Security Engineer

🏢 SambaSafety · all SambaSafety jobs
📍 United States
💰 USD 130,000 - 150,000 / annual
📅 Posted 2026-08-12 · via Himalayas
🏷 Security-Engineering,Application-Security,Vulnerability-Management,Threat-Detection,Cybersecurity,Security-Engineer,IT-Security-Engineer,Information-Security-Engineer,Cybersecurity-Engineer
Apply on original site ↗

Who we are:

Hi, we’re SambaSafety and we offer the industry’s most comprehensive driver monitoring software. Our mission is promoting safer communities by reducing risk through data insights. Companies trust SambaSafety to keep their employees safe on the roads, price and reduce risk, help protect their brand, their bottom line, and our global community.

We’ve built an inclusive, supportive, and exceptional culture where every employee is empowered in their role. Don’t take our word for it; we’ve been recognized as a Top Workplace by The Denver Post, Albuquerque Journal, Sacramento Bee, and Built In Colorado. And our employees rate SambaSafety as top-notch, with a rock solid Top Rating on Glassdoor.
What You’ll Do:

We are seeking an experienced Security Engineer to join our growing security team in a multifaceted role that combines vulnerability management, application security, MITRE ATT&CK-based threat detection, AI-driven security automation, and security engineering expertise. This position requires a technical security professional with knowledge spanning cloud security, identity and access management (IAM), endpoint detection and response (EDR), SIEM administration, and hands-on scripting for automation development. The successful candidate will work closely with development teams, infrastructure teams, vendors, and internal stakeholders to optimize our security posture and manage enterprise risk.
Key Responsibilities:

Application Security & Vulnerability Remediation

- Lead application security vulnerability remediation efforts across development teams

- Administer SAST tooling

- Administer DAST tooling

- Administer SCA and software composition / dependency scanning tools

- Triage and validate vulnerability findings to reduce false positives

- Provide remediation guidance to development teams on OWASP Top 10 and secure coding practices

- Integrate scanning tools with ticketing systems and CI/CD pipelines

- Generate AppSec metrics and reports

- Provide security code review support

Vulnerability Assessment & Management

- Administer vulnerability management platforms

- Configure scan policies, schedules, and asset groups

- Validate and prioritize vulnerability findings using risk-based prioritization (CVSS + context)

- Conduct expert analysis and risk scoring of vulnerabilities

- Coordinate remediation with IT and development teams

- Manage vulnerability exceptions and risk acceptances

- Track vulnerability aging and SLA compliance

- Generate management reports and dashboards

- Participate in product vulnerability management meetings

- Participate in Security by Design reviews

MITRE ATT&CK & Threat Detection

- Develop detection rules mapped to ATT&CK techniques

- Implement ATT&CK-based alert triage workflows

- Configure SIEM correlation rules using ATT&CK

- Conduct gap analysis of ATT&CK coverage

- Integrate threat intelligence feeds with ATT&CK mapping

- Build ATT&CK-based hunting queries

- Create ATT&CK-mapped incident reports

AI-Driven Security Automation & Agent Engineering

- Build and maintain scripted, cloud-based automation pipelines supporting the team's AI-driven security operations platform

- Develop and tune AI agent prompts, verdict logic, and disposition rules for automated alert triage

- Extend the team's internal tool-integration framework connecting security platforms for AI-assisted operations

- Integrate automation with SIEM, EDR, and ticketing systems

- Build automated enrichment and reporting workflows

- Monitor and tune agent/automation performance and disposition accuracy

- Develop custom integrations using APIs and cloud-native services

- Maintain observability for automated security workflows

Security Engineering & Architecture

- Lead Tier 2/3 security incident investigation and response

- Administer EDR, SIEM, and IAM platforms

- Implement and tune detection rules and alerts

- Manage cloud security configurations

- Support penetration testin

← All remote jobs