Staff Security Engineer

Robots and Pencils

$116K — $160K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years in security or software engineering with 3+ years in cloud security
  • Expertise in application security and secure coding practices
  • Experience with threat modeling and vulnerability management
  • Strong knowledge of cloud security at identity, network, and data levels
  • Proficient in integrating security automation into CI/CD pipelines
  • Experience with incident response and detection engineering
  • Skilled in securing AI/LLM applications against various threats

Responsibilities

  • Define security architecture and standards for cloud applications
  • Lead threat modeling and security design reviews
  • Architect and own cloud security controls
  • Integrate security automation into CI/CD processes
  • Oversee detection engineering and incident response practices
  • Manage security of AI systems in production
  • Utilize AI tools to enhance work quality

Benefits

  • Paid time off
  • Medical/dental/vision insurance
  • 401(k) plan for eligible employees
Full Job Description
Staff Security Engineer

This position is remote based in the US

Applicants outside of the US will not be considered for this role

Position Overview

We're looking for a Staff Security Engineer to lead the security of the cloud applications and AI systems we build and ship for clients. This role is ideal for an experienced engineer who can define security architecture and standards, own the hardest security problems end-to-end, and provide technical leadership across teams.

In this role, you will work as a key technical leader on a cross-functional team, defining security architecture across cloud infrastructure, application code, and AI/LLM workloads. You'll lead threat modeling and security reviews, mentor more junior engineers, partner closely with engineering and leadership, and ensure the systems we ship are secure, reliable, and built to last.

What You'll Do

Craft & Delivery
  • Define security architecture and engineering standards across web, API, and cloud-native systems, leading the hardening of complex services
  • Lead threat modeling and security design reviews across applications and AI systems, setting how risk is identified and prioritized
  • Architect cloud security controls across identity, network, and data layers, owning IAM strategy, secrets management, and encryption
  • Lead the integration of security automation into CI/CD pipelines, driving shift-left detection and policy-as-code across teams
  • Lead detection engineering, logging, and incident response practices across production systems
  • Own the security of AI and LLM-powered applications in production, defining defenses against prompt injection, data leakage, model abuse, and agentic-AI threats
  • Lead the design and integration of AI services into production security workflows, including LLM APIs, tool and function calling, and multi-step agent flows for detection and triage
  • Bring an AI-forward mindset to your daily work, using tools like Claude, Cursor, and other modern AI assistants to ship higher-quality work at pace

Collaboration & Communication
  • Partner with product, engineering, and leadership to shape security strategy and align technical direction with business outcomes
  • Translate complex security tradeoffs, risks, and opportunities into clear narratives that drive decision-making across technical and non-technical stakeholders
  • Lead security reviews and technical discussions, raising the bar for engineering rigor and constructive challenge across the team
  • Engage closely with engineering, data, and client teams to align security work with broader business priorities and measurable outcomes

Leadership & Influence
  • Define security architecture and engineering standards, bringing depth on tradeoffs, long-term implications, and responsible AI practices
  • Mentor and grow junior and mid-level engineers, multiplying impact through coaching, code reviews, and pairing on hard problems
  • Take ownership of the most ambiguous and highest-stakes pieces of work, driving them through to production with care for reliability, cost, and safety


What You'll Bring
  • 7+ years of professional security or software engineering experience, with at least 3 years leading application and cloud security initiatives
  • Deep expertise in application security, secure coding practices, and the OWASP Top 10
  • Strong experience with threat modeling, penetration testing, vulnerability management, and secure code review
  • Deep cloud security expertise across identity, network, and data layers
  • Strong experience embedding security automation and policy-as-code into CI/CD pipelines
  • Strong experience with detection engineering, logging, and incident response at scale
  • Strong experience securing AI and LLM-powered applications, including prompt injection, data leakage, model abuse, and agentic-AI threats
  • Experience with security, compliance, and governance frameworks
  • Demonstrated leadership and technical mentoring experience across a team or organization
  • Strong stakeholder communication skills, with the ability to translate technical depth across audiences
  • Demonstrable, day-to-day usage and expert knowledge of AI-forward tools such as Claude and Cursor
  • Excellent problem-solving skills and the ability to navigate highly ambiguous technical and business challenges with sound judgment

Helpful Extras and Unique Skills

You'll Do Well Here if You Are
  • A doer. You see something broken and fix it. You'd rather move on clarity than wait for certainty.
  • A fast learner who knows you don't know everything. The AI landscape changes weekly. You're senior enough to know better and curious enough to keep learning anyway.
  • Direct in a way that makes the work better. You give honest feedback. You'd rather have the hard conversation than blow smoke.
  • Obsessed with craft. You know genius is in the details. You ship exceptional, not perfect, and you don't put your name on work you wouldn't stand behind.
  • Built for ownership. You honor commitments, admit mistakes fast, and back your teammates when a decision costs something. No handoffs, no finger-pointing.
  • All in. You treat clients' businesses like your own. You take the work seriously without taking yourself seriously.
  • Resourceful when the budget, timeline, or team is tight. Constraints don't slow you down. They sharpen you.
  • Glad to be in the room with people who care as much as you do. Our teams average fifteen-plus years of experience. We hire people who push each other to do better work.

    The below range reflects the range of possible compensation for this role at the time of this posting. We may ultimately pay more or less than the posted range. This range may be modified in the future. An employee's position within the salary range will be based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, shift, travel requirements, sales or revenue-based metrics, any collective bargaining agreements, and business or organizational needs. The salary range for this role is $56. - $77. USD hourly rate. We offer a comprehensive package of benefits including paid time off, medical/dental/vision insurance and 401(k) to eligible employees.

Similar Jobs

More Jobs at Robots and Pencils

More Information Technology Jobs

Find similar Staff Security Engineer jobs: