Roboflow Logo

Roboflow

Security Engineer

Posted 14 Days Ago
In-Office or Remote
2 Locations
165K-200K Annually
Senior level
In-Office or Remote
2 Locations
165K-200K Annually
Senior level
Lead security for the full stack: design secure architectures, build CI/CD and IaC tooling, run threat modeling, red-team/pen tests, incident response, and operate the bug bounty program to prevent and remediate vulnerabilities.
The summary above was generated by AI
Who We Are

Our mission is to make the world programmable. Sight is one of the key ways we understand the world, and soon this will be true for the software we use, too.

We’re building the tools, community, and resources needed to make the world programmable with artificial intelligence. Roboflow simplifies building and using computer vision models. Today, over 1M+ developers, including those from half the Fortune 100, use Roboflow’s machine learning open source and hosted tools. That includes counting cells to accelerate cancer research, improving construction site safety, digitizing floor plans, preserving coral reef populations, guiding drone flight, and much more.

Roboflow is supported by great customers and investors, having raised over 63 million from Y Combinator, Google Ventures, Craft Ventures, Sam Altman, Lachy Groom, amongst other leading software investors.

We are looking for a Senior Security Engineer who views security as an engineering challenge, not a checkbox exercise. You will join our Infrastructure Team to own security across our entire stack (from the low-level GKE configurations to the high-level application logic).

In a startup of our size, "chaos" is just another word for "opportunity." You aren’t here to just manage compliance spreadsheets or interface with IT; you are here to build the tooling, automation, and architecture that makes it impossible for our developers to make a critical mistake as we continually increase velocity.

What You’ll Do
  • Own the Stack: Secure everything from our Kubernetes clusters on the cloud to our SaaS integrations and developer workflows.

  • Usher in the Future: articulate and execute on a vision for what security should be in the age of LLMs giving both us and attackers increasing leverage.

  • Engineer for Security: Build internal tooling and CI/CD automations that catch vulnerabilities before they ever hit production.

  • Architect & Model: Lead threat modeling sessions and secure code reviews, ensuring we design "secure-by-default" APIs and deployments.

  • Harden the Perimeter: Take a first-principles approach to hardening authentication and access control across all internal and external surfaces.

  • Red Team: proactively probe for vulnerabilities and lead the remediation.

  • Lead the Bug Bounty: You will be the primary owner for standing up, launching, and managing our Bug Bounty Program, triaging reports, and driving remediation.

  • Respond & Remediate: Investigate vulnerabilities, lead incident response, orchestrate pen testing, and run blameless postmortems that actually result in systemic change.

  • Evangelize: Be the partner, not the blocker. Translate complex security risks into actionable engineering tasks that your peers can get excited about.

Who You Are
  • Startup Native: You thrive in a fast paced 100–300 person environments. You know how to prioritize when everything feels urgent and are comfortable "failing forward" to find the right solution.

  • Security-First Engineer: You have 6+ years of experience in software/infrastructure engineering with a deep obsession with security. You don't just find holes; you write the code to plug them.

  • Cloud Savvy: You are deeply familiar with Google Cloud (GCP), Kubernetes, and containerized environments.

  • Systems Thinker: You can analyze a system for weaknesses whether they are buried in business logic, IAM configurations, or the codebase.

  • Action-Oriented: You have a track record of responding to real-world incidents and leading remediation efforts without being the "no" person.

Our Technical Stack
  • Cloud: Google Cloud Platform (GCP)

  • Orchestration: Kubernetes (GKE)

  • Infrastructure: Terraform / Infrastructure-as-Code

  • Pipeline: Modern CI/CD workflows and various SaaS integrations

Where You'll Work

Roboflow is distributed across the US and Europe. We currently have Hubs in New York City and San Francisco (and plan to open more as we grow density in new cities). We provide opportunities (like team onsites in different cities) and resources (like a $4000/yr travel stipend) to work in person with other team members as much as you'd like, while also supporting remote team members. You can work from one of our Hubs (we offer a relocation bonus), work from home, work at co-working spaces, etc. We want you to work where you work best!

What You’ll Receive

To determine your salary, we use a number of market and data-driven salary sources. We review all salaries every six months to ensure we stay in line with the market.

