Skip to main content
Redpanda

Staff Security Engineer

RemoteUnited States only
Published
Role
Security
Experience
Staff
Employment
Full-time
Company size
Startup
$210k–$247k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Experienced Staff Security Engineer needed to own and scale application security for Redpanda's products (C++, Go, Rust). Focus on secure SDLC, threat modeling, vulnerability discovery, fuzzing, and PSIRT response. Must have 7+ years in app/product security, ability to review systems code (C++/Rust preferred), and practical AppSec toolchain proficiency.

Core skills

application securityfuzzingsecure SDLC

Required skills

C++RustGoSASTSCAsecret scanningDASTSLSAAWSGCPAzureKubernetes

Optional skills

libFuzzerAFL++OSS-FuzzASanUBSanMSanSOC 2ISO 27001

Required languages

English

What you'll do

  • Lead threat modeling and secure design reviews for new product features across the C++ engine, Go control plane, and Console, catching trust-boundary and authorization flaws before code is written.
  • Own and tune our application security testing (SAST, SCA / dependency scanning, secret scanning, and DAST) across C++, Go, and Rust, driving down false positives and gating the highest-severity findings in CI.
  • Build the fuzzing harnesses for the core engine (coverage-guided and protocol-aware) and partner with platform engineering to run them continuously, integrating sanitizers to surface memory-safety and parsing defects early.
  • Drive deep secure code review in systems languages, pairing your own expertise with AI-assisted analysis, and partner with engineering to eradicate whole classes of vulnerabilities rather than patching one bug at a time.
  • Operate our product security incident response (PSIRT) and coordinated vulnerability disclosure: triaging external researcher reports, driving fixes with engineering, and publishing advisories and CVEs.
  • Strengthen our software supply chain (dependency hygiene, SBOMs, build provenance, and progress toward higher SLSA build levels) in partnership with platform engineering.
  • Stand up a security champions program and secure-by-default building blocks (libraries, patterns, guardrails) so engineering teams can own security with your support.
  • Define security requirements and help shape the security release gates, and advise on product security features: authentication, authorization / RBAC, encryption, audit logging, multi-tenant isolation, and the Agentic Data Plane.
  • Raise the security bar across engineering through pragmatic standards, training, and hands-on partnership, using modern AI-assisted development workflows (including tools like Claude Code) to scale your impact.

What they require

  • 7+ years in application or product security or adjacent specialties, with a track record of owning AppSec initiatives end-to-end and influencing engineering teams without direct authority.
  • The ability to review and reason about code in a systems language (C++ or Rust strongly preferred, since our core engine is C++; Go valuable across the cloud control plane and tooling), whether reviewing it directly or with AI assistance, with strong instincts for memory safety, concurrency, and the vulnerability classes that matter (use-after-free, buffer overflow, injection, authorization flaws).
  • Comfort with the security risks of memory-unsafe code and the appetite to fuzz it; fuzzing or sanitizer experience is a strong plus.
  • Practical proficiency with the AppSec toolchain (SAST, SCA, secret scanning, DAST) and the judgment to apply risk-based prioritization rather than rigid textbook approaches.
  • Demonstrated experience leading threat modeling and secure design reviews for non-trivial systems.
  • Working knowledge of software supply-chain security (dependencies, SBOMs, signing, SLSA) and secure CI/CD practices.
  • Familiarity with cloud (AWS / GCP / Azure) and Kubernetes security as it relates to the application layer.
  • Excellent written and verbal communication skills; comfortable working in a globally distributed, async environment (e.g., GitHub).

Benefits

  • Join Redpanda if you’d enjoy being part of a fast-moving, diverse, people-first organization with team members around the globe and a culture based on trust, transparency, communication, and kindness.
  • You'll dive into a nimble, high-impact team with the latest AI tools — and the budget to actually use them.

Redpanda is the first runtime and control plane for agent-data interaction — a unified platform that combines streaming, SQL analytics, and intelligent connectivity with the governance layer enterprise AI agents need in production.

Data InfrastructureStartup
$210k–$247k/yr