Security Software Engineer
Software engineer focused on security and privacy, improving Tailscale's security through feature development, audits, threat modeling, and spending 50% time writing code. Requires proficiency in Go or similar, security experience, and deep knowledge of vulnerabilities and cryptography.
About the job
Job Description
We’re seeking a talented software engineer, specializing in security and privacy, to help grow our product security team. We’re looking for people who can move Tailscale forward while making it safer to use. The abilities to think on your feet, collaborate with highly technical teams, and be comfortable working asynchronously are essential.
Key Responsibilities
- Improve the security properties of Tailscale by identifying opportunities for security and privacy features, bug fixes, and defense-in-depth, and implementing them across our codebase.
- Audit Tailscale features for technical security weaknesses, identifying mitigations or solutions, and driving them towards resolution.
- Support engineering decisions with threat modeling and security analysis and expertise.
- You will spend at least 50% of your time in this role writing software vs purely operational or governance security responsibilities.
What We Are Looking For
Technical
- Proficiency developing in at least one programming language (Tailscale uses Go)
- Proficiency developing for at least one application platform (e.g. iOS, Android, web, Windows, macOS, Linux)
- Prior experience in a safety-related technical role, e.g.:
- application security or application platform security
- penetration testing
- threat modeling and prioritization
- user experience design or research
- digital forensics and incident response
- Deep understanding of web application vulnerabilities (e.g., OWASP Top 10), client-side security, and common API security flaws
- Collaborate with engineering teams to promote secure coding practices and provide targeted security guidance and training
- Knowledge of cryptographic primitives and protocols
- Knowledge of common networking protocols
Team Fit
- Ability to give and process constructive feedback
- Ability to work independently and collaboratively
- Flexibility to adjust to the dynamic nature of a startup
- Take a risk-based approach to building security controls, balancing your security expertise and broad technical skillsets with practical, usable solutions
Skills
Go, Owasp Top 10, Threat Modeling, Penetration Testing, Cryptography, Networking Protocols, Application Security, Secure Coding, Api Security, Linux
Similar jobs
Security Engineering jobsThe Application Security Engineer will embed security practices throughout the SaaS software development lifecycle, including threat modeling, automated testing, vulnerability remediation, and incident response. The role requires 5+ years of application or product security experience and expertise with DevSecOps workflows, web applications, and CI/CD automation.
The Cyber Threat Intel Analyst tracks, investigates, attributes, and reports on advanced threats targeting cloud, AI, and developer environments. The role requires at least three years of security or threat research experience and strong technical analysis and writing skills.
The GRC Analyst will operate and mature security and compliance programs across major privacy and security frameworks, supporting risk assessments, access reviews, third-party risk, control monitoring, and audits. The role requires 3–5 years of GRC or information security experience and strong cross-functional communication.
Develops safety requirements, analyses, and fail-operational architectures for autonomous-vehicle sensing and perception systems. The role requires 3+ years analyzing safety-critical systems and familiarity with functional-safety standards, sensing hardware, perception, and cross-functional systems engineering.
Own the security posture of a fast-growing developer product across application, infrastructure, cloud, and internal systems. The role requires at least three years of relevant engineering or security experience, strong vulnerability judgment, and hands-on JavaScript or TypeScript expertise.