Senior/Staff Security Engineer - Product Security

Zipline - South San Francisco, CA

Hiring: Senior/Staff Security Engineer - Product Security Company: Zipline Location: South San Francisco, CA Job Posted Time: 2026-09-10 10:33:46 Employment Type: Hybrid Target Skills & Keywords : CI/CD, Embedded Systems, IAM, Kubernetes, LLM, Microservices, OWASP, Python, Regulatory Compliance About the job Experience: •8+ years building and operating security controls for large-scale production systems across application and cloud infrastructure. Required Skills: •Own security outcomes for 2-4 named production areas (examples: fleet orchestration APIs, DC orchestration/robotics control plane, telemetry and command channels, developer CI/CD and secrets platforms). Be the primary security owner for at least one area on hire. •Threat model and perform secure design reviews for services that operate near the physical fleet, regulated workflows, or partner/customer interfaces; produce engineering-tractable mitigations and drive their rollout to completion. •Lead vulnerability management end-to-end for owned services: vulnerability triage with exploitability analysis, prioritized remediation plans with engineering partners, staged verification, and verification metrics for closure and regression prevention. •Build and harden incident response for product incidents: author playbooks, run tabletop exercises with product and operations, validate logging/auditability so incidents are forensic-ready, and participate in incident postmortems with corrective action tracking. •Secure AI/agent-assisted development and ops: define allowed copilots and patterns, implement guardrails to prevent secret exposure and unauthorized actions, and add monitoring/auditing for risky agent behaviors where it intersects owned systems. •Integrate external pentest and red-team results into durable engineering changes; turn test findings into tracked engineering tickets and measurable closure criteria. •Collaborate daily with SREs, platform engineers, autonomy/embedded teams, field ops, and compliance to translate regulatory/safety requirements (e.g., health-adjacent data handling, auditability) into concrete technical controls. Qualifications: •Demonstrable hands-on engineering ability: you ship automation or tooling in Python, Go, or similar and can build integrations with AI tools and agentic security bots (not only write policies). •Deep practical experience with cloud-native stacks and microservices (Kubernetes, containers, IAM, CI/CD, secrets management, logging/telemetry) and with designing least-privilege service-to-service models. •Prior ownership of vulnerability management, incident response playbooks, and verification processes for production services. •Direct experience threat‑modeling and securing systems that interface with physical systems, regulated workflows, or third-party partners (embedded, teleoperation, field ops, or healthcare-adjacent data flows). •Demonstrated capacity to define and track quantitative success metrics (MTTD, MTTR, number of exploitable findings, compliance audit readiness) and be accountable for meeting targets within 6–12 months. •Operates as a technical owner: can persuade engineering teams, prioritize trade-offs, and drive changes through to production without relying solely on policy enforcement. •Skeptical, adversarial mindset: anticipates failure modes and abuse cases for systems that interact with the physical fleet and partner workflows. •Background across multiple domains (cloud infra, web services, and embedded/autonomy) and experience building developer-friendly security platforms or paved-road tooling. •What Else You Need To Know •This is a hybrid role based in South San Francisco; frequent HQ presence required and occasional travel to field sites. This role has production ownership and will participate in incident response; candidates must be prepared for on-call participation when assigned. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!