Source Job

$210,000–$247,000/yr
Global

  • Lead threat modeling and secure design reviews across C++, Go, and Rust
  • Build and tune application security testing (SAST, SCA, secret scanning, DAST) and fuzzing harnesses
  • Operate PSIRT and build security champions program to raise the security bar

C++ Go Rust Threat Modeling

20 jobs similar to Staff Security Engineer

Jobs ranked by similarity.

Europe

  • Define security requirements and design application architectures following a secure-by-default approach.
  • Conduct threat modeling, code reviews, and penetration testing on cloud-based web and mobile apps.
  • Implement, manage, and automate SAST/DAST/SCA security controls and WAF rules to enforce protection at scale.

Prima is a motor insurance company that uses data and technology to provide a great experience for drivers. They are trusted by over 5 million drivers and have over 350 engineers in their Engineering department, fostering a culture of curiosity and collaboration.

$130,100–$187,000/yr
US

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.

Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.

$130,000–$170,000/yr
US

  • Partner with product and engineering teams to identify risks early and build security into new features.
  • Lead threat modeling and secure design reviews for new products and architecture changes.
  • Perform security-focused code reviews and maintain application security tooling integrated into CI/CD.

Jump builds AI-powered tools that help financial advisors automate meeting prep, notes, and follow-up. It is a small startup with a culture that prioritizes security and trust, and security is core to the product.

Europe

  • Act as an Application Security SME, partnering with Engineering and Product teams to embed security throughout the SDLC.
  • Lead application security reviews, threat modeling, code reviews, and penetration testing to identify and mitigate risks.
  • Design and automate security controls across CI/CD pipelines, including SAST, SCA, and other AppSec tooling.

Job&Talent is a world-leading, AI-powered workforce management platform for frontline industries. Headquartered in Madrid, the company operates in 10 countries across Europe, the US, and Latin America, backed by leading investors, and places millions of workers.

Global

  • Act as the primary security partner for the Walrus team, providing architectural guidance and embedding security practices throughout the development lifecycle.
  • Lead security assessments for new features and contribute to ecosystem-wide security initiatives, identifying systemic risks and actionable remediation plans.
  • Drive a security-by-design culture, leveraging AI and automation to focus on high-impact, complex security research and mentor engineers.

Mysten Labs builds foundational infrastructure to accelerate the adoption of decentralized protocols based on blockchain technologies. They are a well-funded, remote-first team with over $300M in Series B funding from top venture firms, fostering a culture of innovation and growth.

$152,000–$175,000/yr
US Unlimited PTO

  • Lead threat modeling, architecture reviews, and code reviews for web applications, APIs, and microservices.
  • Actively develop and commit code to fix security flaws in Python, Go, or JavaScript/TypeScript codebases.
  • Implement and manage security testing tools within CI/CD pipelines to catch vulnerabilities early in the SDLC.

RunPod is the AI Developer Cloud, providing a platform for developers to experiment, train, fine-tune, deploy, and scale AI. We are a small, remote-first team that has processed over 20 billion inference requests and closed a $100M Series A in June 2026.

$190,000–$319,000/yr
US

  • Design and ship security workflows combining deterministic analysis with LLM reasoning to find real vulnerabilities across languages and frameworks.
  • Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy for security-critical work.
  • Push on hard problems in automated triage and validation to close the gap between finding and actionable fix.

Semgrep is a code security platform that helps teams catch and fix vulnerabilities before they ship. They are a venture-backed startup with a transparent culture that values respect and honesty.

$88,800–$125,800/yr
Canada 3w PTO 12w maternity 12w paternity

  • Proactively identify and drive security improvements across the product and platform.
  • Partner with engineering teams to threat model new features and review designs early in development.
  • Build and improve security tooling, libraries, and workflows to make secure development the default path.

Fellow is an AI meeting assistant that helps teams record, transcribe, summarise, and act on their meetings. We are a Series A company backed by major venture firms, with a remote-first culture and a growing team.

US

  • Own threat modeling and secure code reviews for new products and features.
  • Maintain and tune AppSec tooling, and run the bug bounty program.
  • Design and evolve the secure SDLC, and partner with engineering teams to implement secure-by-default patterns.

Ondo Finance is building institutional-grade financial infrastructure for tokenized real-world assets. The company operates at the intersection of traditional finance and on-chain systems, with a focus on security and innovation.

US 18w maternity 16w paternity

  • Contribute to secure-by-design practices and advance the S-SDLC program.
  • Mentor engineers on secure coding and career growth.
  • Evaluate and recommend AI-assisted security tooling.

Spring Health is a global mental health company eliminating every barrier to mental health. They reach more than 170 million people worldwide and are an AI-native company focused on expanding the reach, quality, and humanity of care.

