{"id":2150232,"url":"https://alion.io/job/queue-senior-security-engineer","title":"Senior Security Engineer","company":{"id":3787073,"name":"Queue","domain":"queue.inc","url":"https://alion.io/company/queue-3","size_band":"11-50","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":{"grade":"B","score":75,"open_postings":4,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-10T05:45:15Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Newark, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":116000,"max_usd":226000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":1093},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"HIPAA","optional":false},{"name":"Linux","optional":false},{"name":"Python","optional":false},{"name":"Rust","optional":false},{"name":"Threat Modeling","optional":false},{"name":"TypeScript","optional":false},{"name":"AWS","optional":true}],"status":"live","first_seen_at":"2026-10-09T04:57:56Z","employer_posted_date":"2026-10-09","last_verified_at":"2026-10-11T00:42:33Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"About Us\nQueue builds robots to fill prescriptions. Our machine is designed to take stock bottles of medication and produce counted, labeled vials, so that pharmacists and technicians can spend their time on patients. Our first product is built to work behind the pharmacy counter and to be operated by pharmacy staff.\nAbout the Role\nYou own security engineering for a pharmacy robot and everything it talks to: the machine, its operating-system image, the software that runs on it, the cloud service that commands it, and the path that updates it. When a customer asks how each machine proves its identity, who can reach it and how, and what an independent test found and what was done about it, the answer rests on your work, and every statement in it is backed by something the system produces.\nWhat You'll Own\nThe threat model - A written model of the trust boundaries: machine to cloud, operator to screen, the update path, remote support, and suppliers. You keep it current as designs change.\n\nSecurity review of designs - Designs come to you early; you review them and your review is recorded.\n\nDevice identity and key custody - The threat model, the priorities and the verification are yours. The engineers who own the operating-system image build the platform side with you.\n\nIndependent security testing - Scope, test environment, triage, remediation with the owning squads, and retest evidence. You run it end to end.\n\nFinding and fixing weaknesses - How weaknesses in our code, dependencies, device images and cloud are found, triaged and fixed. It is shared with the squads that own each part: you set the rules, track each finding to closure and report where we stand.\n\nIncident response - The security side of every incident: detection, triage, containment, evidence and what changes afterwards. It is shared with the owning squads, and you run it with the systems reliability engineers, who run the operational response.\n\nCustomer security reviews - A customer's security review asks detailed questions and treats our answers as commitments. Before a statement is sent, you check it against the evidence that can substantiate it: the versioned implementation, the deployed configuration and the operational records. A statement says what is built, what is designed and what is planned, and keeps the three apart.\n\nCloud posture - Identity and access, secrets, the review of infrastructure changes, and what the cloud provider's detection services report.\n\nSecurity and privacy controls - For the controls Queue commits to, including those that follow from HIPAA, you verify each control in the system and take its evidence from the system.\n\nYou assess and you recommend. You do not accept risk on the company's behalf: an exception is recorded with its approver and conditions, and an authorized business owner accepts what remains.\nFirst 90 Days\nDay 30: You have traced the trust boundaries yourself, and you hold the threat model and the record of independent testing. You have reviewed your first design.\n\nDay 60: You hold the priorities and the verification for device identity and key custody, with the engineers who own the operating-system image. You hold the inventory of secrets and keys and their rotation schedule. Every security statement that goes to a customer passes your check first.\n\nDay 90: You have written the scope for the next independent test and prepared the environment it will run against. Every design that came to you has a recorded review. You can hand an assessor a control's evidence as output from the system.\n\nWhat We're Looking For\nMust-Have\nOwnership - you have owned the security of a shipped product end to end, and you can describe a problem you found, fixed and followed until it stayed fixed. Consulting alone or compliance alone is not this.\n\nYou build - you read and write code. Ours is Rust, TypeScript and Python: deep skill in one and comfort reading the others. Your reviews come with a patch or with guidance precise enough to act on.\n\nSystems and network depth - TLS and certificates, identity and access, secrets management, Linux hardening. You can reason about a trust boundary from the hardware to the cloud.\n\nOffensive fluency with defensive judgment - you have run or worked closely with penetration tests. You rank issues by what they could do to this system and its users, and you can defend deferring one.\n\nThreat modeling that engineers use - you would sooner remove an input than add a control, and engineers ask for your review.\n\nExact writing - you state what is true at the strength the evidence supports, to an engineer, an executive or a customer's assessor.\n\nNice-to-Have\nDevice security: verified start-up, hardware-held keys, signed updates, fleet identity.\n\nSecurity in healthcare or another regulated industry, and customer security reviews from the supplier's side.\n\nCloud security engineering on AWS.\n\nSupply-chain security: dependency policy, artifact signing, provenance.\n\nWorking knowledge of IEC 62443, UL 2900-1 or NISTIR 8259.\n\nHow We Hire\nRecruiter Screen (30 min)\n\nTechnical Interview (90 min) - a take-home exercise of 2 to 3 hours, sent at least 24 hours before: a small working system to harden. We go through it together: what you fixed first, and why.\n\nDesign Interview (60 min) - on trust boundaries and key custody.\n\nLeadership Interview (60 min) - how you own your work and work across squads.\n\nTwo interviewers score each technical stage independently.\nWhat We Offer\nOwnership - security engineering for the machine and everything it talks to\n\nHard problems: trust boundaries from the hardware to the cloud, device identity and key custody, and the path that updates the machine\n\nSmall team, zero bureaucracy, high trust\n\nWhy Join Us Now?\nImpact & Growth\nDirect Impact: You check every security statement against the evidence behind it before it goes to a customer\n\nGrowth: The work runs from the review of a design to an independent test and its retest\n\nTeam and Culture\nReports to the Head of Software Engineering with significant autonomy and influence\n\nThe same person sets the security requirements you work to\n\nWho You Work With: You work every day with the engineers who build the on-machine software, the cloud service and the operating-system image\n\nWhere We Work: Hybrid, three days a week at our headquarters in the Bay Area; device security work needs the hardware in front of you\n\nOur Values\nServant Leadership\n\nDo the Hard Things\n\nOwn Your Work\n\nDefault is Now\n\nOwn Your Work comes first in this role: you follow a problem until it stays fixed.\nContact: If you have any questions, please contact us ","description_format":"text","description_chars":6636,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Industrial Robotics"],"lifecycle":[{"event":"open","at":"2026-10-09T05:43:37Z"}],"visa":[],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":30,"reasons":["conf:1","velocity","win:early"],"computed_at":"2026-10-10T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/queue-senior-security-engineer","json_url":"https://alion.io/job/queue-senior-security-engineer.json","meta":{"generated_at":"2026-10-11T04:20:57Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2941,"day_limit":5000,"remaining_today":2059,"minute_limit":60,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":3787073},"rest":"https://alion.io/mcp/rest/get_company?id=3787073"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fqueue-senior-security-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fqueue-senior-security-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fqueue-senior-security-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/queue-senior-security-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fqueue-senior-security-engineer"}]}