Security Engineer

Posted Yesterday
Be an Early Applicant
Hiring Remotely in Holding's Ford, MN, USA
Remote or Hybrid
130K-150K Annually
Senior level
Insurance • Logistics • Software • Transportation • Business Intelligence
SambaSafety a SaaS company HQ'd in Denver, we are the leader In mobility & driver risk intelligence.
The Role
Leads application security, vulnerability management, threat detection, AI-driven security automation, and security engineering. Administers SAST, DAST, SCA, SIEM, EDR, IAM, and cloud security platforms; develops MITRE ATT&CK-mapped detections; investigates Tier 2/3 incidents; builds Python-based automation and AI agent integrations; supports architecture reviews, penetration testing, policy development, threat intelligence, compliance, and security reporting.
Summary Generated by Built In

Who we are:

Hi, we’re SambaSafety and we offer the industry’s most comprehensive driver monitoring software. Our mission is promoting safer communities by reducing risk through data insights. Companies trust SambaSafety to keep their employees safe on the roads, price and reduce risk, help protect their brand, their bottom line, and our global community. 

We’ve built an inclusive, supportive, and exceptional culture where every employee is empowered in their role. Don’t take our word for it; we’ve been recognized as a Top Workplace by The Denver Post, Albuquerque Journal, Sacramento Bee, and Built In Colorado. And our employees rate SambaSafety as top-notch, with a rock solid Top Rating on Glassdoor.

What You’ll Do:

We are seeking an experienced Security Engineer to join our growing security team in a multifaceted role that combines vulnerability management, application security, MITRE ATT&CK-based threat detection, AI-driven security automation, and security engineering expertise. This position requires a technical security professional with knowledge spanning cloud security, identity and access management (IAM), endpoint detection and response (EDR), SIEM administration, and hands-on scripting for automation development. The successful candidate will work closely with development teams, infrastructure teams, vendors, and internal stakeholders to optimize our security posture and manage enterprise risk.

Key Responsibilities:

Application Security & Vulnerability Remediation

  • Lead application security vulnerability remediation efforts across development teams
  • Administer SAST tooling
  • Administer DAST tooling
  • Administer SCA and software composition / dependency scanning tools
  • Triage and validate vulnerability findings to reduce false positives
  • Provide remediation guidance to development teams on OWASP Top 10 and secure coding practices
  • Integrate scanning tools with ticketing systems and CI/CD pipelines
  • Generate AppSec metrics and reports
  • Provide security code review support

Vulnerability Assessment & Management

  • Administer vulnerability management platforms
  • Configure scan policies, schedules, and asset groups
  • Validate and prioritize vulnerability findings using risk-based prioritization (CVSS + context)
  • Conduct expert analysis and risk scoring of vulnerabilities
  • Coordinate remediation with IT and development teams
  • Manage vulnerability exceptions and risk acceptances
  • Track vulnerability aging and SLA compliance
  • Generate management reports and dashboards
  • Participate in product vulnerability management meetings
  • Participate in Security by Design reviews

MITRE ATT&CK & Threat Detection

  • Develop detection rules mapped to ATT&CK techniques
  • Implement ATT&CK-based alert triage workflows
  • Configure SIEM correlation rules using ATT&CK
  • Conduct gap analysis of ATT&CK coverage
  • Integrate threat intelligence feeds with ATT&CK mapping
  • Build ATT&CK-based hunting queries
  • Create ATT&CK-mapped incident reports

AI-Driven Security Automation & Agent Engineering

  • Build and maintain scripted, cloud-based automation pipelines supporting the team's AI-driven security operations platform
  • Develop and tune AI agent prompts, verdict logic, and disposition rules for automated alert triage
  • Extend the team's internal tool-integration framework connecting security platforms for AI-assisted operations
  • Integrate automation with SIEM, EDR, and ticketing systems
  • Build automated enrichment and reporting workflows
  • Monitor and tune agent/automation performance and disposition accuracy
  • Develop custom integrations using APIs and cloud-native services
  • Maintain observability for automated security workflows

Security Engineering & Architecture

  • Lead Tier 2/3 security incident investigation and response
  • Administer EDR, SIEM, and IAM platforms
  • Implement and tune detection rules and alerts
  • Manage cloud security configurations
  • Support penetration testing and red team activities
  • Conduct WAF/CDN rule audits and configuration reviews
  • Provide security engineering expertise for infrastructure and application architecture decisions
  • Support complex security investigations requiring deep technical analysis
  • Contribute to security design reviews and technical security standards

