yandex
flyzipline
Страна
США
Зарплата
230 000 $ – 275 000 $
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
ГибридПолная занятость

Staff Security Engineer - Product Security

Оценка ИИ

Исключительно интересная позиция в компании-лидере рынка дронов с реальным социальным вкладом. Высокая заработная плата, работа с передовыми технологиями (AI/Robotics) и значительное влияние на стратегию безопасности делают эту вакансию топовой для экспертов.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Роль требует редкого сочетания глубоких знаний в безопасности облачных инфраструктур, микросервисов и специфических рисков ИИ (LLM), а также опыта работы с робототехникой и автономными системами. Высокий уровень ответственности (Staff) предполагает лидерство без прямого подчинения и умение писать код на уровне разработчика.

Анализ зарплаты

Медиана245 000 $
Рынок210 000 $ – 290 000 $
Оценка ИИ

Предлагаемая зарплата ($230k - $275k) находится на верхнем уровне рыночных ожиданий для Staff-позиций в районе залива Сан-Франциско, особенно для узкоспециализированных ролей в Product Security. Она полностью соответствует или даже слегка превышает медиану для высокотехнологичных стартапов этой стадии.

Сопроводительное письмо

I am writing to express my strong interest in the Staff Security Engineer position at Zipline. With over 8 years of experience in securing large-scale production systems and a deep background in cloud infrastructure and application security, I am drawn to Zipline’s unique challenge of securing a global autonomous robotics ecosystem. I have a proven track record of shipping security controls in Python and Go, and I am particularly excited about your focus on securing agentic AI workflows, an area where I have been actively applying the NIST and OWASP frameworks.

Throughout my career, I have prioritized building 'paved roads' for developers rather than just writing policy. At my previous roles, I successfully implemented secure SDLC practices and hardened CI/CD pipelines without compromising engineering velocity. I thrive in high-ownership environments and look forward to the opportunity to partner with your software and robotics teams to ensure that Zipline’s mission-critical deliveries remain safe and resilient against evolving threats.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в flyzipline уже сейчас

Присоединяйтесь к Zipline, чтобы защищать будущее автономной логистики и внедрять безопасные ИИ-технологии в реальном мире!

Описание вакансии

About Zipline

Zipline is the world’s largest and most experienced drone delivery service. We are on a mission to serve all humans equally by ensuring access to food, medicine and essential goods anytime, anywhere. We design, build, and operate the world’s largest autonomous logistics system, delivering critical supplies quickly and reliably. Today, Zipline operates on four continents, makes a delivery somewhere in the world every 30 seconds, and has completed millions of deliveries to date, including blood, vaccines, medical supplies, food, and retail products.

Our customers include the world’s largest and most prominent healthcare systems, governments, retailers, restaurants and global businesses who rely on us to save lives, reduce emissions, increase economic opportunity, and provide delivery from point A to point B as fast as possible. The drone is only 15% of what we’ve built to enable seamless, reliable, global operations.

Our system strengthens supply chains, reduces congestion, and gives people time back. With more than 140 million commercial autonomous miles safely flown, Zipline is redefining access to healthcare, consumer products, and food across the globe.

We operate at a global scale and are looking for practical problem solvers who thrive on real-world challenges and rapid growth. Our team is motivated by building systems that have a direct, meaningful impact on people’s lives and by scaling the future of logistics. We are seeking people who sculpt from first principles, enjoy facing adversity, and can do the impossible at record breaking speeds.

About You and The Role

Zipline builds and operates fleets of delivery drones to get medicine to those who need it, fast, regardless of where they live. To power this, the software team is building out the long term scalable solutions to expand rapidly while empowering our world class distribution centers to serve their customers as fast as possible.

Zipline’s security problems aren’t “website got pwned” problems (though those exist too). They’re “real-world autonomy + robotics + global operations + cloud software + regulated/health-adjacent workflows” problems. You’ll partner deeply with software, infrastructure, and (where relevant) embedded/autonomy teams to reduce real risk in real systems. We have a large attack surface

Our ideal candidate works well in startup environments, wears many hats, and collaborates across engineering disciplines. You’ll join a small, high-ownership security team with significant influence over how we scale.

