Skip to content

Open nowPosted 6 hours agoWe saw it 80 min after it went up

Senior Security Engineer

queueinc15 open roles

Where
HQ - Newark, CA
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security Engineerqueueinc · HQ - Newark, CA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on queueinc's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.8%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.2%30 days
This job: posted 6 hours ago

The posting

About Us

Queue builds robots to fill prescriptions. Our machine is designed to take stock bottles of medication and produce counted, labeled vials, so that pharmacists and technicians can spend their time on patients. Our first product is built to work behind the pharmacy counter and to be operated by pharmacy staff.

About the Role

You own security engineering for a pharmacy robot and everything it talks to: the machine, its operating-system image, the software that runs on it, the cloud service that commands it, and the path that updates it. When a customer asks how each machine proves its identity, who can reach it and how, and what an independent test found and what was done about it, the answer rests on your work, and every statement in it is backed by something the system produces.

What You'll Own

- The threat model — A written model of the trust boundaries: machine to cloud, operator to screen, the update path, remote support, and suppliers. You keep it current as designs change.

- Security review of designs — Designs come to you early; you review them and your review is recorded.

- Device identity and key custody — The threat model, the priorities and the verification are yours. The engineers who own the operating-system image build the platform side with you.

- Independent security testing — Scope, test environment, triage, remediation with the owning squads, and retest evidence. You run it end to end.

- Finding and fixing weaknesses — How weaknesses in our code, dependencies, device images and cloud are found, triaged and fixed. It is shared with the squads that own each part: you set the rules, track each finding to closure and report where we stand.

- Incident response — The security side of every incident: detection, triage, containment, evidence and what changes afterwards. It is shared with the owning squads, and you run it with the systems reliability engineers, who run the operational response.

- Customer security reviews — A customer's security review asks detailed questions and treats our answers as commitments. Before a statement is sent, you check it against the evidence that can substantiate it: the versioned implementation, the deployed configuration and the operational records. A statement says what is built, what is designed and what is planned, and keeps the three apart.

- Cloud posture — Identity and access, secrets, the review of infrastructure changes, and what the cloud provider's detection services report.

- Security and privacy controls — For the controls Queue commits to, including those that follow from HIPAA, you verify each control in the system and take its evidence from the system.

You assess and you recommend. You do not accept risk on the company's behalf: an exception is recorded with its approver and conditions, and an authorized business owner accepts what remains.

First 90 Days

- Day 30: You have traced the trust boundaries yourself, and you hold the threat model and the record of independent testing. You have reviewed your first design.

- Day 60: You hold the priorities and the verification for device identity and key custody, with the engineers who own the operating-system image. You hold the inventory of secrets and keys and their rotation schedule. Every security statement that goes to a customer passes your check first.

- Day 90: You have written the scope for the next independent test and prepared the environment it will run against. Every design that came to you has a recorded review. You can hand an assessor a control's evidence as output from the system.

What We're Looking For

Must-Have

- Ownership — you have owned the security of a shipped product end to end, and you can describe a problem you found, fixed and followed until it stayed fixed. Consulting alone or compliance alone is not this.

- You build — you read and write code. Ours is Rust, TypeScript and Python: deep skill in one and comfort reading the others. Your reviews come with a patch or with guidance precise enough to act on.

- Systems and network depth — TLS and certificates, identity and access, secrets management, Linux hardening. You can reason about a trust boundary from the hardware to the cloud.

- Offensive fluency with defensive judgment — you have run or worked closely with penetration tests. You rank issues by what they could do to this system and its users, and you can defend deferring one.

- Threat modeling that engineers use — you would sooner remove an input than add a control, and engineers ask for your review.

- Exact writing — you state what is true at the strength the evidence supports, to an engineer, an executive or a customer's assessor.

Nice-to-Have

- Device security: verified start-up, hardware-held keys, signed updates, fleet identity.

- Security in healthcare or another regulated industry, and customer security reviews from the supplier's side.

- Cloud security engineering on AWS.

- Supply-chain security: dependency policy, artifact signing, provenance.

- Working knowledge of IEC 62443, UL 2900-1 or NISTIR 8259.

How We Hire

- Recruiter Screen (30 min)

- Technical Interview (90 min) — a take-home exercise of 2 to 3 hours, sent at least 24 hours before: a small working system to harden. We go through it together: what you fixed first, and why.

- Design Interview (60 min) — on trust boundaries and key custody.

- Leadership Interview (60 min) — how you own your work and work across squads.

Two interviewers score each technical stage independently.

What We Offer

- Ownership — security engineering for the machine and everything it talks to

- Hard problems: trust boundaries from the hardware to the cloud, device identity and key custody, and the path that updates the machine

- Small team, zero bureaucracy, high trust

Why Join Us Now?

Impact & Growth

- Direct Impact: You check every security statement against the evidence behind it before it goes to a customer

- Growth: The work runs from the review of a design to an independent test and its retest

Team and Culture

- Reports to the Head of Software Engineering with significant autonomy and influence

- The same person sets the security requirements you work to

- Who You Work With: You work every day with the engineers who build the on-machine software, the cloud service and the operating-system image

- Where We Work: Hybrid, three days a week at our headquarters in the Bay Area; device security work needs the hardware in front of you

Our Values

- Servant Leadership

- Do the Hard Things

- Own Your Work

- Default is Now

Own Your Work comes first in this role: you follow a problem until it stays fixed.

Contact: If you have any questions, please contact us at [email protected]

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against queueinc's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on queueinc's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    queueinc's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.