The target salary for this position ranges from $165,000-$200,000

📈 In addition to our cash compensation, we offer generous perks and benefits. Below are some of the highlights:

  • $4000/yr Travel Stipend to travel anywhere anytime to work alongside other Roboflowers

  • $350/mo Productivity stipend to spend on things that make your work environment more productive, like high-speed internet at home or a co-working space

  • $350/mo AI Tools stipend

  • $150/mo team lunch stipend

  • $500/one time home office stipend

  • Cover up to 100% of your health insurance costs for you and your partner or family

  • Equity in the company so we are all invested in the future of computer vision

Interview Process (6+ hours)

Below is the interview process you can expect for this role. We are all motivated to work with an exceptional team and you will be speaking directly with our team about what it's like to work and thrive at Roboflow. We like to be decisive and work fast, so don't be surprised if all the below conversations happen over a day or two.

Before the Interview:

  • We’ll review your application, LinkedIn, Github, etc.

  • The best way to stand out is to write about something you’ve built with Roboflow or contribute to one of our open source projects.

  • We may send you a technical screen if applicable.

Introduction Phase:

  • [30m] Meet with People Ops

  • [30m] Meet with hiring manager to assess for overall mindset and skillset

  • [45m] Technical Assessment

Team Interview Phase:

  • [30m] Meet with another member of the team

  • [60m] Meet with hiring manager or CTO

    • Use this time to review specifics about the job description

    • Begin working through your 30/60/90 projects

    • Ask questions!

Final Interview Stage:

  • [45m] Meet with Head of Operations for a culture discussion

  • [60m / Optional] Meet with Joseph Nelson, CEO

Note: you are welcome to request additional conversations with anyone you would like to meet and we will accommodate as best we can.

Learn More About Us

Roboflow is a diverse, distributed team and an Equal Opportunity Employer. We welcome applicants from all backgrounds and experiences. We offer competitive compensation and benefits, plus opportunities to learn from and contribute to our world-class team.

Equal Employment Opportunity

We’re committed to building an inclusive team where great ideas come from everywhere. We consider all qualified applicants regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, veteran status, or any other protected characteristic.

HQ

Roboflow San Francisco, California, USA Office

San Francisco, CA, United States

Similar Jobs

3 Days Ago
Remote
United States
114K-142K Annually
Mid level
114K-142K Annually
Mid level
Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Assess product and feature security risks through threat modeling, secure architecture reviews, and vulnerability remediation guidance. Partner with product managers, designers, and engineers across the technology stack; promote security culture through training, mentoring, and internal security activities; oversee security debt and explain vulnerability impacts. Build security tooling, automate security practices, develop secure coding patterns, and integrate security tools into engineering workflows.
Top Skills: CContainerizationContinuous DeliveryContinuous IntegrationGoJavaScriptOwasp Top TenRustVirtualization
6 Days Ago
Easy Apply
Remote
United States
Easy Apply
168K-238K Annually
Senior level
168K-238K Annually
Senior level
Cloud • Security • Software • Cybersecurity • Automation
Lead corporate endpoint security architecture with a focus on macOS, designing secure-by-default controls, automation, patching, software distribution, and security baselines across macOS, iOS, Windows, and Linux. Manage configurations through Terraform, GitOps, version control, CI pipelines, and automated rollouts. Partner with IT and security teams to improve telemetry, detection, response, auditability, and operational efficiency. Mentor engineers and serve as a senior escalation point for complex endpoint security issues in a fully remote environment.
Top Skills: BashFleetdmGitGitopsGoGoogle WorkspaceInfrastructure As CodeiOSJamf ProLdapLinuxmacOSOktaPowershellPythonTerraformWindows
9 Days Ago
Remote or Hybrid
USA
120K-180K Annually
Entry level
120K-180K Annually
Entry level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Designs and engineers secure network and cloud architectures across AWS, GCP, Azure, and physical data centers. Responsibilities include threat modeling, network segmentation, monitoring, alerting, automation, attack-surface reduction, and secure connection patterns. The role drives strategic security improvements, partners with product and infrastructure teams, communicates architectural decisions, and mentors engineers. Candidates need deep hybrid networking and cloud security expertise, protocol knowledge, scripting ability, independent problem-solving skills, and strong communication.
Top Skills: AIApplied CryptographyAWSAzureCi/CdDnsGCPGoHttp/SHybrid Cloud NetworkingPrivate EndpointsPythonService MeshesShell ScriptingTcp/IpTlsTransit GatewaysVpcsZero Trust Architecture

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account