A note on our modern reality and agentic tooling:

Engineering teams are increasingly adopting LLM copilots and agentic tools to move faster. That’s useful, until an “assistant” becomes an unmonitored automation path to secrets, sensitive data, or privileged actions. (Think: “obedient intern with production credentials.”) Industry guidance is converging on practical frameworks like the NIST AI Risk Management Framework (including a profile for generative AI) and the OWASP Top 10 for LLM Applications, which explicitly calls out risks like prompt injection, insecure plugin design, and excessive agency.

In this role, you’ll help Zipline safely leverage these tools while containing them so they don’t quietly “rewrite the threat model”.

This is a Hybrid onsite role - you will frequently have conversations in person at our HQ in South San Francisco.

What You'll Do

  • Own security outcomes for critical parts of Zipline’s application and cloud ecosystem (not by writing policy docs that no one reads, but by shipping controls and enabling teams).
  • Partner with engineering teams on secure architecture, threat modeling, and design reviews for services that must be correct, reliable, and defensible under real-world operational pressure.
  • Help us build and scale a pragmatic secure SDLC – CI/CD hardening, dependency/supply-chain controls,  secrets management, and code review patterns that don’t slow teams down.
  • Improve cloud security posture end-to-end: IAM and least privilege, network/service-to-service trust, key management, logging/telemetry, runtime detection, and incident-ready auditability.
  • Drive vulnerability management that actually closes risk: triage, exploitability analysis, remediation partnerships, and verification.
  • Help build and exercise incident response: playbooks, tabletop exercises, logging requirements, and “know it happened / know what changed” operational discipline.
  • Support data classification and access control models aligned to how Zipline operates (including partner/customer interfaces and global operations).
  • Support external penetration tests and turn results into durable improvements, not whack‑a‑mole patches.
  • Contribute to security compliance efforts (e.g., SOC 2 / ISO 27001) in a way that strengthens engineering
  • Secure AI-assisted and agentic engineering workflows (this is explicitly part of the job):
  • define safe patterns for copilots/LLM tools used in development and ops
  • implement guardrails for sensitive data exposure and output handling
  • prevent “agentic overreach” (over‑privileged tools, unsafe tool-calling, silent action-taking)
  • build monitoring/auditing around AI tool use where it matters

What You'll Bring

  • 8+ years of experience designing, building, and operating security controls for large-scale production systems (application, cloud, and infrastructure security).
  • Strong security engineering chops with evidence you can reduce risk in production systems (not just talk about it).
  • Hands-on ability to write and ship code/tools in Python, Go, or similar (you’re expected to build, not just review).
  • Practical experience securing microservice architectures and modern cloud stacks (containers/Kubernetes, IAM, CI/CD, secrets, logging).
  • Comfort operating as a technical leader without authority: you can persuade, teach, and unblock - not police.
  • A skeptical mindset: you naturally ask “what’s the failure mode?” and “how will this be abused?” before shipping changes.
  • Familiarity with the security failure modes of LLM-enabled systems (or the willingness to learn fast), including risks called out by OWASP such as prompt injection, insecure output handling, insecure plugin design, and excessive agency.

Nice To Haves

  • Experience spanning multiple engineering domains (web app + cloud infra + embedded/robotics/autonomy).
  • Experience building developer-friendly security platforms (internal libraries, paved roads, CI integrations, Public Key Infrastructure).
  • Track record of being an effective security “evangelist” (i.e., enabling good behavior with good tools and defaults, not fear).
  • Experience designing guardrails for internal AI/agent usage (policy + technical controls + auditing), especially in environments where safety and reliability are non-negotiable.
  • Deep understanding of distributed systems and how failures actually happen (partial outages, weird retries, cascading dependencies, misconfigurations, permissions drift).

What Else to Know

This will be an in-office or hybrid role based out of our South San Francisco HQs.

