Senior/Staff Security Engineer - Product Security

Zipline · South San Francisco, California, USA

  • Senior
  • Full-time
  • Posted 2026-08-12
  • Confirmed live on 25 September 2026

Apply at Zipline

Job description

About Zipline

Zipline is the world’s largest and most experienced drone delivery service. We are on a mission to serve all humans equally by ensuring access to food, medicine and essential goods anytime, anywhere. We design, build, and operate the world’s largest autonomous logistics system, delivering critical supplies quickly and reliably. Today, Zipline operates on four continents, makes a delivery somewhere in the world every 30 seconds, and has completed millions of deliveries to date, including blood, vaccines, medical supplies, food, and retail products.

Our customers include the world’s largest and most prominent healthcare systems, governments, retailers, restaurants and global businesses who rely on us to save lives, reduce emissions, increase economic opportunity, and provide delivery from point A to point B as fast as possible. The drone is only 15% of what we’ve built to enable seamless, reliable, global operations.

Our system strengthens supply chains, reduces congestion, and gives people time back. With more than 140 million commercial autonomous miles safely flown, Zipline is redefining access to healthcare, consumer products, and food across the globe.

We operate at a global scale and are looking for practical problem solvers who thrive on real-world challenges and rapid growth. Our team is motivated by building systems that have a direct, meaningful impact on people’s lives and by scaling the future of logistics. We are seeking people who sculpt from first principles, enjoy facing adversity, and can do the impossible at record breaking speeds.

About You and The Role

Product security at Zipline protects systems that directly affect safety, regulatory compliance, and uninterrupted delivery of critical goods in real-world operational environments. You will own security for production services and integrations that run our fleet orchestration, distribution center automation, telemetry/teleoperation, and developer/operator toolchains. This role is mission-critical: your work will reduce attack surface that could cause service outages, unsafe drone behavior, data exposure of patient/partner data, or regulatory failure.

You will join a small, high-ownership security team and partner deeply with software, infrastructure, autonomy/embedded, and field-ops teams. Expect hands-on engineering work, prioritized ownership of specific services, and a mandate to ship controls that measurably reduce risk in production systems under operational pressure. This is a hybrid onsite role: you will be at our South San Francisco HQ frequently and must be available for occasional travel to distribution centers and test sites.

What You'll Do

• Own security outcomes for 2-4 named production areas (examples: fleet orchestration APIs, DC orchestration/robotics control plane, telemetry and command channels, developer CI/CD and secrets platforms). Be the primary security owner for at least one area on hire.

• Deliver measurable risk reduction: define baseline metrics (e.g., mean-time-to-detect, mean-time-to-remediate, number of exploitable findings) and be accountable to improving them by defined targets in 6 and 12 months (example targets: cut exploitable high-risk findings by 50% in owned services; reduce MTTD for critical alerts to
What You'll Bring

Hard requirements (must-haves):

• 8+ years building and operating security controls for large-scale production systems across application and cloud infrastructure.

• Demonstrable hands-on engineering ability: you ship automation or tooling in Python, Go, or similar and can build integrations with AI tools and agentic security bots (not only write policies).

• Deep practical experience with cloud-native stacks and microservices (Kubernetes, containers, IAM, CI/CD, secrets management, logging/telemetry) and with designing least-privilege service-to-service models.

• Prior ownership of vulnerability management, incident response playbooks, and verification processes for production services.

• Direct experience threat‑modeling and securing systems that interface with physical systems, regulated workflows, or third-party partners (embedded, teleoperation, field ops, or healthcare-adjacent data flows).

• Ability to define and track quantitative success metrics (MTTD, MTTR, number of exploitable findings, compliance audit readiness) and be accountable for meeting targets within 6–12 months.

Non-negotiable traits:

• Operates as a technical owner: can persuade engineering teams, prioritize trade-offs, and drive changes through to production without relying solely on policy enforcement.

• Skeptical, adversarial mindset: anticipates failure modes and abuse cases for systems that interact with the physical fleet and partner workflows.

Additional strong qualifications (if present):

• Experience securing LLM/agentic tools in engineering workflows and mitigating OWASP LLM risks (prompt injection, unsafe plugin/output handling, agentic privilege misuse).

• Backgr

Prepare for the interview

Nothing collected for this employer yet. The Blind 75 is what technical screens draw from; practise it here, with a coach, in Java or Python.

More at Zipline

All open software jobs