Staff Security Engineer
Staff Security Engineer owns security across applications, infrastructure, and workflows at LiveKit. Requires 6+ years software engineering experience, hands-on security expertise in cloud/container environments, threat modeling, and incident response.
About the job
Responsibilities
- Own security across the stack—applications, services, infrastructure, and developer workflows.
- Proactively identify, assess, and mitigate risks in both infrastructure and application codebases.
- Lead secure code reviews, architecture discussions, and threat modeling sessions.
- Build tooling and automations that help prevent security issues before they reach production.
- Harden authentication and access control across internal and external surfaces.
- Partner closely with engineers across teams to design secure-by-default APIs, workflows, and deployments.
- Investigate vulnerabilities, respond to security incidents, and manage disclosure processes when needed.
- Stay current with security research, tooling, and threats—then put that knowledge into action.
Requirements
- Hands-on engineer who understands security from first principles.
- 6+ years of experience as a software engineer with an interest in security engineering.
- Led or heavily contributed to security engineering efforts across applications, infrastructure, or both.
- Analyze systems for weaknesses—whether they’re in business logic, configuration, or code.
- Experienced with threat modeling, secure coding practices, and vulnerability management.
- Worked with CI/CD systems, cloud platforms (AWS, GCP, etc.), and containerized environments.
- Translate security concerns into engineering action without being the “no” person.
- Excellent communicator and collaborator who can document and evangelize best practices.
- Responded to real-world security incidents, led postmortems, or driven remediation efforts.
Nice-to-Haves
- Experience with security reviews of WebRTC, media pipelines, or real-time systems.
- Contributions to open-source security tooling or research.
- Hands-on experience with static and dynamic analysis tools, fuzzing, or sandboxing.
Compensation
- Competitive salary and equity package.
- Health, dental, and vision benefits.
- Flexible vacations.
- Remote-friendly work environment, with equipment provided.
Skills
AWS, GCP, CI/CD, Kubernetes, Threat Modeling, Secure Coding, Vulnerability Management, Webrtc, Static Analysis, Dynamic Analysis, Fuzzing, Sandboxing
Similar jobs
Security Engineering jobsLeads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.
Leads enterprise AI security architecture and develops security systems, automation, and agentic AI identity strategies at scale. Requires 7+ years in security or infrastructure security, enterprise technical leadership, cloud and container security expertise, and strong programming skills.
Leads enterprise Zero Trust and secure-access networking, owning Zscaler architecture and operations while supporting Palo Alto, wireless, LAN/WAN, and multi-cloud infrastructure. The role requires 10+ years of network experience, deep ZIA/ZPA expertise, automation skills, and major-incident leadership.
Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.
Staff Identity Engineer serving as a technical authority for enterprise IAM, owning Okta architecture, cloud identity guardrails, automation, and AI identity security. Requires deep Okta and authentication-protocol expertise, multi-cloud experience, and technical leadership.