Senior/Staff Security Engineer - Product Security
Zipline · South San Francisco, California
- Location
- South San Francisco, California, USA
- Level
- Staff
- Posted
- 2 days ago
About this role
About Zipline
Zipline is the world’s largest and most experienced drone delivery service. We are on a mission to serve all humans equally by ensuring access to food, medicine and essential goods anytime, anywhere. We design, build, and operate the world’s largest autonomous logistics system, delivering critical supplies quickly and reliably. Today, Zipline operates on four continents, makes a delivery somewhere in the world every 30 seconds, and has completed millions of deliveries to date, including blood, vaccines, medical supplies, food, and retail products.
Our customers include the world’s largest and most prominent healthcare systems, governments, retailers, restaurants and global businesses who rely on us to save lives, reduce emissions, increase economic opportunity, and provide delivery from point A to point B as fast as possible. The drone is only 15% of what we’ve built to enable seamless, reliable, global operations.
Our system strengthens supply chains, reduces congestion, and gives people time back. With more than 140 million commercial autonomous miles safely flown, Zipline is redefining access to healthcare, consumer products, and food across the globe.
We operate at a global scale and are looking for practical problem solvers who thrive on real-world challenges and rapid growth. Our team is motivated by building systems that have a direct, meaningful impact on people’s lives and by scaling the future of logistics. We are seeking people who sculpt from first principles, enjoy facing adversity, and can do the impossible at record breaking speeds.
About You and The Role
Product security at Zipline protects systems that directly affect safety, regulatory compliance, and uninterrupted delivery of critical goods in real-world operational environments. You will own security for production services and integrations that run our fleet orchestration, distribution center automation, telemetry/teleoperation, and developer/operator toolchains. This role is mission-critical: your work will reduce attack surface that could cause service outages, unsafe drone behavior, data exposure of patient/partner data, or regulatory failure.
You will join a small, high-ownership security team and partner deeply with software, infrastructure, autonomy/embedded, and field-ops teams. Expect hands-on engineering work, prioritized ownership of specific services, and a mandate to ship controls that measurably reduce risk in production systems under operational pressure. This is a hybrid onsite role: you will be at our South San Francisco HQ frequently and must be available for occasional travel to distribution centers and test sites.
What You'll Do
- Own security outcomes for 2-4 named production areas (examples: fleet orchestration APIs, DC orchestration/robotics control plane, telemetry and command channels, developer CI/CD and secrets platforms). Be the primary security owner for at least one area on hire.
- Deliver measurable risk reduction: define baseline metrics (e.g., mean-time-to-detect, mean-time-to-remediate, number of exploitable findings) and be accountable to improving them by defined targets in 6 and 12 months (example targets: cut exploitable high-risk findings by 50% in owned services; reduce MTTD for critical alerts to <30m).
- Design and implement production controls: IAM/least-privilege policies, service-to-service trust, key lifecycle and KMS integrations, runtime telemetry and alerting, secure OTA/update patterns for edge devices, and hardened CI/CD pipelines and build artifact provenance.
- Threat model and perform secure design reviews for services that operate near the physical fleet, regulated workflows, or partner/customer interfaces; produce engineering-tractable mitigations and drive their rollout to completion.
- Lead vulnerability management end-to-end for owned services: vulnerability triage with exploitability analysis, prioritized remediation plans with engineering partners, staged verification, and verification metrics for closure and regression prevention.
- Build and harden incident response for product incidents: author playbooks, run tabletop exercises with product and operations, validate logging/auditability so incidents are forensic-ready, and participate in incident postmortems with corrective action tracking.
- Secure AI/agent-assisted development and ops: define allowed copilots and patterns, implement guardrails to prevent secret exposure and unauthorized actions, and add monitoring/auditing for risky agent behaviors where it intersects owned systems.
- Integrate external pentest and red-team results into durable engineering changes; turn test findings into tracked engineering tickets and measurable closure criteria.
- Collaborate daily with SREs, platform engineers, autonomy/embedded teams, field ops, and compliance to translate regulatory/safety requirements (e.g., health-adjacent data handling, auditability) into concrete technical controls.
What You'll Bring
Hard requirements (must-haves):
- 8+ years building and operating security controls for large-scale production systems across application and cloud infrastructure.
- Demonstrable hands-on engineering ability: you ship automation or tooling in Python, Go, or similar and can build integrations with AI tools and agentic security bots (not only write policies).
- Deep practical experience with cloud-native stacks and microservices (Kubernetes, containers, IAM, CI/CD, secrets management, logging/telemetry) and with designing least-privilege service-to-service models.
