About this role.
Roboflow is hiring a Senior Security Engineer to own security across its cloud infrastructure, application stack, SaaS integrations, and developer workflows. The role emphasizes hands-on security engineering, including GCP and GKE hardening, Terraform and CI/CD automation, threat modeling, secure code review, incident response, and vulnerability remediation. The engineer will also establish and manage the bug bounty program and partner closely with developers to embed secure-by-default practices. This is a high-impact startup role for a security-focused infrastructure engineer who can set technical direction while delivering practical controls. The distributed team supports work from hubs, home, or co-working spaces across the US and Europe.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
5/5Pace & Pressure
5/5Autonomy Level
5/5Communication Load
5/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I would begin with an asset and trust-boundary inventory covering GCP projects, GKE clusters, CI/CD systems, source control, SaaS integrations, and privileged identities. I would prioritize issues by exploitability, blast radius, and business impact, immediately addressing critical IAM, secret-management, internet-exposure, and production-access gaps. In parallel, I would define a security roadmap with measurable controls and clear ownership across engineering.
I would apply layered controls: least-privilege GCP IAM and Kubernetes RBAC, workload identity, network policies, private cluster and control-plane protections where appropriate, image provenance and scanning, admission policies, runtime monitoring, secret management, and audited break-glass access. I would also ensure cluster, node, and dependency patching have defined ownership and service-level expectations.
I would automate high-signal checks early in the workflow, such as secrets detection, dependency and container scanning, infrastructure-as-code policy checks, and SAST tuned to reduce false positives. Findings should be severity-based, actionable, and linked to clear remediation guidance; only critical, credible risks should block deployment by default. I would measure bypasses, remediation time, and false-positive rates to continuously improve the developer experience.
I would bring engineering and product stakeholders together to map data flows, identities, trust boundaries, external dependencies, and abuse cases. We would identify threats across authentication, authorization, data exposure, prompt or model misuse where relevant, supply chain risk, and operational failure modes. The output would be a prioritized set of design decisions, security requirements, and test cases assigned before release.
I would acknowledge the report promptly, reproduce and validate the impact, classify severity using a consistent framework, and coordinate a contained remediation plan with the owning engineers. I would preserve evidence, assess related attack paths and potential exposure, communicate status responsibly to the reporter, and verify the fix before closure. For significant issues, I would lead a blameless postmortem and convert lessons into preventive controls or automated detection.
Who We Are
Our mission is to make the world programmable. Sight is one of the key ways we understand the world, and soon this will be true for the software we use, too.
We’re building the tools, community, and resources needed to make the world programmable with artificial intelligence. Roboflow simplifies building and using computer vision models. Today, over 1M+ developers, including those from half the Fortune 100, use Roboflow’s machine learning open source and hosted tools. That includes counting cells to accelerate cancer research, improving construction site safety, digitizing floor plans, preserving coral reef populations, guiding drone flight, and much more.
Roboflow is supported by great customers and investors, having raised over 63 million from Y Combinator, Google Ventures, Craft Ventures, Sam Altman, Lachy Groom, amongst other leading software investors.
We are looking for a Senior Security Engineer who views security as an engineering challenge, not a checkbox exercise. You will join our Infrastructure Team to own security across our entire stack (from the low-level GKE configurations to the high-level application logic).
In a startup of our size, “chaos” is just another word for “opportunity.” You aren’t here to just manage compliance spreadsheets or interface with IT; you are here to build the tooling, automation, and architecture that makes it impossible for our developers to make a critical mistake as we continually increase velocity.
What You’ll Do
Own the Stack: Secure everything from our Kubernetes clusters on the cloud to our SaaS integrations and developer workflows.
Usher in the Future: articulate and execute on a vision for what security should be in the age of LLMs giving both us and attackers increasing leverage.
Engineer for Security: Build internal tooling and CI/CD automations that catch vulnerabilities before they ever hit production.
Architect & Model: Lead threat modeling sessions and secure code reviews, ensuring we design “secure-by-default” APIs and deployments.