The starting cash range for this role is $230,000 - $275,000; please note that this is a target, starting cash range for a candidate who meets the minimum qualifications for this role. We are always open to negotiation. The final cash pay for this role will depend on a variety of factors, including a specific candidate's experience, qualifications, skills, working location, and projected impact. The total compensation package for this role may also include: equity compensation; overtime pay; discretionary annual or performance bonuses; sales incentives; benefits such as medical, dental and vision insurance; paid time off; and more.

Zipline is an equal opportunity employer and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws or our own sensibilities.

We value diversity at Zipline and welcome applications from those who are traditionally underrepresented in tech. If you like the sound of this position but are not sure if you are the perfect fit, please apply.

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • Python
  • Go
  • Kubernetes
  • Docker
  • IAM
  • CI/CD
  • Cloud Security
  • Threat Modeling
  • Microservices
  • Infrastructure as Code
  • SOC 2
  • ISO 27001
  • LLM Security
  • OWASP Top 10

Возможные вопросы на собеседовании

Проверка практического опыта обеспечения безопасности в специфическом контексте Zipline.

Как бы вы подошли к моделированию угроз для системы управления дронами, учитывая сочетание облачного бэкенда и физических устройств в полевых условиях?

Вакансия делает особый упор на безопасность ИИ-агентов.

Какие конкретные механизмы контроля вы бы внедрили для предотвращения 'чрезмерной агентности' (excessive agency) у внутреннего LLM-помощника с доступом к API?

Оценка способности кандидата внедрять безопасность без ущерба для скорости разработки.

Опишите ваш опыт создания 'paved roads' (безопасных путей) для разработчиков. Как вы измеряете успех таких инициатив?

Проверка навыков реагирования на инциденты в сложной распределенной среде.

Как организовать логирование и аудит в системе с миллионами автономных миль, чтобы быстро восстановить цепочку событий при компрометации учетных данных в CI/CD?

Оценка лидерских качеств и умения убеждать.

Расскажите о случае, когда вам нужно было убедить команду разработчиков внедрить критическое изменение в архитектуру, которое замедляло их текущий спринт. Как вы достигли консенсуса?

Похожие вакансии

Атом Безопасность
200 000 ₽ – 400 000 ₽

Application Security Еngineer (AppSec)

УдалённоРоссия
C++ · Rust · JavaScript · Python · TypeScript · SAST · DAST · SCA · ASOC · CI/CD · GitLab CI · Docker · Fuzzing · Threat Modeling
+14 навыков
NDA
Не указана

Head of SOC (Центр мониторинга кибербезопасности)

HeadВ офисеКыргызстан
SoC · SIEM · Incident Response · Cybersecurity Strategy · Security Architecture · Team Management
+6 навыков
HaaS Platform
от 400 000 ₽

Pentester (Offensive Security)

SeniorУдалённоРоссия
Pentesting · Linux · Python · Bash · Burp Suite · NMAP · OWASP Top 10 · Network Security · Red Team · Vulnerability Assessment · Go · JavaScript · C++
+13 навыков
СберАвто
200 000 ₽ – 350 000 ₽

Специалист по информационной безопасности

SeniorУдалённоРоссия
Fortinet · Palo Alto Networks · Check Point · ELK stack · Splunk · Cisco Prime · MaxPatrol · ArcSight · SolarWinds · VPN · PKI · OSPF · EIGRP · BGP · Kaspersky Security Center · Cortex XDR · Solar Dozor · Ansible · Terraform · Vulnerability Management · Patch Management
+21 навыков
Крупная международная ИТ компания
Не указана

Solution Sales Consultant (Cybersecurity)

В офисеУзбекистан
Cybersecurity · Solution Sales · Discovery Sessions · Business Analysis · English · Russian · Uzbek
+7 навыков
СберАвто
Не указана

Application security specialist

SeniorУдалённоРоссия
SAST · DAST · IAST · RASP · SCA · WAF · SSDLC · DevSecOps · OWASP · Linux · Python · Go · Threat Modeling
+13 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

flyzipline
Страна
США
Зарплата
230 000 $ – 275 000 $