Redpanda Data
Staff Security Engineer
Remote work allowed only within certain countries or regions.
Employer listed it 6 weeks ago · Added yesterday
Been open since 6 weeks ago, still being checked, but it has been live a while.
Salary
$210k to $247k per year
Location
Work style
Async
Contract
Full-time
Experience
Lead
Category
Software
Stated by the employer in the job description
Remote flexibility
Region Restricted
Remote work is allowed, but only for candidates based in United States, Canada.
What the employer says
- Source listing states candidate location: "US - Remote, Canada - Remote, Remote"
What Nomaders makes of it
- Applications outside the listed area are usually rejected
- Timezone overlap with the listed area is often expected
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Redpanda is the first runtime and control plane for agent-data interaction — a unified platform that combines streaming, SQL analytics, and intelligent connectivity with the governance layer enterprise AI agents need in production.
Built on infrastructure already trusted by Fortune 500 companies and fast-growing startups, Redpanda enforces governance entirely outside the agent's data path, controlling what agents see, limiting what they do, and capturing a tamper-proof record of everything they touch, so organizations never have to choose between innovation and control.
About the Role:
We're looking for an experienced Staff Security Engineer to own and scale application security across Redpanda's products, from the C++ core streaming engine to our Go cloud control plane, Console, and Rust/Go data-transform SDKs. Security at Redpanda is an engineering problem, not a checklist: you'll spend your time analyzing and breaking real systems code, building the paved roads and automation that make the secure path the default, and helping teams ship faster because security is built in rather than bolted on.
You'll be one of two engineers on a small, high-trust product security team, partnering every day with the engineers who build a system that Fortune 500 companies trust with their most critical data. Reporting to the Director of Information Security and working alongside our infrastructure security engineer, you'll own the day-to-day application-security work: secure SDLC, threat modeling, code-level vulnerability discovery, fuzzing the core engine, and our coordinated vulnerability disclosure and PSIRT response. As the application-security practice grows, you'll help shape its technical direction (in partnership with the Director, who owns the overall security program) and raise the security bar across all of engineering.
You Will:
Lead threat modeling and secure design reviews for new product features across the C++ engine, Go control plane, and Console, catching trust-boundary and authorization flaws before code is written.
Own and tune our application security testing (SAST, SCA / dependency scanning, secret scanning, and DAST) across C++, Go, and Rust, driving down false positives and gating the highest-severity findings in CI.
Build the fuzzing harnesses for the core engine (coverage-guided and protocol-aware) and partner with platform engineering to run them continuously, integrating sanitizers to surface memory-safety and parsing defects early.
Drive deep secure code review in systems languages, pairing your own expertise with AI-assisted analysis, and partner with engineering to eradicate whole classes of vulnerabilities rather than patching one bug at a time.
Operate our product security incident response (PSIRT) and coordinated vulnerability disclosure: triaging external researcher reports, driving fixes with engineering, and publishing advisories and CVEs.
Strengthen our software supply chain (dependency hygiene, SBOMs, build provenance, and progress toward higher SLSA build levels) in partnership with platform engineering.
Stand up a security champions program and secure-by-default building blocks (libraries, patterns, guardrails) so engineering teams can own security with your support.
Define security requirements and help shape the security release gates, and advise on product security features: authentication, authorization / RBAC, encryption, audit logging, multi-tenant isolation, and the Agentic Data Plane.
Raise the security bar across engineering through pragmatic standards, training, and hands-on partnership, using modern AI-assisted development workflows (including tools like Claude Code) to scale your impact.
You Have:
7+ years in application or product security or adjacent specialties, with a track record of owning AppSec initiatives end-to-end and influencing engineering teams without direct authority.
The ability to review and reason about code in a systems language (C++ or Rust strongly preferred, since our core engine is C++; Go valuable across the cloud control plane and tooling), whether reviewing it directly or with AI assistance, with strong instincts for memory safety, concurrency, and the vulnerability classes that matter (use-after-free, buffer overflow, injection, authorization flaws).
Comfort with the security risks of memory-unsafe code and the appetite to fuzz it; fuzzing or sanitizer experience is a strong plus.
Practical proficiency with the AppSec toolchain (SAST, SCA, secret scanning, DAST) and the judgment to apply risk-based prioritization rather than rigid textbook approaches.
Demonstrated experience leading threat modeling and secure design reviews for non-trivial systems.
Working knowledge of software supply-chain security (dependencies, SBOMs, signing, SLSA) and secure CI/CD practices.
Familiarity with cloud (AWS / GCP / Azure) and Kubernetes security as it relates to the application layer.
Excellent written and verbal communication skills; comfortable working in a globally distributed, async environment (e.g., GitHub).
Requirements
- ·7+ years in application or product security or adjacent specialties, with a track record of owning AppSec initiatives end-to-end and influencing engineering teams without direct authority.
- ·Comfort with the security risks of memory-unsafe code and the appetite to fuzz it; fuzzing or sanitizer experience is a strong plus.
- ·Practical proficiency with the AppSec toolchain (SAST, SCA, secret scanning, DAST) and the judgment to apply risk-based prioritization rather than rigid textbook approaches.
- ·Demonstrated experience leading threat modeling and secure design reviews for non-trivial systems.
- ·Working knowledge of software supply-chain security (dependencies, SBOMs, signing, SLSA) and secure CI/CD practices.
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, region restricted, matches where you plan to live and work.
- 2Tailor your CV to the role at Redpanda Data, mentioning your remote working experience and working hours (Async).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 1d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$210k to $247k per year · You'll be taken to the employer's careers page.