Harden the Perimeter: Take a first-principles approach to hardening authentication and access control across all internal and external surfaces.
Red Team: proactively probe for vulnerabilities and lead the remediation.
Lead the Bug Bounty: You will be the primary owner for standing up, launching, and managing our Bug Bounty Program, triaging reports, and driving remediation.
Respond & Remediate: Investigate vulnerabilities, lead incident response, orchestrate pen testing, and run blameless postmortems that actually result in systemic change.
Evangelize: Be the partner, not the blocker. Translate complex security risks into actionable engineering tasks that your peers can get excited about.
Who You Are
Startup Native: You thrive in a fast paced 100–300 person environments. You know how to prioritize when everything feels urgent and are comfortable “failing forward” to find the right solution.
Security-First Engineer: You have 6+ years of experience in software/infrastructure engineering with a deep obsession with security. You don’t just find holes; you write the code to plug them.
Cloud Savvy: You are deeply familiar with Google Cloud (GCP), Kubernetes, and containerized environments.
Systems Thinker: You can analyze a system for weaknesses whether they are buried in business logic, IAM configurations, or the codebase.
Action-Oriented: You have a track record of responding to real-world incidents and leading remediation efforts without being the “no” person.
Our Technical Stack
Cloud: Google Cloud Platform (GCP)
Orchestration: Kubernetes (GKE)
Infrastructure: Terraform / Infrastructure-as-Code
Pipeline: Modern CI/CD workflows and various SaaS integrations
Where You’ll Work
Roboflow is distributed across the US and Europe. We currently have Hubs in New York City and San Francisco (and plan to open more as we grow density in new cities). We provide opportunities (like team onsites in different cities) and resources (like a $4000/yr travel stipend) to work in person with other team members as much as you’d like, while also supporting remote team members. You can work from one of our Hubs (we offer a relocation bonus), work from home, work at co-working spaces, etc. We want you to work where you work best!
What You’ll Receive
To determine your salary, we use a number of market and data-driven salary sources. We review all salaries every six months to ensure we stay in line with the market.
The target salary for this position ranges from $165,000-$200,000
📈 In addition to our cash compensation, we offer generous perks and benefits. Below are some of the highlights:
$4000/yr Travel Stipend to travel anywhere anytime to work alongside other Roboflowers
$350/mo Productivity stipend to spend on things that make your work environment more productive, like high-speed internet at home or a co-working space
$350/mo AI Tools stipend
$150/mo team lunch stipend
$500/one time home office stipend
Cover up to 100% of your health insurance costs for you and your partner or family
Equity in the company so we are all invested in the future of computer vision
Interview Process (6+ hours)
Below is the interview process you can expect for this role. We are all motivated to work with an exceptional team and you will be speaking directly with our team about what it’s like to work and thrive at Roboflow. We like to be decisive and work fast, so don’t be surprised if all the below conversations happen over a day or two.
Before the Interview:
We’ll review your application, LinkedIn, Github, etc.
The best way to stand out is to write about something you’ve built with Roboflow or contribute to one of our open source projects.
We may send you a technical screen if applicable.
Introduction Phase:
[30m] Meet with People Ops
[30m] Meet with hiring manager to assess for overall mindset and skillset
[45m] Technical Assessment
Team Interview Phase:
[30m] Meet with another member of the team
[60m] Meet with hiring manager or CTO
Use this time to review specifics about the job description
Begin working through your 30/60/90 projects
Ask questions!
Final Interview Stage:
[45m] Meet with Head of Operations for a culture discussion
[60m / Optional] Meet with Joseph Nelson, CEO
Note: you are welcome to request additional conversations with anyone you would like to meet and we will accommodate as best we can.
Learn More About Us
Roboflow is a diverse, distributed team and an Equal Opportunity Employer. We welcome applicants from all backgrounds and experiences. We offer competitive compensation and benefits, plus opportunities to learn from and contribute to our world-class team.
Equal Employment Opportunity
We’re committed to building an inclusive team where great ideas come from everywhere. We consider all qualified applicants regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, veteran status, or any other protected characteristic.
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.








