Skip to content
Order.coOrder.co

Staff Security Engineer

Staff-level security engineer owning cross-team security architecture, leading complex initiatives, and mentoring senior engineers. Requires deep expertise in Ruby on Rails, AWS, cloud security, compliance frameworks, and production systems at scale.

About the job

Responsibilities

  • Own Platform team-level architectural security decisions; research, design and own security frameworks, evolution paths, and technical debt strategy while others build against your direction
  • Lead and contribute to large, complex security initiatives; decompose work, coordinate execution, and surface risks before they become incidents
  • Proactively detect and remediate security vulnerabilities with discernment using AI tooling as an accelerant while applying rigorous judgment on correctness and risk
  • Champion security standards, testing patterns, and observability; driving improvements in security beyond your immediate team by embedding security in the software development lifecycle and infrastructure changes
  • Mentor senior engineers toward Staff-level behaviors; your impact compounds through the engineers you develop, not just the code you write
  • Align multiple teams on security strategy; translate business goals into secure system design and represent security strategy in organizational discussions

Requirements

  • Proficiency in Ruby on Rails and PostgreSQL, including understanding the framework's security tools (Active Record encryption, CSP, sanitization, asynchronous background processing)
  • Hands-on security experience with AWS, infrastructure as code, and CI/CD at scale
  • Expert-level knowledge of network security, operating systems (Linux), and cloud platforms
  • Experience with NIST, ISO27001, CIS MITRE ATT&CK, CSA CCM, SOC2, GDPR frameworks
  • Strong track record with cloud security, API security, secure software development, threat modeling, identity and access management, network segmentation, vulnerability management, incident response, and compliance-driven security controls

Nice-to-Haves

  • You've owned production systems at scale and made security trade-offs under real constraints
  • You self-direct technical improvement work beyond the product roadmap
  • You develop others and make engineers around you more effective and higher-scope

Skills

Ruby on Rails, Postgres, AWS, Infrastructure As Code, CI/CD, Network Security, Linux, Cloud Security, Api Security, Threat Modeling, Identity And Access Management, Nist, ISO 27001, SOC 2, GDPR

Mysten Labs

Mysten Labs

United States

Staff Security Engineer, Walrus
$180k+/yrRemote8+ YOESecurity Engineering

Leads security architecture, assessments, automation, and security-by-design practices for the Walrus team and broader ecosystem. The role requires 8+ years of security engineering experience, broad technical expertise, and Staff-level leadership.

Grow Therapy

Grow Therapy

Seattle, WA
Senior/Staff Engineer, Application & Product Security
$182k+/yrRemote6+ YOESecurity Engineering

Build and lead application and product security practices across a 145-engineer organization, embedding secure defaults, CI guardrails, threat modeling, and vulnerability mitigation into product development. The role requires 6+ years of hands-on security experience, strong coding ability, and microservices expertise.

Ironclad

Ironclad

San Francisco, CA

Staff IAM Engineer
$170k+/yrHybrid4+ YOESecurity Engineering

Own security-critical identity and corporate security controls, managing IAM platforms, SSO/MFA integrations, RBAC policies, and endpoint trust for macOS/Windows environments.

Chainguard

Chainguard

United States
Staff Vulnerability Management Engineer
$170k+/yrRemote7+ YOESecurity Engineering

Leads vulnerability disclosure operations at scale, including novel vulnerability measurement, CVE assignment, embargo coordination, and industry collaboration. The Staff individual contributor provides technical leadership and requires extensive software security or open source experience.

GitLab

GitLab

United States
Staff Security Researcher
$168k+/yrRemote7+ YOESecurity Engineering

Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.