Logo for Roboflow

Security Engineer

Roles & Responsibilities

  • 6+ years of software/infrastructure engineering experience with a strong focus on security
  • Deep familiarity with Google Cloud Platform (GCP), Kubernetes (GKE), and containerized environments
  • Systems thinking: ability to analyze a system for weaknesses across code, IAM configurations, and business logic
  • Action‑oriented with a track record of incident response and leading remediation efforts

Requirements:

  • Own the stack: secure Kubernetes clusters, cloud infrastructure, SaaS integrations, and developer workflows across the stack
  • Architect and engineer for security: lead threat modeling and secure-code reviews; build internal tooling and CI/CD automation to catch vulnerabilities before production; ensure secure-by-default APIs and deployments
  • Harden the perimeter and respond: implement strong authentication and access controls; lead vulnerability remediation, incident response, and postmortems
  • Lead red team activities and bug bounty program: proactively probe for vulnerabilities, triage reports, drive remediation, and translate security risks into actionable engineering tasks

Job description

Who We Are

Our mission is to make the world programmable. Sight is one of the key ways we understand the world, and soon this will be true for the software we use, too.

We’re building the tools, community, and resources needed to make the world programmable with artificial intelligence. Roboflow simplifies building and using computer vision models. Today, over 1M+ developers, including those from half the Fortune 100, use Roboflow’s machine learning open source and hosted tools. That includes counting cells to accelerate cancer research, improving construction site safety, digitizing floor plans, preserving coral reef populations, guiding drone flight, and much more.

Roboflow is supported by great customers and investors, having raised over 63 million from Y Combinator, Google Ventures, Craft Ventures, Sam Altman, Lachy Groom, amongst other leading software investors.

We are looking for a Senior Security Engineer who views security as an engineering challenge, not a checkbox exercise. You will join our Infrastructure Team to own security across our entire stack (from the low-level GKE configurations to the high-level application logic).

In a startup of our size (~100 people), "chaos" is just another word for "opportunity." You aren’t here to just manage compliance spreadsheets or interface with IT; you are here to build the tooling, automation, and architecture that makes it impossible for our developers to make a critical mistake as we continually increase velocity.

What You’ll Do

  • Own the Stack: Secure everything from our Kubernetes clusters on the cloud to our SaaS integrations and developer workflows.

  • Usher in the Future: articulate and execute on a vision for what security should be in the age of LLMs giving both us and attackers increasing leverage.

  • Engineer for Security: Build internal tooling and CI/CD automations that catch vulnerabilities before they ever hit production.

  • Architect & Model: Lead threat modeling sessions and secure code reviews, ensuring we design "secure-by-default" APIs and deployments.

  • Harden the Perimeter: Take a first-principles approach to hardening authentication and access control across all internal and external surfaces.

  • Red Team: proactively probe for vulnerabilities and lead the remediation.

  • Lead the Bug Bounty: You will be the primary owner for standing up, launching, and managing our Bug Bounty Program, triaging reports, and driving remediation.

  • Respond & Remediate: Investigate vulnerabilities, lead incident response, orchestrate pen testing, and run blameless postmortems that actually result in systemic change.

Evangelize: Be the partner, not the blocker. Translate complex security risks into actionable engineering tasks that your peers can get excited about.

Who You Are

  • Startup Native: You thrive in scrappy 100–200 person environments. You know how to prioritize when everything feels urgent and are comfortable "failing forward" to find the right solution.

  • Security-First Engineer: You have 6+ years of experience in software/infrastructure engineering with a deep obsession with security. You don't just find holes; you write the code to plug them.

  • Cloud Savvy: You are deeply familiar with Google Cloud (GCP), Kubernetes, and containerized environments.

  • Systems Thinker: You can analyze a system for weaknesses whether they are buried in business logic, IAM configurations, or the codebase.

  • Action-Oriented: You have a track record of responding to real-world incidents and leading remediation efforts without being the "no" person.

Our Technical Stack

  • Cloud: Google Cloud Platform (GCP)

  • Orchestration: Kubernetes (GKE)

  • Infrastructure: Terraform / Infrastructure-as-Code

  • Pipeline: Modern CI/CD workflows and various SaaS integrations

What You’ll Receive

To determine your salary, we use a number of market and data-driven salary sources. We review all salaries every six months to ensure we stay in line with the market.

📈 In addition to our cash compensation, we offer generous perks and benefits. Below are some of the highlights:

  • $4000/yr Travel Stipend to travel anywhere anytime to work alongside other Roboflowers

  • $350/mo Productivity stipend to spend on things that make your work environment more productive, like high-speed internet at home or a co-working space

  • Cover up to 100% of your health insurance costs for you and your partner or family

  • Equity in the company so we are all invested in the future of computer vision

Interview Process (6+ hours)

Below is the interview process you can expect for this role. We are all motivated to work with an exceptional team and you will be speaking directly with our team about what it's like to work and thrive at Roboflow. We like to be decisive and work fast, so don't be surprised if all the below conversations happen over a day or two.

Security Engineer Related jobs

Other jobs at Roboflow

We help you get seen. Not ignored.

We help you get seen faster — by the right people.

🚀

Auto-Apply

We apply for you — automatically and instantly.

Save time, skip forms, and stay on top of every opportunity. Because you can't get seen if you're not in the race.

AI Match Feedback

Know your real match before you apply.

Get a detailed AI assessment of your profile against each job posting. Because getting seen starts with passing the filters.

Upgrade to Premium. Apply smarter and get noticed.

Upgrade to Premium

Join thousands of professionals who got noticed and hired faster.