waypointjobs

SambaSafety

Security Engineer

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

Who we are:

Hi, we’re SambaSafety and we offer the industry’s most comprehensive driver monitoring software. Our mission is promoting safer communities by reducing risk through data insights. Companies trust SambaSafety to keep their employees safe on the roads, price and reduce risk, help protect their brand, their bottom line, and our global community.

We’ve built an inclusive, supportive, and exceptional culture where every employee is empowered in their role. Don’t take our word for it; we’ve been recognized as a Top Workplace by The Denver Post, Albuquerque Journal, Sacramento Bee, and Built In Colorado. And our employees rate SambaSafety as top-notch, with a rock solid Top Rating on Glassdoor.

What You’ll Do:

We are seeking an experienced Security Engineer to join our growing security team in a multifaceted role that combines vulnerability management, application security, MITRE ATT&CK-based threat detection, AI-driven security automation, and security engineering expertise. This position requires a technical security professional with knowledge spanning cloud security, identity and access management (IAM), endpoint detection and response (EDR), SIEM administration, and hands-on scripting for automation development. The successful candidate will work closely with development teams, infrastructure teams, vendors, and internal stakeholders to optimize our security posture and manage enterprise risk.

Key Responsibilities:

Application Security & Vulnerability Remediation

Lead application security vulnerability remediation efforts across development teams

Administer SAST tooling

Administer DAST tooling

Administer SCA and software composition / dependency scanning tools

Triage and validate vulnerability findings to reduce false positives

Provide remediation guidance to development teams on OWASP Top 10 and secure coding practices

Integrate scanning tools with ticketing systems and CI/CD pipelines

Generate AppSec metrics and reports

Provide security code review support

Vulnerability Assessment & Management

Administer vulnerability management platforms

Configure scan policies, schedules, and asset groups

Validate and prioritize vulnerability findings using risk-based prioritization (CVSS + context)

Conduct expert analysis and risk scoring of vulnerabilities

Coordinate remediation with IT and development teams

Manage vulnerability exceptions and risk acceptances

Track vulnerability aging and SLA compliance

Generate management reports and dashboards

Participate in product vulnerability management meetings

Participate in Security by Design reviews

MITRE ATT&CK & Threat Detection

Develop detection rules mapped to ATT&CK techniques

Implement ATT&CK-based alert triage workflows

Configure SIEM correlation rules using ATT&CK

Conduct gap analysis of ATT&CK coverage

Integrate threat intelligence feeds with ATT&CK mapping

Build ATT&CK-based hunting queries

Create ATT&CK-mapped incident reports

AI-Driven Security Automation & Agent Engineering

Build and maintain scripted, cloud-based automation pipelines supporting the team's AI-driven security operations platform

Develop and tune AI agent prompts, verdict logic, and disposition rules for automated alert triage

Extend the team's internal tool-integration framework connecting security platforms for AI-assisted operations

Integrate automation with SIEM, EDR, and ticketing systems

Build automated enrichment and reporting workflows

Monitor and tune agent/automation performance and disposition accuracy

Develop custom integrations using APIs and cloud-native services

Maintain observability for automated security workflows

Security Engineering & Architecture

Lead Tier 2/3 security incident investigation and response

Administer EDR, SIEM, and IAM platforms

Implement and tune detection rules and alerts

Manage cloud security configurations

Support penetration testing and red team activities

Conduct WAF/CDN rule audits and configuration reviews

Provide security engineering expertise for infrastructure and application architecture decisions

Support complex security investigations requiring deep technical analysis

Contribute to security design reviews and technical security standards

Policy & Threat Intelligence

Draft and review security policies and procedures

Conduct policy gap analysis against frameworks

Analyze threat intelligence from multiple sources

Integrate threat feeds into detection and automation workflows

Implement IOC blocking and detection rules

Participate in information sharing communities (ISACs)

Create threat intelligence reports

Required Qualifications:

Education & Experience

Bachelor's degree in Computer Science, Information Security, Engineering, or related technical field, or equivalent professional experience

5-7 years of experience in security engineering with demonstrated expertise in multiple security domains, including application security