Policy & Threat Intelligence

  • Draft and review security policies and procedures
  • Conduct policy gap analysis against frameworks
  • Analyze threat intelligence from multiple sources
  • Integrate threat feeds into detection and automation workflows
  • Implement IOC blocking and detection rules
  • Participate in information sharing communities (ISACs)
  • Create threat intelligence reports

Required Qualifications: 

Education & Experience

  • Bachelor's degree in Computer Science, Information Security, Engineering, or related technical field, or equivalent professional experience
  • 5-7 years of experience in security engineering with demonstrated expertise in multiple security domains, including application security

Technical Skills

  • Expert knowledge of vulnerability management platforms
  • Proficient in MITRE ATT&CK mapping for detection rules and incident response
  • Strong experience with SAST, DAST, and SCA tooling for application security
  • Deep understanding of application vulnerabilities (OWASP Top 10, injection flaws, XSS, authentication bypasses)
  • Hands-on scripting experience building cloud-based automation (serverless functions, event-driven pipelines, secrets management)
  • Experience with, or strong interest in, AI agent engineering and tool-integration protocols for security operations
  • Proficiency administering EDR platforms
  • Experience with SIEM administration
  • Solid understanding of IAM platforms and federation/SSO concepts
  • Proficiency in cloud security (AWS, Azure, or GCP)
  • Solid understanding of WAF configuration and audit
  • Proficiency in scripting and automation (Python required; PowerShell a plus)
  • Understanding of DevSecOps and secure CI/CD practices
  • Practical experience with AI-powered security tooling, including building or operating LLM-based agents, and awareness of emerging AI threats (prompt injection, tool/agent security risks)
  • Ability to produce dashboards and reporting for technical and executive audiences

Platform & Domain Experience

  • SIEM administration
  • Security automation/orchestration, including AI agent-based automation
  • Vulnerability management platforms
  • EDR platforms
  • DLP platforms
  • GRC platforms
  • SAST tooling
  • DAST tooling
  • SCA / dependency scanning tooling
  • Cloud security (AWS, Azure, or GCP)
  • Threat intelligence platforms
  • Ticketing and collaboration platforms

Soft Skills & Experience

  • Strong analytical thinking and problem-solving capabilities
  • Excellent communication skills for technical and business audiences
  • Strong Agile proficiency with ability to integrate security into sprint planning
  • Experience collaborating with development teams and partnering on secure coding
  • Ability to translate technical vulnerability findings into actionable remediation guidance
  • Strong written communication skills for security documentation, audit responses, and questionnaire completion
  • Act as escalation point for Security Analysts
  • Participate in project security reviews
  • Support sales team with security questionnaires
  • Participate in customer security calls

Preferred Qualifications:

Certifications

  • CySA+ (CompTIA)
  • Cloud Security certification (AWS, Azure, or GCP)
  • GIAC GSEC
  • Certified Ethical Hacker (CEH)
  • GIAC GWEB (Web Application Penetration Tester)
  • CompTIA PenTest+ (optional)
  • GIAC GCTI (Cyber Threat Intelligence) (optional)
  • SIEM Platform Certification (optional)

Additional Experience

  • DevSecOps experience integrating SAST/DAST into CI/CD pipelines
  • Secure software development lifecycle (SSDLC) implementation experience
  • Compliance experience with SOC 2, ISO 27001, or industry-specific regulations
  • Experience with security audit preparation and vendor risk assessment programs
  • Threat intelligence analysis and integration experience
  • Experience coordinating third-party penetration testing
  • Security awareness training development and delivery
  • Experience building or integrating LLM-based agents/automation for security operations
  • Experience with container and Kubernetes security concepts

Benefits and Perks:

  • Flexible and generous Paid Time Off and Paid Volunteer Days
  • 401k Employer Match 
  • Generous Healthcare Benefits 
  • Up to 12 weeks paid time off for maternity leave based on tenure
  • Wellness &Tuition Reimbursement
  • Flexible Work Arrangements
  • Lots of SambaSafety swag & SambaSafety Events 

Our team of talented and committed safety professionals is exceptional. At SambaSafety we strive to foster an inclusive culture that supports, encourages and celebrates a wide array of diversity. We are committed to create a space where all employees can show up as their authentic selves every day, and we work to advance employee equality, diversity and inclusion.

SambaSafety provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, gender identity, and expression or genetics.

