All remote jobs
Open role
Remote opportunity atRoboflow

Security Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
42Listing views
4Application actions
19 Oct 2026Apply before
Opportunity details

About this role.

AI Summary

Roboflow is hiring a Senior Security Engineer to own security across its cloud infrastructure, application stack, SaaS integrations, and developer workflows. The role emphasizes hands-on security engineering, including GCP and GKE hardening, Terraform and CI/CD automation, threat modeling, secure code review, incident response, and vulnerability remediation. The engineer will also establish and manage the bug bounty program and partner closely with developers to embed secure-by-default practices. This is a high-impact startup role for a security-focused infrastructure engineer who can set technical direction while delivering practical controls. The distributed team supports work from hubs, home, or co-working spaces across the US and Europe.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

5/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

5/5
IndependentCollaborative
AI insightThis senior role requires broad, production-level expertise spanning cloud, Kubernetes, IAM, application security, CI/CD, offensive testing, and incident response. The engineer is expected to own the security function in a fast-moving startup and independently prioritize foundational work alongside active risks.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate
$182,500
US market range$160k–$215k
AI insightThe disclosed target base salary range is $165,000-$200,000 USD yearly, with a midpoint of $182,500. A competitive US market range for a senior cloud and product security engineer with GCP/Kubernetes ownership is approximately $160,000-$215,000 annually; equity and the listed stipends are additional benefits, not salary.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you prioritize security work during your first 90 days at Roboflow?

I would begin with an asset and trust-boundary inventory covering GCP projects, GKE clusters, CI/CD systems, source control, SaaS integrations, and privileged identities. I would prioritize issues by exploitability, blast radius, and business impact, immediately addressing critical IAM, secret-management, internet-exposure, and production-access gaps. In parallel, I would define a security roadmap with measurable controls and clear ownership across engineering.

What controls would you implement to secure a GKE environment?

I would apply layered controls: least-privilege GCP IAM and Kubernetes RBAC, workload identity, network policies, private cluster and control-plane protections where appropriate, image provenance and scanning, admission policies, runtime monitoring, secret management, and audited break-glass access. I would also ensure cluster, node, and dependency patching have defined ownership and service-level expectations.

Describe how you would embed security into CI/CD without slowing development excessively.

I would automate high-signal checks early in the workflow, such as secrets detection, dependency and container scanning, infrastructure-as-code policy checks, and SAST tuned to reduce false positives. Findings should be severity-based, actionable, and linked to clear remediation guidance; only critical, credible risks should block deployment by default. I would measure bypasses, remediation time, and false-positive rates to continuously improve the developer experience.

How would you run an effective threat-modeling session for a new API or AI-enabled feature?

I would bring engineering and product stakeholders together to map data flows, identities, trust boundaries, external dependencies, and abuse cases. We would identify threats across authentication, authorization, data exposure, prompt or model misuse where relevant, supply chain risk, and operational failure modes. The output would be a prioritized set of design decisions, security requirements, and test cases assigned before release.

How would you respond to a credible vulnerability report from a bug bounty researcher?

I would acknowledge the report promptly, reproduce and validate the impact, classify severity using a consistent framework, and coordinate a contained remediation plan with the owning engineers. I would preserve evidence, assess related attack paths and potential exposure, communicate status responsibly to the reporter, and verify the fix before closure. For significant issues, I would lead a blameless postmortem and convert lessons into preventive controls or automated detection.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

Who We Are

Our mission is to make the world programmable. Sight is one of the key ways we understand the world, and soon this will be true for the software we use, too.

We’re building the tools, community, and resources needed to make the world programmable with artificial intelligence. Roboflow simplifies building and using computer vision models. Today, over 1M+ developers, including those from half the Fortune 100, use Roboflow’s machine learning open source and hosted tools. That includes counting cells to accelerate cancer research, improving construction site safety, digitizing floor plans, preserving coral reef populations, guiding drone flight, and much more.

Roboflow is supported by great customers and investors, having raised over 63 million from Y Combinator, Google Ventures, Craft Ventures, Sam Altman, Lachy Groom, amongst other leading software investors.

We are looking for a Senior Security Engineer who views security as an engineering challenge, not a checkbox exercise. You will join our Infrastructure Team to own security across our entire stack (from the low-level GKE configurations to the high-level application logic).

In a startup of our size, “chaos” is just another word for “opportunity.” You aren’t here to just manage compliance spreadsheets or interface with IT; you are here to build the tooling, automation, and architecture that makes it impossible for our developers to make a critical mistake as we continually increase velocity.

What You’ll Do

  • Own the Stack: Secure everything from our Kubernetes clusters on the cloud to our SaaS integrations and developer workflows.

