Staff Security Engineer

Redpanda Data
•$210,000 - $247,000

About The Position

Redpanda is seeking an experienced Staff Security Engineer to lead and scale application security across its product suite, including the C++ core streaming engine, Go cloud control plane, Console, and Rust/Go data-transform SDKs. This role emphasizes a proactive, engineering-driven approach to security, focusing on analyzing and improving systems, building automated security measures, and integrating security into the development lifecycle. The engineer will be part of a small, high-trust product security team, collaborating closely with development engineers. The position reports to the Director of Information Security and works alongside the infrastructure security engineer. Key responsibilities include managing the secure SDLC, threat modeling, vulnerability discovery, fuzzing, and coordinating vulnerability disclosure and PSIRT response. The role also involves shaping the technical direction of the application security practice and elevating security standards across the engineering organization.

Requirements

  • 7+ years in application or product security or adjacent specialties, with a track record of owning AppSec initiatives end-to-end and influencing engineering teams without direct authority.
  • Ability to review and reason about code in a systems language (C++ or Rust strongly preferred, since core engine is C++; Go valuable across cloud control plane and tooling), whether reviewing it directly or with AI assistance, with strong instincts for memory safety, concurrency, and vulnerability classes (use-after-free, buffer overflow, injection, authorization flaws).
  • Comfort with security risks of memory-unsafe code and appetite to fuzz it; fuzzing or sanitizer experience is a strong plus.
  • Practical proficiency with the AppSec toolchain (SAST, SCA, secret scanning, DAST) and judgment to apply risk-based prioritization rather than rigid textbook approaches.
  • Demonstrated experience leading threat modeling and secure design reviews for non-trivial systems.
  • Working knowledge of software supply-chain security (dependencies, SBOMs, signing, SLSA) and secure CI/CD practices.
  • Familiarity with cloud (AWS / GCP / Azure) and Kubernetes security as it relates to the application layer.
  • Excellent written and verbal communication skills; comfortable working in a globally distributed, async environment (e.g., GitHub).

Nice To Haves

  • Experience with fuzzing (libFuzzer / AFL++ / OSS-Fuzz) and sanitizers (ASan / UBSan / MSan) on a C or C++ codebase.
  • Background securing distributed systems, databases, or data-infrastructure products, including threat modeling consensus / replication and multi-tenant isolation.
  • Experience running a PSIRT, operating as a CNA, or managing a bug bounty / coordinated disclosure program.
  • Exposure to compliance programs (SOC 2, ISO 27001, HIPAA, FedRAMP) from the engineering-evidence side.
  • Contributions to open-source security, or experience handling vulnerabilities in a public open-source repository.

Responsibilities

  • Lead threat modeling and secure design reviews for new product features across the C++ engine, Go control plane, and Console, catching trust-boundary and authorization flaws before code is written.
  • Own and tune application security testing (SAST, SCA / dependency scanning, secret scanning, and DAST) across C++, Go, and Rust, driving down false positives and gating the highest-severity findings in CI.
  • Build fuzzing harnesses for the core engine (coverage-guided and protocol-aware) and partner with platform engineering to run them continuously, integrating sanitizers to surface memory-safety and parsing defects early.
  • Drive deep secure code review in systems languages, pairing expertise with AI-assisted analysis, and partner with engineering to eradicate whole classes of vulnerabilities rather than patching one bug at a time.
  • Operate product security incident response (PSIRT) and coordinated vulnerability disclosure: triaging external researcher reports, driving fixes with engineering, and publishing advisories and CVEs.
  • Strengthen software supply chain (dependency hygiene, SBOMs, build provenance, and progress toward higher SLSA build levels) in partnership with platform engineering.
  • Stand up a security champions program and secure-by-default building blocks (libraries, patterns, guardrails) so engineering teams can own security with support.
  • Define security requirements and help shape security release gates, and advise on product security features: authentication, authorization / RBAC, encryption, audit logging, multi-tenant isolation, and the Agentic Data Plane.
  • Raise the security bar across engineering through pragmatic standards, training, and hands-on partnership, using modern AI-assisted development workflows (including tools like Claude Code) to scale impact.

Benefits

  • Fast-moving, diverse, people-first organization
  • Culture based on trust, transparency, communication, and kindness
  • Nimble, high-impact team
  • Latest AI tools
  • Budget to use AI tools
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service