RefolkCandidates
Open nowEngineeringEngineering

Software Engineer, Security Infrastructure

Sift · Marina Del Rey, California

Location
Marina Del Rey, California, United States
Workplace
Hybrid
Employment
Full time
Level
Mid level
Posted
4 months ago

About this role

About Sift

Sift is the data infrastructure platform for hardware engineering teams. We turn high-frequency telemetry into engineering insights for mission-critical machines: rockets, satellites, autonomous vehicles, energy systems, and defense platforms. Founded by former SpaceX engineers, we are building the review and analysis layer for the AI era of physical systems.

In This Role, You’ll:

  • Secure-by-default guardrails: Build the patterns, libraries, and secure-by-default standards (authentication, authorization, input handling, cryptography) that make whole classes of vulnerabilities hard to introduce, and review Go and Rust for security.

  • Threat modeling and secure design: Partner with engineering teams on new features and architectural changes across a distributed, polyglot system, and turn the results into concrete design decisions.

  • Software supply chain: Own dependency integrity, artifact signing, and build-pipeline trust. This matters especially for the self-managed and air-gapped deployments our customers run.

  • Developer-facing security tooling: Extend the app sec toolchain in CI/CD - SAST, software composition analysis, secret scanning, and fuzzing - and keep it high-signal, tuning it so findings are accurate and actionable for developers rather than noise. Partner with the owning teams to drive real risks to remediation.

  • Raise engineering's security fluency: Through design reviews, documentation, and direct collaboration, help the whole org build securely by default.

The Skillset You’ll Bring:

  • 5+ years building production software, including hands-on security ownership of a real codebase. You are a software engineer first, applying that skill to security.

  • Ability to read and review either Go and/or Rust with fluency. You don't need to have shipped both, but you should be able to reason about security in our stack from day one.

  • Strong grounding in application security fundamentals: web and API vulnerability classes, authentication and authorization patterns, and applied cryptography.

  • Experience with threat modeling and secure design review on non-trivial, distributed systems.

  • Hands-on experience embedding security tooling (SAST, SCA, secret scanning) into developer workflows and CI/CD; tuning it for signal over noise.

  • A bias toward building and shipping solutions that scale across teams, and toward driving their adoption. Comfortable picking up an existing security baseline and pushing it forward rather than needing to start from zero.

  • Clear communication with engineers and leadership. You can explain risk and tradeoffs to people who don't live in security.

Bonus Points:

  • Experience securing software that ships to customer-controlled, on-premise, or air-gapped environments.

  • Familiarity with software supply chain tooling and standards (Sigstore, SLSA, SBOM generation).

  • Background with Rust memory-safety considerations, or with fuzzing native and high-throughput data paths.

  • Container image and build-time security (image scanning, minimal/hardened base images).

  • Familiarity with DAST or dynamic testing approaches.

  • Exposure to regulated environments (defense, aerospace, or similar).

Location:

SIFT’s headquarters is in Marina Del Rey, CA (Next to LAX). We collaborate in person twice a week - on Mondays and Thursdays - and come together for a full week every two months. We are open to relocating candidates to LA or working from our San Francisco office for the right candidate.

Salary range: $180,000 - $230,000 per year. Plus equity and benefits.

Eligibility:

U.S. Citizenship Required: This position requires U.S. citizenship due to the nature of certain customer environments, security requirements, and access obligations associated with the role.

As published by Sift. Applications are handled on their site.

Skills this posting mentions

Artificial IntelligenceThreat ModelingAutonomous Vehicles

About Sift

Sift is transforming how modern machines are built and operated. Our platform goes beyond traditional monitoring, enabling automated data review that catches unusual conditions in systems too complex for manual checks. This not only enhances reliability but also dramatically speeds up development cycles. At our core, we provide a unified solution for ingesting, storing, and analyzing vast amounts of machine data. By combining powerful data processing with easy-to-use visualizations, we help engineers make sense of enormous amounts of information. From spacecraft to self-driving cars, Sift is the backbone of innovation for companies pushing technology to new limits. Born from the challenges of spaceflight, Sift aims to accelerate technological progress. We believe that by giving engineers better tools to understand and improve their creations, we can unlock a new era of innovation. Our mission goes beyond solving today's engineering problems; we're building the foundation for a future where the most ambitious machines are developed with confidence, run with precision, and constantly improved. We're also tackling related challenges like simplifying regulatory compliance, and improving manufacturing processes. By connecting data from various sources - from sensors to manufacturing records to regulatory requirements - we're empowering a new generation of engineers to build the technologies that will shape our world. Join us in our journey to usher in this new age of reliable, groundbreaking technology. Whether you're launching rockets, developing autonomous systems, or advancing energy and transportation, Sift is your partner in turning vast amounts of data into insights that drive innovation forward.

All 44 openings at Sift

One click, then it is written

Apply to Sift with a resume written for this role.

Queue Software Engineer, Security Infrastructure and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Sift’s form for you.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • 25 sent a week, free
  • No card
  • Nothing sent until you say so

More roles at Sift

See all

Similar roles elsewhere

See more

Put this to work

Paste your career in once. Every application after that is written for you.

Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • New matches ranked and written before you are up.
  • Every bullet stays inside what your history supports. Nothing invented.
  • Queued, submitted, interviewing, offer: one screen, not a spreadsheet.

500 free credits on sign-up. No card. Nothing is sent until you say so.

Listed from the job board Sift publishes. Refolk is not the employer and does not handle their hiring. Applications go to Sift directly.