solutions to expand rapidly while empowering our world class distribution centers to serve their customers as fast as possible. Zipline’s security problems aren’t “website got pwned” problems (though those exist too). They’re “real-world autonomy + robotics + global operations + cloud software + regulated/health-adjacent workflows” problems. You’ll partner deeply with software, infrastructure, and (where relevant) embedded/autonomy teams to reduce real risk in real systems. We have a large attack surface Our ideal candidate works well in startup environments, wears many hats, and collaborates across engineering disciplines. You’ll join a small, high-ownership security team with significant influence over how we scale. A note on our modern reality and agentic tooling: Engineering teams are increasingly adopting LLM copilots and agentic tools to move faster. That’s useful, until an “assistant” becomes an unmonitored automation path to secrets, sensitive data, or privileged actions. (Think: “obedient intern with production credentials.”) Industry guidance is converging on practical frameworks like the NIST AI Risk Management Framework (including a profile for generative AI) and the OWASP Top 10 for LLM Applications, which explicitly calls out risks like prompt injection, insecure plugin design, and excessive agency. In this role, you’ll help Zipline safely leverage these tools while containing them so they don’t quietly “rewrite the threat model”. This is a Hybrid onsite role - you will frequently have conversations in person at our HQ in South San Francisco. What You'll Do Own security outcomes for critical parts of Zipline’s application and cloud ecosystem (not by writing policy docs that no one reads, but by shipping controls and enabling teams). Partner with engineering teams on secure architecture, threat modeling, and design reviews for services that must be correct, reliable, and defensible under real-world operational pressure. Help us build and scale a pragmatic secure SDLC – CI/CD hardening, dependency/supply-chain controls, secrets management, and code review patterns that don’t slow teams down. Improve cloud security posture end-to-end: IAM and least privilege, network/service-to-service trust, key management, logging/telemetry, runtime detection, and incident-ready auditability. Drive vulnerability management that actually closes risk: triage, exploitability analysis, remediation partnerships, and verification. Help build and exercise incident response: playbooks, tabletop exercises, logging requirements, and “know it happened / know what changed” operational discipline. Support data classification and access control models aligned to how Zipline operates (including partner/customer interfaces and global operations). Support external penetration tests and turn results into durable improvements, not whack‑a‑mole patches. Contribute to security compliance efforts (e.g., SOC 2 / ISO 27001) in a way that strengthens engineering Secure AI-assisted and agentic engineering workflows (this is explicitly part of the job): define safe patterns for copilots/LLM tools used in development and ops implement guardrails for sensitive data exposure and output handling prevent “agentic overreach” (over‑privileged tools, unsafe tool-calling, silent action-taking) build monitoring/auditing around AI tool use where it matters What You'll Bring 8+ years of experience designing, building, and operating security controls for large-scale production systems (application, cloud, and infrastructure security). Strong security engineering chops with evidence you can reduce risk in production systems (not just talk about it). Hands-on ability to write and ship code/tools in Python, Go, or similar (you’re expected to build, not just review). Practical experience securing microservice architectures and modern cloud stacks (containers/Kubernetes, IAM, CI/CD, secrets, logging). Comfort operating as a technical leader without authority: you can persuade, teach, and unblock - not police. A skeptical mindset: you naturally ask “what’s the failure mode?” and “how will this be abused?” before shipping changes. Familiarity with the security failure modes of LLM-enabled systems (or the willingness to learn fast), including risks called out by OWASP such as prompt injection, insecure output handling, insecure plugin design, and excessive agency. Nice To Haves Experience spanning multiple engineering domains (web app + cloud infra + embedded/robotics/autonomy). Experience building developer-friendly security platforms (internal libraries, paved roads, CI integrations, Public Key Infrastructure). Track record of being an effective security “evangelist” (i.e., enabling good behavior with good tools and defaults, not fear). Experience designing guardrails for internal AI/agent usage (policy + technical controls + auditing), especially in environments where safety and reliability are non-negotiable. Deep understanding of distributed systems and how failures actually happen (partial outages, weird retries, cascading dependencies, misconfigurations, permissions drift). What Else to Know This will be an in-office or hybrid role based out of our South San Francisco HQs. The starting cash range for this role is $230,000 - $275,000; please note that this is a target, starting cash range for a candidate who meets the minimum qualifications for this role. We are always open to negotiation. The final cash pay for this role will depend on a variety of factors, including a specific candidate's experience, qualifications, skills, working location, and projected impact. The total compensation package for this role may also include: equity compensation; overtime pay; discretionary annual or performance bonuses; sales incentives; benefits such as medical, dental and vision insurance; paid time off; and more. Zipline is an equal opportunity employer and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws or our own sensibilities.
Create a job alert for this search

Staff Security Engineer - Product Security • South San Francisco, California, USA

Similar jobs

Lead Security Engineer - DevSecOps & Platform Resilience

CoderabbitSan Francisco, CA, United States
Full-time

An innovative tech company in San Francisco is seeking a Lead Security Engineer to architect, harden, and defend its infrastructure.In this role, you'll lead security initiatives and embed security... Show more