- Prior ownership of vulnerability management, incident response playbooks, and verification processes for production services.
- Direct experience threat‑modeling and securing systems that interface with physical systems, regulated workflows, or third-party partners (embedded, teleoperation, field ops, or healthcare-adjacent data flows).
- Ability to define and track quantitative success metrics (MTTD, MTTR, number of exploitable findings, compliance audit readiness) and be accountable for meeting targets within 6 - 12 months.
Non-negotiable traits:
- Operates as a technical owner: can persuade engineering teams, prioritize trade-offs, and drive changes through to production without relying solely on policy enforcement.
- Skeptical, adversarial mindset: anticipates failure modes and abuse cases for systems that interact with the physical fleet and partner workflows.
Additional strong qualifications (if present):
- Experience securing LLM/agentic tools in engineering workflows and mitigating OWASP LLM risks (prompt injection, unsafe plugin/output handling, agentic privilege misuse).
- Background across multiple domains (cloud infra, web services, and embedded/autonomy) and experience building developer-friendly security platforms or paved-road tooling.
What Else You Need To Know
This is a hybrid role based in South San Francisco; frequent HQ presence required and occasional travel to field sites. This role has production ownership and will participate in incident response; candidates must be prepared for on-call participation when assigned.
Zipline is an equal opportunity employer and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws or our own sensibilities.
We value diversity at Zipline and welcome applications from those who are traditionally underrepresented in tech. If you like the sound of this position but are not sure if you are the perfect fit, please apply!
Voluntary Self-Identification
For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.
As set forth in Zipline ’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.
As published by Zipline. Applications are handled on their site.
About Zipline
Zipline was founded to create the first logistics system that serves all humans equally. Our aim is to solve the world’s most urgent and complex access challenges. Leveraging expertise in robotics and autonomy, Zipline designs, manufactures and operates the world’s largest automated delivery system. Zipline serves tens of millions of people around the world and is making good on the promise of building an equitable and more resilient global supply chain. From powering Rwanda’s national blood delivery network and Ghana’s COVID-19 vaccine distribution, to providing on-demand home delivery for Walmart and enabling leading healthcare providers to bring care into the home in the United States, Zipline is transforming the way goods move. By transitioning to clean, electric, instant logistics, we can decarbonize delivery, decrease road congestion, and reduce fossil fuel consumption and air pollution, while providing equitable access for billions of people. The technology is complex but the idea is simple: a teleportation service that delivers what you need, when you need it. Zipline is inspiring people, governments, and businesses to imagine what is possible when goods can move as seamlessly as information. To join the team, check out our career page: https://flyzipline.com/careers/
All 331 openings at ZiplineOne click, then it is written
Apply to this role, tailored
Queue Senior/Staff Security Engineer - Product Security at Zipline and I will read the posting, rewrite your resume against it, draft the cover letter, and score the fit before you send anything.
Each one finishes ready to go. Send it yourself, or press one button and I fill in the employer’s form for you. New accounts start with 500 free credits, no card.
More roles at Zipline
See all- Today
- Today
- Today
Civil and Structural Engineer Intern (Summer 2027)
South San Francisco, California
InternshipEngineering - Today
- Today
Video Production and Social Media Intern (Spring 2027)
South San Francisco, California
InternshipProduct - Today
Similar roles elsewhere
See more- Today
Civil and Structural Engineer Intern (Summer 2027)
ZiplineSouth San Francisco, California
InternshipEngineering - Today
Applications Engineer Intern (Summer 2027)
ZiplineSouth San Francisco, California
InternshipEngineering - Today
Civil and Structural Engineer Intern (Spring 2027)
ZiplineSouth San Francisco, California
InternshipEngineering - Today
Software Engineering Sr. Manager - Marketplace
ZiplineSouth San Francisco, California
$135k - $240k/yrManagerEngineering - Today
Director of Software Engineering - Marketplace
ZiplineSouth San Francisco, California
$170k - $295k/yrDirectorEngineering
Put this to work
Reading about the job search is not the job search.
Paste your career in once. I write the resume, then every week I rank the live openings against your history, tailor a resume and a cover letter to the best of them, fill in the forms if you ask me to, and keep going until you land. Your part is deciding what goes out.
- 140+ curated roles a week, found, written, and scored for you.
- Every bullet stays inside what your history actually supports.
- Queued, submitted, interviewing, offer, all in one place instead of a spreadsheet.
500 free credits on sign-up. No card.
Listed from the job board Zipline publishes. Refolk is not the employer and does not handle their hiring. Applications go to Zipline directly.