← Back to all jobs
F

Staff Security Engineer

Flock Safety

19d ago

0$185k - $230kDevRemote, USjobspy_indeed
remoteindeed

Job Description

**Location** ------------ Remote \- USA **Employment Type** ------------------- Full time **Location Type** ----------------- Remote **Department** -------------- Security **Compensation** ---------------- * $185K – $230K • Offers Equity Where you fall within the compensation range is based on how you demonstrate the attributes and competencies required for the role. We mostly reserve the upper half of our compensation bands for internal growth. During your call with one of our recruiters, they can further clarify the salary range and our total compensation. Overview**The Problem** =============== As Flock rapidly expands its fleet of connected hardware devices and cloud platforms, establishing a dedicated, centralized product security response program is critical to protecting our public safety network. Managing vulnerabilities across hardware, firmware, and cloud systems requires a single point of accountability to coordinate disclosures and drive fixes to closure. You will stand up our Product Security Incident Response Team (PSIRT), serve as the technical owner of our Coordinated Vulnerability Disclosure (CVD) program, and safeguard the products our customers depend on. **What You'll Own** =================== * Own the operational model and execution of Flock's Product Security Incident Response Team (PSIRT) across every externally reported and internally discovered product vulnerability. * Serve as the operational lead for our CVE Numbering Authority (CNA), managing vulnerability intake, triage SLAs, severity rubrics, and public CVE record publishing. * Drive cross\-functional remediation efforts across Hardware, Firmware, Device SRE, Cloud SRE, Mobile, Legal, Communications, and Support to ensure timely patch delivery. * Author clear, accurate public security advisories, internal postmortems, and executive summaries tailored to technical, legal, and leadership audiences. * Establish metrics and operational reporting for PSIRT performance, tracking time\-to\-triage, time\-to\-fix, and time\-to\-disclose. **What This Role is Not** ========================= * This isn't a people management position, you are an individual contributor who drives execution and policy adherence through cross\-functional influence. * This is not a corporate security or internal SOC role, your sole focus centers on product security, field devices, and embedded software platforms. * This isn't a passive triage desk, you will actively guide technical remediation strategies and defend severity decisions with engineering leaders and external security researchers. **What You Bring** ================== * Demonstrated experience leading or running a PSIRT, product security, or coordinated vulnerability disclosure function, ideally within connected hardware or IoT environments. * Deep operational experience acting as a CVE Numbering Authority (CNA) or implementing the FIRST PSIRT Services Framework across discovery, triage, remediation, and