Skip to content

Open nowPosted 12 hours ago

Staff Security Engineer

Jellyfish6 open roles

Pay
$185,000 – $270,000 a year
Where
United States
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowStaff Security EngineerJellyfish · United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Jellyfish's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Jellyfish postings stay open a median of 12 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.2%30 days
This job: posted 12 hours ago

Jellyfish median: 12 days open

The posting

Jellyfish empowers engineering organizations to become as valuable and effective as possible by analyzing the data from tools and practices they already use. Our products help engineering leaders align their decisions with business initiatives and deliver software-- the right software, efficiently, and on time. We’re solving a real problem that people have today, and our growth is testament to the market potential.

We are looking for a Staff Security Engineer to own and lead all Security Engineering activities at Jellyfish. In this pivotal role, you will define the vision, build the strategy, and scale our security engineering program. With a deep background in application security, automated vulnerability management, and SaaS platform security, you will be the ultimate technical authority for security across the organization. You will partner closely with engineering leadership to embed security into our DNA while continuing to stay hands-on by building security features and writing high-quality code. This is a unique opportunity to have complete ownership of security at a high-growth company.

If this sounds exciting, we’d like to hear from you!

WHAT YOU’LL DO:

- Define Security Strategy & Roadmap: Own and drive the strategic security roadmap, aligning overarching security initiatives with executive business objectives and mitigating top-tier organizational risks.

- Architectural Leadership: Own, design, and mandate scalable, resilient security architectures across our core infrastructure, platform, and product ecosystem.

- Own the SDLC: Define, implement, and govern the Secure Development Lifecycle (SDLC) company-wide, pioneering automated threat modeling, continuous risk assessments, and secure development practices.

- Secure AI Development & Governance: Partner closely with engineering and data science teams to establish and enforce secure development lifecycle (SDLC) practices specifically for both internal AI tools and customer-facing AI features.

- AI Threat & Risk Modeling: Lead comprehensive threat modeling and continuous risk assessments tailored to artificial intelligence and machine learning ecosystems, mitigating unique risks such as prompt injection, data poisoning, and sensitive data leakage.

- Drive Automation at Scale: Spearhead the overarching strategy and development for automated remedial workflows, comprehensive vulnerability management, and advanced software composition analysis solutions.

- Mentorship & Cross-Functional Influence: Act as the definitive security leader, mentoring engineers, advising executive leadership on security posture, and cultivating a pervasive culture of security and inclusion.

- Lead Threat & Incident Management: Direct the organizational response for critical security incidents, oversee manual and automated threat modeling, and dictate the strategy for pentesting and bug bounty programs.

ABOUT YOU:

- Extensive, proven track record of owning, building, and scaling application security programs in a SaaS or fast-paced startup environment.

- Deep technical expertise in software engineering (e.g., Python, JavaScript/TypeScript, Rust, C/C++) combined with architectural-level understanding of reliability, safety, and security.

- Deep understanding of the unique security challenges presented by Artificial Intelligence and Large Language Models (LLMs), with practical experience securing both internal AI infrastructure and customer-facing AI applications.

- A forward-thinking approach to AI risk management, possessing the ability to balance rapid AI product innovation with rigorous security, compliance, and data privacy standards.

- Demonstrated ability to drive cross-functional consensus, influence engineering leadership, and execute large-scale performance, testing, and security initiatives.

- You possess strong business acumen, naturally balancing the needs of the user, product velocity, and enterprise security when dictating solutions.

- You are a recognized expert who loves tackling complex research in computer security and sharing your knowledge through technical talks and engineering-wide education.

- You thrive in autonomous environments, adept at identifying gaps, setting the direction, and executing with a distributed team.

- You are eligible to work in the U.S. for any employer.

- Located in EST or CST time zone (preferred).

BONUS POINTS IF:

- You bring expert-level skills with our technology stack and cloud environments (Python, Django, Postgres, AWS, Terraform, Circle CI/GitLab/GitHub Actions, Semgrep, LLVM).

- You are a prominent voice or active contributor in open-source security projects, standardizations, or industry working groups (e.g., OpenSSF, Mozilla).

- You have experience transforming the ways security and engineering teams collaborate, implementing cutting-edge tools to reduce friction and improve security posture.

- You have led security at a high-growth startup before, and loved it.

We believe that it takes a diverse team to build the best company we can. Jellyfish welcomes people from all backgrounds and especially encourages applications from members of groups underrepresented in the software industry.

A list of job experiences and qualification requirements is great, but humility, a performance-driven attitude, and a team-player approach are most important to us. We love to have fun and win in the process. We only hire people who have a passion for building great companies in an environment where a sense of humor is a must.

Occasional travel may be required.

Applicants must be authorized to work for any employer in the US. We are unable to sponsor or take over sponsorship of an employment visa at this time.

Let’s talk about us! This is all about you, but you want to know a little about us. Jellyfish https://jellyfish.co is the leading intelligence platform for AI-Integrated engineering, helping more than 1,000 companies including DraftKings, Keller Williams and Blue Yonder, leverage AI to transform how they build software. By combining the industry’s deepest engineering dataset with context-rich intelligence, Jellyfish helps R&D organizations understand what’s driving impact, adopt proven industry best practices, and make smarter decisions across AI adoption, planning, delivery, and engineering performance.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Jellyfish's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Jellyfish's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Jellyfish's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.