771,423open jobs
48,517companies
117,598added this week
Browse all
Salary
$210k – $247k per year
Location
Remote (United States, Canada)
Seniority
Staff · 7+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 25, 2026. First seen by Alion on Aug 10, 2026.

Overview
Company
Impact
Profile match
Redpanda SQL is a self-hosted data warehouse built for high-performance OLAP and time-series analytics. Postgres-compatible and powered by the Oxla MPP engine. Register for early access today.

Redpanda is the first runtime and control plane for agent-data interaction - a unified platform that combines streaming, SQL analytics, and intelligent connectivity with the governance layer enterprise AI agents need in production.

Built on infrastructure already trusted by Fortune 500 companies and fast-growing startups, Redpanda enforces governance entirely outside the agent's data path, controlling what agents see, limiting what they do, and capturing a tamper-proof record of everything they touch, so organizations never have to choose between innovation and control.

About the Role:

We're looking for an experienced Staff Security Engineer to own and scale application security across Redpanda's products, from the C++ core streaming engine to our Go cloud control plane, Console, and Rust/Go data-transform SDKs. Security at Redpanda is an engineering problem, not a checklist: you'll spend your time analyzing and breaking real systems code, building the paved roads and automation that make the secure path the default, and helping teams ship faster because security is built in rather than bolted on.

You'll be one of two engineers on a small, high-trust product security team, partnering every day with the engineers who build a system that Fortune 500 companies trust with their most critical data. Reporting to the Director of Information Security and working alongside our infrastructure security engineer, you'll own the day-to-day application-security work: secure SDLC, threat modeling, code-level vulnerability discovery, fuzzing the core engine, and our coordinated vulnerability disclosure and PSIRT response. As the application-security practice grows, you'll help shape its technical direction (in partnership with the Director, who owns the overall security program) and raise the security bar across all of engineering.

You Will:

  • Lead threat modeling and secure design reviews for new product features across the C++ engine, Go control plane, and Console, catching trust-boundary and authorization flaws before code is written.

  • Own and tune our application security testing (SAST, SCA / dependency scanning, secret scanning, and DAST) across C++, Go, and Rust, driving down false positives and gating the highest-severity findings in CI.

  • Build the fuzzing harnesses for the core engine (coverage-guided and protocol-aware) and partner with platform engineering to run them continuously, integrating sanitizers to surface memory-safety and parsing defects early.

  • Drive deep secure code review in systems languages, pairing your own expertise with AI-assisted analysis, and partner with engineering to eradicate whole classes of vulnerabilities rather than patching one bug at a time.

  • Operate our product security incident response (PSIRT) and coordinated vulnerability disclosure: triaging external researcher reports, driving fixes with engineering, and publishing advisories and CVEs.

  • Strengthen our software supply chain (dependency hygiene, SBOMs, build provenance, and progress toward higher SLSA build levels) in partnership with platform engineering.

  • Stand up a security champions program and secure-by-default building blocks (libraries, patterns, guardrails) so engineering teams can own security with your support.

  • Define security requirements and help shape the security release gates, and advise on product security features: authentication, authorization / RBAC, encryption, audit logging, multi-tenant isolation, and the Agentic Data Plane.

  • Raise the security bar across engineering through pragmatic standards, training, and hands-on partnership, using modern AI-assisted development workflows (including tools like Claude Code) to scale your impact.

You Have:

  • 7+ years in application or product security or adjacent specialties, with a track record of owning AppSec initiatives end-to-end and influencing engineering teams without direct authority.

  • The ability to review and reason about code in a systems language (C++ or Rust strongly preferred, since our core engine is C++; Go valuable across the cloud control plane and tooling), whether reviewing it directly or with AI assistance, with strong instincts for memory safety, concurrency, and the vulnerability classes that matter (use-after-free, buffer overflow, injection, authorization flaws).

  • Comfort with the security risks of memory-unsafe code and the appetite to fuzz it; fuzzing or sanitizer experience is a strong plus.

  • Practical proficiency with the AppSec toolchain (SAST, SCA, secret scanning, DAST) and the judgment to apply risk-based prioritization rather than rigid textbook approaches.

  • Demonstrated experience leading threat modeling and secure design reviews for non-trivial systems.

  • Working knowledge of software supply-chain security (dependencies, SBOMs, signing, SLSA) and secure CI/CD practices.

  • Familiarity with cloud (AWS / GCP / Azure) and Kubernetes security as it relates to the application layer.

  • Excellent written and verbal communication skills; comfortable working in a globally distributed, async environment (e.g., GitHub).

Nice to Have:

  • Experience with fuzzing (libFuzzer / AFL++ / OSS-Fuzz) and sanitizers (ASan / UBSan / MSan) on a C or C++ codebase.

  • Background securing distributed systems, databases, or data-infrastructure products, including threat modeling consensus / replication and multi-tenant isolation.

  • Experience running a PSIRT, operating as a CNA, or managing a bug bounty / coordinated disclosure program.

  • Exposure to compliance programs (SOC 2, ISO 27001, HIPAA, FedRAMP) from the engineering-evidence side.

  • Contributions to open-source security, or experience handling vulnerabilities in a public open-source repository.