 • Promoted

Senior Security Architect

TradeJobsWorkForce94706 Albany, CA, US
Full-time

Senior Security Architect Job Duties: Enhances security team accomplishments and competence by planning deliver... Show more

 • Promoted

Staff+ Product Security Engineer

VerkadaSan Mateo, CA, United States
Full-time

StaffProduct Security EngineerVerkada is transforming how organizations protect their people and places with an integrated, AI-powered platform.A leader in cloud physical security, Verkada helps or... Show more

 • Promoted

Remote Corporate Security Engineer (Senior / Staff)

P2PSan Francisco, CA, United States
Remote
Full-time

A leading technology company is searching for a Senior / Staff Security Engineer to enhance the security of its corporate infrastructure.This role involves designing and managing security for corpo... Show more

 • Promoted

Security Engineer

Corridor Security IncSan Francisco, CA, United States
Full-time

Security EngineerAI has changed software development.Security hasn't caught up until now.Corridor is changing the game of product security, giving developers the ability to secure their AI coding.O... Show more

 • Promoted

Product Security Engineer INTL India

Insight GlobalSan Francisco, CA, United States
Full-time

Product Security EngineerInsight Global is seeking a Product Security Engineer to join a leading global enterprise software company known for its cloud-based solutions that help businesses manage c... Show more

 • Promoted

Aerospace Engineer

TradeJobsWorkforce94707 Berkeley, CA, US
Full-time

Aerospace Engineer Job Duties: Contributes to the design, manufacturing, and testing of aircraft and a... Show more

 • Promoted

Security Professional Flex Officer

Allied UniversalVallejo, CA, United States
Part-time

Company Overview: Allied Universal®, North America's leading security and facility services company, offers rewarding careers that provide you a sense of purpose.While working in a dynamic, welcom... Show more

 • Promoted

Offensive Security Engineer, Agent Security

OpenAISan Francisco, CA, United States
Full-time

Principal-Level Offensive Security EngineerSecurity is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all of humanity.The Security team protects OpenA... Show more

 • Promoted

Senior Security Engineer

BeaconAISan Carlos, CA, United States
Full-time +1

Lead Security Software EngineerWe're a fast-moving team of aviators, engineers, and operators building an AI platform to make flying safer, more efficient, and more capable.Backed by top investors,... Show more

 • Promoted

Electrical Engineer, Principal

PG&E CorporationBERKELEY, California, US
Full-time

Job Category: Engineering / Science .Business Unit: Energy Delivery.Job Location: Oakland; Alameda; Alta; American Canyon; Angels Camp; Antioch; Auberry; Auburn; Avenal; Avila Beach; Bakersfield; B... Show more

 • Promoted

Staff Product Manager, Security

PostmanSan Francisco, CA, United States
Full-time

Who Are We?Postman is the world's leading API platform, used by more than 45 milliondevelopers and 500,000 organizations, including 98% of the Fortune 500.Postman is helping developers and professi... Show more

 • Promoted

Senior Security Engineer (Detection & Response)

ScribdSan Francisco, CA, United States
Full-time

Senior Security Engineer Focused on Detection & ResponseThe Infrastructure Security team at Scribd is responsible for protecting our applications, platforms, and users through proactive, engine... Show more

 • Promoted

Security Engineer II, Offensive Security

RipplingSan Francisco, CA, United States
Full-time

Security Engineer Offensive SecurityRippling is looking for a hands-on Security Engineer Offensive Security to join our growing security team.In this role, you'll design and execute offensive secur... Show more

 • Promoted

Security Engineer

SierraSan Francisco, CA, United States
Full-time

Security LeadAt Sierra, we're creating a platform to help businesses build better, more human customer experiences with AI.We are primarily an in-person company based in San Francisco, with growing... Show more

 • Promoted

Product Security Engineer

ChimeSan Francisco, CA, United States
Full-time

Product Security EngineerWe are looking for an early-career Security Engineer to join our Product Security team, someone who has a builder's mindset, is eager to learn, and is excited to contribute... Show more

 • Promoted

Staff Product Security Engineer

CrusoeSan Francisco, CA, United States
Full-time

Staff Product Security EngineerCrusoe's mission is to accelerate the abundance of energy and intelligence.We're crafting the engine that powers a world where people can create ambitiously with AI w... Show more

 • Promoted

Security Engineer, Application Security

Glean.infoSan Francisco, CA, United States
Full-time

Security Engineer, Application SecurityGlean is the Work AI platform that helps everyone work smarter with AI.What began as the industry's most advanced enterprise search has evolved into a full-sc... Show more

 • Promoted

Offensive Security Engineer

LiveRampSan Francisco, CA, United States
Full-time

Offensive Security EngineerThe Offensive Security Engineer is responsible for proactively identifying, validating, and helping remediate security weaknesses across the company's SaaS platform, whic... Show more

 • Promoted

Senior Staff Engineer – DevSecOps

UsefulBI CorporationAlameda, CA, United States
Full-time

We are seeking a Senior Staff Engineer – DevSecOps to lead the design, implementation, and continuous improvement of cloud security and DevSecOps practices across AWS and Azure environments.This ro... Show more