Enter a job title or keyword

Staff Application Security Engineer

Samsara


Job Location:

San Francisco, CA - USA

Yearly Salary: USD 165200 - 295000
Posted: 17 September 2026 (12 hours ago)
Application Deadline: 15 December 2026
Vacancies: 1 Vacancy

Job Summary

Who we are

Samsara (NYSE: IOT) is the pioneer of the Connected Operations Cloud which is a platform that enables organizations that depend on physical operations to harness Internet of Things (IoT) data to develop actionable insights and improve their operations. At Samsara we are helping improve the safety efficiency and sustainability of the physical operations that power our global economy. Representing more than 40% of global GDP these industries are the infrastructure of our planet including agriculture construction field services transportation and manufacturing and we are excited to help digitally transform their operations at scale.

Working at Samsara means youll help define the future of physical operations and be on a team thats shaping an exciting array of product solutions including Video-Based Safety Vehicle Telematics Apps and Driver Workflows and Equipment Monitoring. As part of a recently public company youll have the autonomy and support to make an impact as we build for the long term.


About the role:

Samsara sits at the center of hardware software AI and the physical world processing 25 trillion data points annually across thousands of connected devices. The Samsara Application Security team protects this vast footprint end-to-end spanning cloud services internal systems and firmware running on IoT hardware in the field.

As a Staff Application Security Engineer youll drive the overarching technical direction for our application security and vulnerability management programs. This is a high-visibility role where youll influence a broad surface area while retaining the flexibility to dive deep into critical domain focus areas as security priorities evolve.

This is a remote position open to candidates residing in the US.

You should apply if:
  • You want to impact the industries that run our world: Your efforts will result in real-world impacthelping to keep the lights on get food into grocery stores reduce emissions and most importantly ensure workers return home safely.
  • You are the architect of your own career: If you put in the work this role wont be your last at Samsara. We set up our employees for success and have built a culture that encourages rapid career development and countless opportunities to experiment and master your craft in a hyper-growth environment.
  • Youre energized by our opportunity: The vision we have to digitize large sectors of the global economy requires your full focus and best efforts to bring forth creative ambitious ideas for our customers.
  • You want to be with the best: At Samsara we win together celebrate together and support each other. You will be surrounded by a high-caliber team that will encourage you to do your best.
In this role you will:
  • Lead the ongoing strategy operation and continuous improvement of Samsaras vulnerability management program along with other core application security programs not just execute against an existing process but define what the process should be.
  • Own and drive down mean time to remediate (MTTR) across the vulnerability backlog as SLAs tighten.
  • Build and champion automation and tooling that scale vulnerability detection and response across cloud firmware/IoT and corporate systems rather than relying on manual one-by-one review.
  • Set technical and architectural direction for the program translating leaderships strategic priorities into a concrete execution plan for the team.
  • Drive remediation by building trust with engineering teams and providing clear actionable guidance partnering with technical program management on reporting rather than owning it directly.
  • Mentor and level up other engineers on secure design and remediation practices and be a technical voice other teams look to when priorities are unclear.
  • Communicate risk and remediation tradeoffs to engineering leadership in terms they can act on without owning the relationship end to end.
  • Participate in security incident investigations involving high-profile vulnerabilities assessing potential impact on Samsaras infrastructure.
  • Be regularly on call to support critical vulnerability response.
  • Champion role model and embed Samsaras cultural principles (Focus on Customer Success Build for the Long Term Adopt a Growth Mindset Be Inclusive Win as a Team) as we scale globally and across new offices

Minimum requirements for the role:

  • 10 years of relevant experience as a cloud engineer or security engineer including hands-on vulnerability management across a broad multi-product enterprise environment not a single product or teams slice of it.
  • Proficiency in Go Python and JavaScript.
  • Demonstrated ability to independently set technical and architectural direction for a security program and to drive remediation across a broad multi-surface environment without direct authority over the teams doing the fixing.
  • Significant experience with modern vulnerability management tooling (e.g. Wiz Semgrep) and deep familiarity with vulnerability scoring frameworks such as CVSS and EPSS.
  • Strong AWS cloud services background.
  • Deep understanding of Static Application Security Testing (SAST) Dynamic Application Security Testing (DAST) and Software Composition Analysis (SCA).
  • Hands-on use of AI/LLM tooling in your own security workflow triage detection logic remediation drafting plus credibility speaking to how AI is changing the threat landscape and the tooling available to address it.

An ideal candidate also has:

  • Experience with C/C relevant to firmware and embedded systems.
  • Background at a cloud-native AI-forward company actively building agentic or AI-driven products.
  • Experience with security automation platforms (e.g. Tines) and serverless frameworks (e.g. AWS Lambda).
  • Experience integrating vulnerability management into modern CI/CD pipelines with a shift-left mentality.
  • Experience spanning SaaS firmware and corporate IT security programs not just one product line.
  • Experience managing vulnerabilities within a FedRAMP-certified environment.
  • Experience building extending or wiring up AI copilots/agents for security workflows (e.g. automated triage remediation drafting).

Required Experience:

Staff IC


About Company

Publicly traded company [NYSE: IOT] offering a single platform for fleet operations at scale. Products include real-time GPS, ELD, AI-powered dash cams, telematics, maintenance, routing, & driver app. Recognized by the Forbes Cloud 100.

View Profile View Profile