  • Usher in the Future: articulate and execute on a vision for what security should be in the age of LLMs giving both us and attackers increasing leverage.

  • Engineer for Security: Build internal tooling and CI/CD automations that catch vulnerabilities before they ever hit production.

  • Architect & Model: Lead threat modeling sessions and secure code reviews, ensuring we design “secure-by-default” APIs and deployments.

  • Harden the Perimeter: Take a first-principles approach to hardening authentication and access control across all internal and external surfaces.

  • Red Team: proactively probe for vulnerabilities and lead the remediation.

  • Lead the Bug Bounty: You will be the primary owner for standing up, launching, and managing our Bug Bounty Program, triaging reports, and driving remediation.

  • Respond & Remediate: Investigate vulnerabilities, lead incident response, orchestrate pen testing, and run blameless postmortems that actually result in systemic change.

  • Evangelize: Be the partner, not the blocker. Translate complex security risks into actionable engineering tasks that your peers can get excited about.

Who You Are

  • Startup Native: You thrive in a fast paced 100–300 person environments. You know how to prioritize when everything feels urgent and are comfortable “failing forward” to find the right solution.

  • Security-First Engineer: You have 6+ years of experience in software/infrastructure engineering with a deep obsession with security. You don’t just find holes; you write the code to plug them.

  • Cloud Savvy: You are deeply familiar with Google Cloud (GCP), Kubernetes, and containerized environments.

  • Systems Thinker: You can analyze a system for weaknesses whether they are buried in business logic, IAM configurations, or the codebase.

  • Action-Oriented: You have a track record of responding to real-world incidents and leading remediation efforts without being the “no” person.

Our Technical Stack

  • Cloud: Google Cloud Platform (GCP)

  • Orchestration: Kubernetes (GKE)

  • Infrastructure: Terraform / Infrastructure-as-Code

  • Pipeline: Modern CI/CD workflows and various SaaS integrations

Where You’ll Work

Roboflow is distributed across the US and Europe. We currently have Hubs in New York City and San Francisco (and plan to open more as we grow density in new cities). We provide opportunities (like team onsites in different cities) and resources (like a $4000/yr travel stipend) to work in person with other team members as much as you’d like, while also supporting remote team members. You can work from one of our Hubs (we offer a relocation bonus), work from home, work at co-working spaces, etc. We want you to work where you work best!

What You’ll Receive

To determine your salary, we use a number of market and data-driven salary sources. We review all salaries every six months to ensure we stay in line with the market.

The target salary for this position ranges from $165,000-$200,000

📈 In addition to our cash compensation, we offer generous perks and benefits. Below are some of the highlights:

  • $4000/yr Travel Stipend to travel anywhere anytime to work alongside other Roboflowers

  • $350/mo Productivity stipend to spend on things that make your work environment more productive, like high-speed internet at home or a co-working space

  • $350/mo AI Tools stipend

  • $150/mo team lunch stipend

  • $500/one time home office stipend

  • Cover up to 100% of your health insurance costs for you and your partner or family

  • Equity in the company so we are all invested in the future of computer vision

Interview Process (6+ hours)

Below is the interview process you can expect for this role. We are all motivated to work with an exceptional team and you will be speaking directly with our team about what it’s like to work and thrive at Roboflow. We like to be decisive and work fast, so don’t be surprised if all the below conversations happen over a day or two.

Before the Interview:

  • We’ll review your application, LinkedIn, Github, etc.

  • The best way to stand out is to write about something you’ve built with Roboflow or contribute to one of our open source projects.

  • We may send you a technical screen if applicable.

Introduction Phase:

  • [30m] Meet with People Ops

  • [30m] Meet with hiring manager to assess for overall mindset and skillset

  • [45m] Technical Assessment

Team Interview Phase:

  • [30m] Meet with another member of the team

  • [60m] Meet with hiring manager or CTO

    • Use this time to review specifics about the job description

    • Begin working through your 30/60/90 projects

    • Ask questions!

Final Interview Stage:

  • [45m] Meet with Head of Operations for a culture discussion

  • [60m / Optional] Meet with Joseph Nelson, CEO

Note: you are welcome to request additional conversations with anyone you would like to meet and we will accommodate as best we can.

Learn More About Us

Roboflow is a diverse, distributed team and an Equal Opportunity Employer. We welcome applicants from all backgrounds and experiences. We offer competitive compensation and benefits, plus opportunities to learn from and contribute to our world-class team.

Equal Employment Opportunity

We’re committed to building an inclusive team where great ideas come from everywhere. We consider all qualified applicants regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, veteran status, or any other protected characteristic.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent AI Tools Salaries
Menu