Software Engineer, Security Infrastructure

Siftstack
Marina Del Rey, CA

Who this role is best for

Security-focused engineers with Go or Rust expertise and experience in distributed systems will find this senior role at Siftstack rewarding.

Best fit for

  • Senior engineers who have led security initiatives in production systems with high-stakes data flows
    — “Build the patterns, libraries, and secure-by-default standards
  • Candidates with a track record of integrating security tooling into CI/CD pipelines and reducing false positives
    — “keep it high-signal, tuning it so findings are accurate and actionable
  • Individuals experienced in securing software for air-gapped or on-premise environments
    — “This matters especially for the self-managed and air-gapped deployments our customers run.

Things to consider

  • U.S. citizenship is mandatory due to access obligations and customer environments
    — “This position requires U.S. citizenship
  • The role demands regular in-person collaboration in LA or SF, not fully remote
    — “We collaborate in person twice a week—on Mondays and Thursdays

How to stand out

  • Emphasize hands-on work with SAST, SCA, or secret scanning in CI/CD environments
    — “embedding security tooling (SAST, SCA, secret scanning) into developer workflows
  • Showcase work in threat modeling for distributed systems with concrete outcomes
    — “Threat modeling and secure design: Partner with engineering teams on new features
  • Demonstrate fluency in Go or Rust with security-focused contributions or reviews
    — “Ability to read and review either Go and/or Rust with fluency
  • Demonstrate experience with software supply chain security practices like artifact signing
    — “Own dependency integrity, artifact signing, and build-pipeline trust
Pace · SteadyCollaboration · HighAutonomy · HighDecision Impact · CompanyLevel · Senior

Derived from job-description analysis by Serendipath's career intelligence engine.

What success looks like

  • secure-by-default guardrails
  • threat modeling
  • secure design
  • software supply chain
  • security tooling
Typical background
software engineeringsecurity

Skills & requirements

Required

GoRustSecurity OwnershipThreat ModelingSecure DesignSoftware Supply ChainSecurity ToolingSecurity FluencyCommunication

Preferred

Rust Memory-safetyFuzzingContainer Image SecurityDASTRegulated Environments

Stack & domain

GoRustSASTSCASecret ScanningFuzzingSigstoreSLSASBOM GenerationContainer Image And Build-time SecurityDASTDynamic Testing Approaches

About the role

Original posting from Siftstack via Ashby

ABOUT SIFT

Sift is the data infrastructure platform for hardware engineering teams. We turn high-frequency telemetry into engineering insights for mission-critical machines: rockets, satellites, autonomous vehicles, energy systems, and defense platforms. Founded by former SpaceX engineers, we are building the review and analysis layer for the AI era of physical systems.

In This Role, You’ll:

  • Secure-by-default guardrails: Build the patterns, libraries, and standards for authentication, authorization, input handling, and cryptography that make whole classes of vulnerability hard to introduce. Ensure the secure path is the path of least resistance.
  • Software supply chain: Own dependency integrity, artifact signing, and build-pipeline trust. This matters especially for the self-managed and air-gapped deployments our customers run.
  • Threat modeling and secure design: Partner with engineering teams on new features and architectural changes across a distributed, polyglot system, and turn the results into concrete design decisions.
  • Developer-facing security tooling: Own the appsec toolchain in CI/CD: SAST, software composition analysis, secret scanning, and fuzzing. Tune it so developers get findings worth acting on, then work with the owning teams to drive remediation.
  • Raise engineering’s security fluency: Make security knowledge something engineers pick up from design reviews, documentation, and working with you, not something they have to come ask for.

The Skillset You’ll Bring:

  • 5+ years building production software, including direct security ownership of a codebase you shipped. You are a software engineer first, applying that skill to security.
  • Fluency reading and reviewing a compiled systems language, with depth in Go or Rust.
  • Strong grounding in application security: web and API vulnerability classes, authentication and authorization patterns, and applied cryptography, applied through threat modeling and design review on distributed systems.
  • Hands-on experience embedding security tooling (SAST, SCA, secret scanning) into developer workflows and CI/CD, tuned for signal over noise.
  • A track record of building security tooling or libraries that other teams actually adopted.
  • Clear communication with engineers and leadership. You can explain risk and tradeoffs to people who don’t live in security.

Bonus Points:

  • Experience securing software that ships to customer-controlled, on-premise, or air-gapped environments.
  • Familiarity with software supply chain tooling and standards (Sigstore, SLSA, SBOM generation).
  • Fuzzing native or high-throughput data paths.
  • Exposure to regulated environments such as defense or aerospace.

Location:

SIFT’s headquarters is in Marina Del Rey, CA (Next to LAX). We collaborate in person twice a week—on Mondays and Thursdays—and come together for a full week every two months. We are open to relocating candidates to LA or working from our San Francisco office for the right candidate.

Salary range: $180,000 - $230,000 per year. Plus equity and benefits.

Eligibility:

U.S. Citizenship Required: This position requires U.S. citizenship due to the nature of certain customer environments, security requirements, and access obligations associated with the role.

Source: Siftstack careers (Ashby)

Similar roles