Software Engineer - Security
Job description
About the role
You will design and build the automation and internal tooling that keep our multi-tenant cloud and corporate environments secure and audit-ready. You will write code that operates security controls, integrates identity and cloud systems, handles SCIM provisioning, drives vulnerability scanning, and automates evidence collection to replace manual, time-intensive processes with reliable engineering. In this role, you will start with high-impact automation work such as making security and compliance controls run, report, and self-remediate without manual effort and grow into broader security engineering over time, from system design and architecture to hardening our production security capabilities. You will translate complex security and governance requirements into practical, testable code and own the end-to-end implementation of security tooling that directly protects our customers and operations. If you are an engineer who wants to solve real security and automation problems end to end, this role gives you the room to build systems that scale and endure. You will participate in the security team's on-call rotation to ensure that automated controls remain reliable and actionable at all times.
Key facts
What you'll do
- Design and build automation that operates and enforces security controls by integrating cloud, infrastructure, and identity systems so controls run, and where possible self-remediate, without manual intervention.
- Build tooling and integrations across cloud APIs, identity providers (e.g., SCIM provisioning), vulnerability scanners, and ticketing systems into a coherent, automated system.
- Automate how we collect, validate, and report compliance evidence continuously across our cloud and corporate environments.
- Build dashboards and pipelines that give real-time visibility into control status, gaps, and audit readiness.
- As part of Security and GRC, translate framework requirements into practical, testable, code-driven controls.
- Improve how we monitor, prioritize, patch, and respond to vulnerabilities across our cloud footprint.
- Over time, design and build internal security systems end to end (e.g., vulnerability risk management, web application firewalls), review RFCs, and partner with engineering teams on architecturally significant, security-relevant decisions.
- Participate in the security team's on-call rotation.
Requirements
- 3+ years of experience in a software, security, infrastructure, or platform engineering role.
- Strong coding ability, with experience building and maintaining tooling in languages such as Python or Go.
- Experience automating workflows and integrating systems via APIs.
- Working knowledge of cloud environments (ideally AWS), including how security and identity controls are implemented.
- Interest in engineering solutions to security and compliance problems rather than managing them manually.
- Comfort operating across both design and hands-on implementation, with an eagerness to grow into broader security engineering work over time.
- This position requires access to export-controlled technology, technical data, and/or controlled information, including information subject to the International Traffic in Arms Regulations (ITAR), Export Administration Regulations (EAR), and/or U.S. government contract requirements. Candidates must be eligible to access such information without additional U.S. government authorization, unless the company determines that any required authorization can be obtained.
- You must be physically located in or be willing to relocate to the United States for this role.
- You must have the right to work in the United States for this employer now and in the future.
- You must be able to start within 30 days of accepting the offer.
- You must be able to commit to a minimum of 40 hours per week for this role.
- You must be able to pass a background check and meet our security and compliance standards.
Nice to have
- Experience building or automating tooling for security platforms (SIEM, IAM/IdP, vulnerability management, EDR, and cloud security tools).
- Experience with compliance automation or GRC tooling (e.g., evidence collection, continuous control monitoring).
- Experience working in or automating for FedRAMP, SOC 2, ISO 27001, Texas RAMP, or CJIS-aligned environments.
- Experience with Kubernetes debugging, operations, or automation.
- Background supporting government, defense, or other highly regulated customers.
- Obtaining FAA Part 107 certification within the first 60 days of employment is strongly encouraged for all Skydio employees and required for certain positions.
Practical notes
- This role is based in San Mateo, California, United States and is eligible for relocation assistance for qualified candidates.
- The engagement type is full_time.
- You must be able to start within 30 days of accepting the offer.
- You must be able to commit to a minimum of 40 hours per week for this role.
- FAA Part 107 certification is strongly encouraged within the first 60 days of employment and required for certain positions.
- Compensation for this role includes a base salary range that varies based on skill level, proficiencies, transferable knowledge, and experience, along with equity and comprehensive benefits packages. Relocation assistance may also be provided for eligible roles.