Canada

  • Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features and APIs.
  • Develop and maintain scalable security tools and automation pipelines for vulnerability detection across the SDLC.
  • Contribute to security architecture reviews and support bug bounty programs and incident response.

Lime is a global leader in micromobility on a mission to make transportation shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered over a billion rides in 30 countries and is a fast-paced, lean, remote-first team.

Canada

  • Leads product security work across Black Duck's portfolio, including architecture reviews, threat models, vulnerability triage, and customer-facing security inquiries.
  • Maintains detection content in CrowdStrike NG-SIEM and Sumo Logic, contributes to SOAR automations, and coordinates vulnerability fixes with engineering teams.
  • Acts as an informal technical resource for less experienced team members, explains complex security topics to diverse stakeholders, and documents runbooks and SOPs.

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. A recognized pioneer in application security with industry-leading tools and services, they partner with teams to maximize security and quality in DevSecOps.

Global

  • Design and implement security controls across applications, cloud infrastructure, and development environments.
  • Conduct architecture reviews, threat modeling, and security assessments for new products.
  • Identify, prioritize, and remediate vulnerabilities across the technology stack.

SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.

Europe

  • Design, build, and own security integrations and detections across multiple libraries, with .NET and/or Java as your primary focus.
  • Take projects from prototype to deployed, correct, operable, and maintainable, writing code that safely instruments thousands of applications in production.
  • Mentor teammates and act as a force multiplier, raising the bar on code quality and testing.

Datadog is the leading observability and security platform for the AI era, providing businesses with unified visibility across the technology stack to manage complexity at scale. The company operates at high scale with trillions of data points per day and values pragmatism, honesty, and simplicity in its engineering culture.

US

  • Conduct and support static and dynamic application-security testing using tools like Fortify, X-Ray, and OWASP ZAP.
  • Work with software engineers to understand root causes, resolve vulnerabilities, and integrate security testing into CI/CD workflows.
  • Strengthen software supply-chain security and apply secure development practices in environments using GitLab, OpenShift, and Kubernetes.

Rackner builds secure software supporting high-impact Department of Defense planning and decision-support missions. The company has delivered more than $30 million in recent federal awards and fosters a collaborative, mission-focused culture.

$169,150–$191,250/yr
US Unlimited PTO

  • Collaborate with engineering and product teams to improve security posture through threat modeling, assurance, and secure implementation.
  • Identify security gaps and vulnerabilities in ClickHouse Cloud and OSS, triaging vulnerabilities from bug bounty and responsible disclosure.
  • Drive adoption of security tools and develop automation to scale security processes.

ClickHouse provides a leading real-time analytics platform for data warehousing, observability, and AI workloads. With over 3,000 customers and rapid growth, the company fosters a remote-friendly, innovative culture.

Brazil

  • Identify and remediate vulnerabilities across the product ecosystem using code reviews and automation.
  • Integrate security tools and practices into CI/CD pipelines to ensure secure development.
  • Collaborate with engineering teams to apply threat modeling and secure-by-design principles.

They are a partner company specializing in digital product security. The team size is not specified, but the culture emphasizes trust, collaboration, and remote work.

US Unlimited PTO

  • Partner with product and engineering teams to identify security risks and implement secure solutions throughout the product lifecycle.
  • Lead threat modeling activities, secure design reviews, and security-focused code reviews to improve development practices.
  • Build, maintain, and improve application security tooling and participate in incident response activities.

The partner company is a fast-moving engineering organization focused on protecting modern software products and the sensitive data they manage. The team values innovation, inclusion, and continuous improvement, and offers a collaborative culture with high ownership.

$160,000–$195,000/yr

  • Lead and evolve the company's application security strategy, roadmap, and day-to-day operations.
  • Manage and optimize AppSec tooling including GitHub Advanced Security, Invicti, Hadrian, and Cloudflare WAF.
  • Build secure development standards, conduct security reviews, and partner with engineering teams on design and code review.

Beyond Finance helps everyday Americans escape debt and achieve financial freedom through compassionate, individualized care and customized solutions. The company is rapidly growing, has helped over 1 million clients, and fosters a forward-thinking culture focused on compliance and ethics.

Global

  • Assist in developing secure software by writing and optimising Rust code for security-critical components.
  • Conduct deep manual and automated code audits to identify and mitigate security vulnerabilities.
  • Design and implement machine learning models for automated security analysis and threat mitigation.

Parity builds core blockchain infrastructure for a decentralized web, including Polkadot and Kusama. Our remote-first global team develops open-source software and is committed to a respectful, innovative culture.