Technical Skills

Expert knowledge of vulnerability management platforms

Proficient in MITRE ATT&CK mapping for detection rules and incident response

Strong experience with SAST, DAST, and SCA tooling for application security

Deep understanding of application vulnerabilities (OWASP Top 10, injection flaws, XSS, authentication bypasses)

Hands-on scripting experience building cloud-based automation (serverless functions, event-driven pipelines, secrets management)

Experience with, or strong interest in, AI agent engineering and tool-integration protocols for security operations

Proficiency administering EDR platforms

Experience with SIEM administration

Solid understanding of IAM platforms and federation/SSO concepts

Proficiency in cloud security (AWS, Azure, or GCP)

Solid understanding of WAF configuration and audit

Proficiency in scripting and automation (Python required; PowerShell a plus)

Understanding of DevSecOps and secure CI/CD practices

Practical experience with AI-powered security tooling, including building or operating LLM-based agents, and awareness of emerging AI threats (prompt injection, tool/agent security risks)

Ability to produce dashboards and reporting for technical and executive audiences

Platform & Domain Experience

SIEM administration

Security automation/orchestration, including AI agent-based automation

Vulnerability management platforms

EDR platforms

DLP platforms

GRC platforms

SAST tooling

DAST tooling

SCA / dependency scanning tooling

Cloud security (AWS, Azure, or GCP)

Threat intelligence platforms

Ticketing and collaboration platforms

Soft Skills & Experience

Strong analytical thinking and problem-solving capabilities

Excellent communication skills for technical and business audiences

Strong Agile proficiency with ability to integrate security into sprint planning

Experience collaborating with development teams and partnering on secure coding

Ability to translate technical vulnerability findings into actionable remediation guidance

Strong written communication skills for security documentation, audit responses, and questionnaire completion

Act as escalation point for Security Analysts

Participate in project security reviews

Support sales team with security questionnaires

Participate in customer security calls

Preferred Qualifications:

Certifications

CySA+ (CompTIA)

Cloud Security certification (AWS, Azure, or GCP)

GIAC GSEC

Certified Ethical Hacker (CEH)

GIAC GWEB (Web Application Penetration Tester)

CompTIA PenTest+ (optional)

GIAC GCTI (Cyber Threat Intelligence) (optional)

SIEM Platform Certification (optional)

Additional Experience

DevSecOps experience integrating SAST/DAST into CI/CD pipelines

Secure software development lifecycle (SSDLC) implementation experience

Compliance experience with SOC 2, ISO 27001, or industry-specific regulations

Experience with security audit preparation and vendor risk assessment programs

Threat intelligence analysis and integration experience

Experience coordinating third-party penetration testing

Security awareness training development and delivery

Experience building or integrating LLM-based agents/automation for security operations

Experience with container and Kubernetes security concepts

Benefits and Perks:

Flexible and generous Paid Time Off and Paid Volunteer Days

401k Employer Match

Generous Healthcare Benefits

Up to 12 weeks paid time off for maternity leave based on tenure

Wellness &Tuition Reimbursement

Flexible Work Arrangements

Lots of SambaSafety swag & SambaSafety Events

Our team of talented and committed safety professionals is exceptional. At SambaSafety we strive to foster an inclusive culture that supports, encourages and celebrates a wide array of diversity. We are committed to create a space where all employees can show up as their authentic selves every day, and we work to advance employee equality, diversity and inclusion.

SambaSafety provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, gender identity, and expression or genetics.

Come join us to find out for yourself what all the excitement is about!

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

infisical

Jobicy

Senior Full Stack Engineer

Remote — Brazil, Canada, Europe, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Mission

Remote — USA

Salary not specifiedRemote

The Music Mission enables music creators to grow, engage, and monetize their fan bases on Spotify. Central to the Music Mission's vision is the d…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Promotion

Remote — USA

Salary not specifiedRemote

The Music Mission enables Music creators to grow, engage & monetize their fan bases on Spotify. Central to the Music Mission's vision is the deve…

Listing review due 2026-10-07View job

infisical

Jobicy

Strategic Finance

Remote — Canada, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job