Enter a job title or keyword

Senior Security Engineer

Queueinc


Job Location:

Newark, DE - USA

Monthly Salary: Not provided by the employer
Posted: 10 October 2026 (Yesterday)
Application Deadline: 7 January 2027
Vacancies: 1 Vacancy

Department:

Engineering

Job Summary

About Us

Queue builds robots to fill prescriptions. Our machine is designed to take stock bottles of medication and produce counted labeled vials so that pharmacists and technicians can spend their time on patients. Our first product is built to work behind the pharmacy counter and to be operated by pharmacy staff.

About the Role

You own security engineering for a pharmacy robot and everything it talks to: the machine its operating-system image the software that runs on it the cloud service that commands it and the path that updates it. When a customer asks how each machine proves its identity who can reach it and how and what an independent test found and what was done about it the answer rests on your work and every statement in it is backed by something the system produces.

What Youll Own

  • The threat model A written model of the trust boundaries: machine to cloud operator to screen the update path remote support and suppliers. You keep it current as designs change.

  • Security review of designs Designs come to you early; you review them and your review is recorded.

  • Device identity and key custody The threat model the priorities and the verification are yours. The engineers who own the operating-system image build the platform side with you.

  • Independent security testing Scope test environment triage remediation with the owning squads and retest evidence. You run it end to end.

  • Finding and fixing weaknesses How weaknesses in our code dependencies device images and cloud are found triaged and fixed. It is shared with the squads that own each part: you set the rules track each finding to closure and report where we stand.

  • Incident response The security side of every incident: detection triage containment evidence and what changes afterwards. It is shared with the owning squads and you run it with the systems reliability engineers who run the operational response.

  • Customer security reviews A customers security review asks detailed questions and treats our answers as commitments. Before a statement is sent you check it against the evidence that can substantiate it: the versioned implementation the deployed configuration and the operational records. A statement says what is built what is designed and what is planned and keeps the three apart.

  • Cloud posture Identity and access secrets the review of infrastructure changes and what the cloud providers detection services report.

  • Security and privacy controls For the controls Queue commits to including those that follow from HIPAA you verify each control in the system and take its evidence from the system.

You assess and you recommend. You do not accept risk on the companys behalf: an exception is recorded with its approver and conditions and an authorized business owner accepts what remains.

First 90 Days

  • Day 30: You have traced the trust boundaries yourself and you hold the threat model and the record of independent testing. You have reviewed your first design.

  • Day 60: You hold the priorities and the verification for device identity and key custody with the engineers who own the operating-system image. You hold the inventory of secrets and keys and their rotation schedule. Every security statement that goes to a customer passes your check first.

  • Day 90: You have written the scope for the next independent test and prepared the environment it will run against. Every design that came to you has a recorded review. You can hand an assessor a controls evidence as output from the system.

What Were Looking For

Must-Have

  • Ownership you have owned the security of a shipped product end to end and you can describe a problem you found fixed and followed until it stayed fixed. Consulting alone or compliance alone is not this.

  • You build you read and write code. Ours is Rust TypeScript and Python: deep skill in one and comfort reading the others. Your reviews come with a patch or with guidance precise enough to act on.

  • Systems and network depth TLS and certificates identity and access secrets management Linux hardening. You can reason about a trust boundary from the hardware to the cloud.

  • Offensive fluency with defensive judgment you have run or worked closely with penetration tests. You rank issues by what they could do to this system and its users and you can defend deferring one.

  • Threat modeling that engineers use you would sooner remove an input than add a control and engineers ask for your review.

  • Exact writing you state what is true at the strength the evidence supports to an engineer an executive or a customers assessor.

Nice-to-Have

  • Device security: verified start-up hardware-held keys signed updates fleet identity.

  • Security in healthcare or another regulated industry and customer security reviews from the suppliers side.

  • Cloud security engineering on AWS.

  • Supply-chain security: dependency policy artifact signing provenance.

  • Working knowledge of IEC 62443 UL 2900-1 or NISTIR 8259.

How We Hire

  • Recruiter Screen (30 min)

  • Technical Interview (90 min) a take-home exercise of 2 to 3 hours sent at least 24 hours before: a small working system to harden. We go through it together: what you fixed first and why.

  • Design Interview (60 min) on trust boundaries and key custody.

  • Leadership Interview (60 min) how you own your work and work across squads.

Two interviewers score each technical stage independently.

What We Offer

  • Ownership security engineering for the machine and everything it talks to

  • Hard problems: trust boundaries from the hardware to the cloud device identity and key custody and the path that updates the machine

  • Small team zero bureaucracy high trust

Why Join Us Now

Impact & Growth

  • Direct Impact: You check every security statement against the evidence behind it before it goes to a customer

  • Growth: The work runs from the review of a design to an independent test and its retest

Team and Culture

  • Reports to the Head of Software Engineering with significant autonomy and influence

  • The same person sets the security requirements you work to

  • Who You Work With: You work every day with the engineers who build the on-machine software the cloud service and the operating-system image

  • Where We Work: Hybrid three days a week at our headquarters in the Bay Area; device security work needs the hardware in front of you

Our Values

  • Servant Leadership

  • Do the Hard Things

  • Own Your Work

  • Default is Now

Own Your Work comes first in this role: you follow a problem until it stays fixed.

Contact: If you have any questions please contact us at


Required Experience:

Senior IC