Come join us to find out for yourself what all the excitement is about!


Skills Required

  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent professional experience
  • 5-7 years of experience in security engineering, including application security expertise
  • Expert knowledge of vulnerability management platforms
  • Experience mapping MITRE ATT&CK techniques for detection rules and incident response
  • Experience with SAST, DAST, and SCA application security tooling
  • Understanding of OWASP Top 10 and application vulnerabilities
  • Hands-on experience building cloud-based security automation
  • Experience with or strong interest in AI agent engineering and security tool integration
  • Experience administering EDR platforms
  • Experience administering SIEM platforms
  • Understanding of IAM platforms and federation or SSO concepts
  • Proficiency in AWS, Azure, or GCP cloud security
  • Understanding of WAF configuration and auditing
  • Python scripting proficiency
  • Understanding of DevSecOps and secure CI/CD practices
  • Experience with AI-powered security tooling and LLM-based agents
  • Ability to produce technical and executive security dashboards and reports
  • CySA+ certification
  • AWS, Azure, or GCP cloud security certification
  • GIAC GSEC certification
  • Certified Ethical Hacker certification
  • GIAC GWEB certification
  • CompTIA PenTest+ certification
  • GIAC GCTI certification
  • SIEM platform certification
  • DevSecOps and SSDLC implementation experience
  • SOC 2, ISO 27001, or industry-specific compliance experience
  • Security audit preparation and vendor risk assessment experience
  • Threat intelligence analysis and integration experience
  • Experience coordinating third-party penetration testing
  • Security awareness training development and delivery experience
  • Experience building or integrating LLM-based security automation
  • Container and Kubernetes security experience

What the Team is Saying

Julia Porter
Brenden Macy
Derik Cissell
Michelle Gagnon
John Russell
Kyle McGaw
Abby Abreu
Kevin Lawlor
Tommy Cordova

SambaSafety Compensation & Benefits Highlights

  • Healthcare Strength Healthcare coverage is presented as robust, with medical, dental, and vision options alongside HSA/FSA accounts and employer HSA contributions. One plan is noted as having 100% employer-paid premiums.
  • Leave & Time Off Breadth Time off is positioned as flexible and generous, including flexible/unlimited PTO, paid holidays and volunteer time, and paid parental leave up to 12 weeks for primary caregivers (3 weeks for secondary). Remote-friendly arrangements and seasonal programs like Summer Fridays are also cited in some descriptions.
  • Retirement Support Retirement benefits include a 401(k) with a stated company match of 50% on the first 6% contributed. This formula equates to an effective 3% employer contribution.

SambaSafety Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Denver, CO
300 Employees
Year Founded: 1998

What We Do

SambaSafety is a recognized innovator and leading provider of cloud-based risk management solutions for over 15,000 organizations with automotive mobility exposure, including many on Fortune’s Global 500 list. Employers and insurers benefit from SambaSafety’s continuous monitoring, intuitive insights, risk reduction tools, and configurable pricing solutions. Through the collection, correlation, and analysis of federal, state, local, and telematics data sources, SambaSafety's flexible, end-to-end capabilities enable businesses and insurers to better evaluate and mitigate driving risk, accelerate product development, reduce crashes, and foster safer communities.

Why Work With Us

Recognized as one of the Top 100 Tech Companies by Builtin and DenverPost & over 4.7 review on Glassdoor, we are the pioneer of driver risk management software in North America. We are proud to be an inclusive culture that supports diversity of all kinds and we are committed to all employees bringing their authentic selves to work every single day.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

SambaSafety Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: Flexible
HQDenver, CO
Milton Keynes, GB
Learn more

Similar Jobs

SambaSafety Logo SambaSafety

Business Intelligence Analyst

Insurance • Logistics • Software • Transportation • Business Intelligence
Remote or Hybrid
United States
300 Employees
100K-110K Annually

SambaSafety Logo SambaSafety

Senior Business Intelligence Engineer

Insurance • Logistics • Software • Transportation • Business Intelligence
Remote or Hybrid
United States
300 Employees
100K-130K Annually

SambaSafety Logo SambaSafety

Sales Development Representative

Insurance • Logistics • Software • Transportation • Business Intelligence
Remote or Hybrid
2 Locations
300 Employees
55K-60K Annually

SambaSafety Logo SambaSafety

Software Operations Engineer

Insurance • Logistics • Software • Transportation • Business Intelligence
Remote or Hybrid
United States
300 Employees
60K-70K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account