Staff Software Engineer - Security
As a Staff Software Engineer - Security, you will design, review, and build systems to secure Skydio's cloud and corporate environments. You will partner with cross-functional teams on architectural decisions and build internal security tooling, playing a key role in protecting commercial, government, and DoD customers.
About the job
About the Role:
As a Staff Software Engineer - Security at Skydio, you will partner closely with security engineers and cross-functional teams to design, review, and build systems that secure our multi-tenant cloud and corporate environments. You will split your time roughly evenly between architecture and hands-on engineering. On one side, you will review RFCs, shape system design, and advise on initiatives with meaningful security implications. On the other, you will build and harden internal security tooling end to end. You will play a key role in maturing the systems that protect Skydio’s commercial, government, and DoD customers.
How you’ll make an impact:
- Review RFCs and partner with engineering teams on architectural decisions that have security implications
- Design and build internal security systems end to end, including roadmap areas such as web application firewalls and vulnerability risk management tooling
- Harden and improve security-related production software components as opportunities for better resilience and protection are identified
- Partner with Compliance to translate FedRAMP, SOC 2, Texas RAMP, ISO 27001, and CJIS requirements into practical technical controls
- Improve how we monitor, prioritize, patch, and respond to vulnerabilities across our cloud footprint
- Contribute to authentication and identity systems across cloud and corporate environments, including SSO and SCIM implementations
- Participate in the security team’s on-call rotation
What makes you a good fit:
- 7+ years of experience in cloud security, platform security, infrastructure security, or a related security-focused engineering role
- Strong experience working in AWS, ideally in multi-tenant cloud environments
- Strong coding ability and comfort building and maintaining tooling in languages such as Python or Go
- Experience reviewing system designs and RFCs and providing clear, actionable security guidance
- Working knowledge of SIEM, vulnerability management, and related security tooling
- Comfort operating across both technical design and hands-on implementation in a role that spans both strategy and execution
Nice to have:
- Experience working in FedRAMP, SOC 2, ISO 27001, Texas RAMP, or CJIS-aligned environments
- Experience building or deeply integrating authentication and identity systems, including SSO, SCIM, and front-door authentication
- Experience with Kubernetes debugging, operations, or automation
- Background supporting government, defense, or other highly regulated customers
Compensation:
At Skydio, our compensation packages for regular, full-time employees include competitive base salaries, equity in the form of stock options, and comprehensive benefits packages. Compensation will vary based on factors, including skill level, proficiencies, transferable knowledge, and experience. Relocation assistance may also be provided for eligible roles. The annual base salary range for this position is $220,000 - 270,000*. Fundamentally, we believe that equity is the key to long-term financial growth, and we ensure all regular, full-time employees have the opportunity to significantly benefit from the company's success. Regular, full-time employees are eligible to enroll in the Company’s group health insurance plans. Regular, full-time employees are eligible to receive the following benefits: Paid vacation time, sick leave, holiday pay and 401K savings plan. This position and all associated benefits are subject to applicable federal, state, and local laws, as well as the Company’s policies and eligibility criteria.
*Compensation for certain positions may vary based on the position’s location.
Skills
Cloud Security, AWS, Python, Go, SIEM, Vulnerability Management, FedRAMP, SOC 2, ISO 27001, Kubernetes
Similar jobs
Security Engineering jobsDesign and operate distributed, low-latency infrastructure that protects Reddit from DDoS attacks, bots, scraping, and other network threats. The role requires 7+ years of distributed-systems experience plus expertise in security, networking, and production operations.
Staff-level AppSec engineer building secure coding practices and vulnerability management for a commerce platform. Requires 6+ years in application security with deep AWS and Python experience.
Staff Security Software Engineer leading identity and access strategy, architecture, and hands-on platform development across customer, employee, contractor, and agentic identities. Requires 10+ years of production software experience and deep expertise in identity and authorization systems.
Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.
Own and scale IT general controls, access governance, segregation of duties, and audit readiness across enterprise applications. The role combines SOX expertise with AI-enabled continuous controls monitoring and requires 10+ years of controls, audit, or enterprise governance experience.