Your browser does not support javascript! Please enable it, otherwise web will not work for you.

Senior/Staff Security Engineer

Home > Python programming jobs

Senior/Staff Security Engineer in USA

  • Zipline
  • Full time
  • Email
  • South San Francisco, CA

Responsibilities

  • Own security outcomes for two to four named production areas and serve as the primary security owner for at least one area.
  • Define and improve quantitative security metrics such as MTTD, MTTR, exploitable findings, and compliance audit readiness.
  • Design and implement IAM, least-privilege, service-to-service trust, KMS, runtime telemetry, alerting, secure OTA update, CI/CD, and artifact-provenance controls.
  • Perform threat modeling and secure design reviews for fleet, regulated, physical-system, and partner-facing services, and drive mitigations through completion.
  • Lead vulnerability triage, remediation planning, staged verification, and regression prevention for owned services.
  • Build incident-response playbooks, run tabletop exercises, validate forensic logging and auditability, and participate in postmortems.
  • Secure AI and agent-assisted development and operations through allowed-use patterns, guardrails, monitoring, and auditing.
  • Integrate penetration-test and red-team findings into tracked engineering changes with measurable closure criteria.
  • Collaborate with SRE, platform, autonomy/embedded, field-operations, and compliance teams, and participate in assigned on-call rotations.

Requirements

  • 8+ years building and operating security controls for large-scale production systems across application and cloud infrastructure.
  • Hands-on engineering ability with Python, Go, or similar, including automation, tooling, and integrations with AI tools and agentic security bots.
  • Deep experience with cloud-native stacks, microservices, Kubernetes, containers, IAM, CI/CD, secrets management, logging, telemetry, and least-privilege service-to-service models.
  • Prior ownership of vulnerability management, incident-response playbooks, and production verification processes.
  • Experience threat-modeling and securing systems interfacing with physical systems, regulated workflows, or third-party partners, including embedded, teleoperation, field operations, or healthcare-adjacent data flows.
  • Ability to define, track, and deliver quantitative security targets within six to twelve months.
  • Technical ownership, prioritization, stakeholder influence, and ability to drive security changes into production.
  • Preferred experience securing LLM or agentic tools, mitigating OWASP LLM risks, working across cloud infrastructure, web services, and embedded/autonomy, or building developer-friendly security platforms.

Benefits

  • Hybrid role based in South San Francisco with frequent presence at the company headquarters.
  • Occasional travel to distribution centers, field sites, and test sites is required.
  • Participation in incident response and assigned on-call rotations is required.

Zipline

Zipline is redefining logistics with its instant delivery system that addresses urgent access challenges for a diverse range of customers, including governments and businesses. By leveraging advanced technology like robotics and autonomy, Zipline ensures equitable access to essential goods, wheth...

Similar positions

Software Engineer in Test

  • Roadie
  • Full time
  • USA
  • 09/13/2026
  • Salary: Competitive
  • Remote

Principal Software Engineer - Builder Experience

  • Elastic
  • Full time
  • Remote
  • 09/13/2026
  • Salary: €73k-€116k
  • Greece

Principal Software Engineer - Builder Experience

  • Elastic
  • Full time
  • Remote
  • 09/13/2026
  • Salary: zł 369k-zł 584k
  • Poland

Senior Devops Engineer

  • Woliba
  • Full time
  • USA
  • 09/13/2026
  • Remote

Senior Core Infrastructure Engineer

  • Oracle
  • Full time
  • USA
  • 09/13/2026
  • Salary: Competitive
  • Nashville, TN