U.S. base salary range for this role is $210,000 - $247,000. Our salary ranges are determined by role, level, and location. We strive to consider each candidate's job-related skills, location, experience, relevant education or training to determine individual base salary. Your talent partner will share more about the specific salary range for your preferred location during the hiring process.

Please note that Redpanda uses artificial intelligence (AI) technology to assist in the screening and assessment of applications for this position. However, all final hiring decisions are made by our human hiring team.

Vacancy Status: This job posting is for an existing vacancy.

Join Redpanda if you’d enjoy being part of a fast-moving, diverse, people-first organization with team members around the globe and a culture based on trust, transparency, communication, and kindness. You'll dive into a nimble, high-impact team with the latest AI tools - and the budget to actually use them.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
771,423 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
In your city
≈ $80k – $180k per year (Estimated) • Remote (Spain) • Full-Time • 5+ years exp • Lecce • Valencia • Elche • Paris
Python
Ruby
PowerShell
Bash
DevOps
Splunk
GCP
Azure
AWS
Linux
Windows
TCP/IP
Cybersecurity
Crowdstrike
Microsoft Sentinel
Microsoft Defender
GDPR
IBM QRadar
SIEM
Apply
≈ $48k – $107k per year (Estimated) • Remote (India) • Full-Time • 5+ years exp
Python
Ruby
PowerShell
Bash
DevOps
Splunk
GCP
Azure
AWS
Linux
Windows
Cybersecurity
Crowdstrike
Microsoft Sentinel
Microsoft Defender
GDPR
IBM QRadar
SIEM
Apply
≈ $80k – $180k per year (Estimated) • Remote (Spain) • Full-Time • 5+ years exp • Lecce • Valencia • Elche • Paris
Python
Ruby
PowerShell
Bash
DevOps
Splunk
GCP
Azure
AWS
Windows
Cybersecurity
Crowdstrike
Microsoft Sentinel
Microsoft Defender
GDPR
IBM QRadar
SIEM
Apply
≈ $34k – $76k per year (Estimated) • Remote (India) • 6+ years exp • Gurgaon
DevOps
Azure
AWS
Incident Management
BGP
OSPF
MPLS
Apply
≈ $118k – $240k per year (Estimated) • Remote (United States) • 8+ years exp • Bachelor's Degree • Cleveland
DevOps
Splunk
Linux
Unix
Cybersecurity
GDPR
Sumo Logic
SIEM
Apply
$209k – $239k per year • In office • Full-Time • 9+ years exp • Bachelor's Degree • Chicago
Python
Java
SQL
Scala
Python
pySpark
Databases
Snowflake
Databricks
Cassandra
DynamoDB
Amazon Redshift
AI/ML
Spark
Dagster
Machine Learning
DevOps
Splunk
GCP
Azure
AWS
Management
Agile
Apply
≈ $111k – $244k per year (Estimated) • Equity • In office • Full-Time • Durham
Python
C++
AI/ML
Computer Vision
DevOps
Docker
Apply
$90k – $130k per year • Equity • In office • Full-Time • 1+ year exp • Durham
Python
C++
AI/ML
Computer Vision
Machine Learning
Apply
Mechatronics Engineer 3 hours ago
$90k – $120k per year • Equity • In office • Full-Time • 1+ year exp • Durham
Python
C++
AI/ML
Computer Vision
DevOps
Docker
Apply
Firmware Engineer 3 hours ago
$80k – $110k per year • Equity • In office • Full-Time • 1+ year exp • Durham
Python
C++
AI/ML
Computer Vision
DevOps
Docker
Apply
≈ $76k – $138k per year (Estimated) • Hybrid • Full-Time • 7+ years exp • Warsaw
Go
JavaScript
TypeScript
SQL
Databases
Redpanda
AI/ML
Claude Code
AI Agents
Frontend
React.js
DevOps
GCP
Azure
AWS
Management
Stripe
Apply
≈ $79k – $143k per year (Estimated) • Hybrid • Full-Time • 10+ years exp • Warsaw
SQL
Databases
Redpanda
AI/ML
Model Context Protocol
AI Agents
LLM
A2A
Tool Use
DevOps
GitHub
Apply
≈ $84k – $133k per year (Estimated) • Hybrid • Full-Time • Warsaw
JavaScript
TypeScript
SQL
Databases
Apache Kafka
Redpanda
AI/ML
Claude Code
AI Agents
Frontend
Webpack
React.js
Vite
React Query
Rspack
pnpm
Turborepo
DevOps
gRPC
Netlify
GitHub
Design
Figma
Apply
$175k – $206k per year • Remote (United Kingdom) • Full-Time • 10+ years exp
SQL
Databases
Apache Kafka
Redpanda
AI/ML
AI Agents
Flink
LLM
OpenAI
Anthropic
Management
Stripe
Apply
$194k – $229k per year • Remote (United States) • Full-Time • 10+ years exp • New York
SQL
Databases
Apache Kafka
Redpanda
AI/ML
AI Agents
Flink
LLM
OpenAI
Anthropic
Management
Stripe
Apply
See all jobs
This is one of many
771,423 more open roles from verified company boards, updated every day.