Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Staff Security Engineer, Prod Sec image - Rise Careers
Job details

Staff Security Engineer, Prod Sec

About Kandji


Kandji is the Apple device management and security platform that empowers secure and productive global work. With Kandji, Apple devices transform themselves into enterprise-ready endpoints, with all the right apps, settings, and security systems in place. Through advanced automation and thoughtful experiences, we’re bringing much-needed harmony to the way IT, InfoSec, and Apple device users work today and tomorrow.


Some of the smartest money in tech has partnered with Kandji to realize our vision, including Tiger Global, Felicis, Greycroft, First Round Capital, and Okta Ventures. In July 2024, Kandji raised $100 million in capital from General Catalyst, bringing Kandji’s valuation to $850 Million.


Since Kandji’s Series C in 2021, the company has seen a 600%+ increase in annual recurring revenue, and its customer base has grown nearly 4X across 40+ industries. Notable customers include Allbirds, Canva, and Notion, and the company has partnerships with such industry giants as ServiceNow, AWS, and Okta.


Kandji was also named to Forbes’ Next Billion Dollar Startup List 2023 and recognized as a top venture-backed startup with the potential to reach unicorn status.


The Opportunity


This role requires a deep understanding of Cybersecurity principles, application security, DevSecOps, incident response, cloud security, offensive security, and proactive threat detection. Kandji is seeking someone with a proven track record of managing security risks, driving security initiatives, and collaborating across product and engineering teams. This role reports directly to the Head of Infosec.


Day to Day
  • Collaborate with Product, Engineering, and DevOps to embed security into our API and platform development lifecycle.
  • Perform threat modeling and security reviews to spot risks early and keep our products secure
  • Identify, triage, and remediate security vulnerabilities in our codebase, infrastructure, and third-party dependencies
  • Support and manage our bug bounty program, coordinating triage and resolution.
  • Build and tweak automation tools for security testing and monitoring (e.g., static/dynamic analysis, secrets detection, dependency scanning)
  • Participate in security incident response efforts, including investigation, containment, and post-mortem analysis, to ensure rapid resolution and continuous improvement
  • Harden our cloud systems (AWS, Terraform, Snowflake) and products to meet industry standards and protect against evolving threats
  • Partner with cross-functional teams to make security seamless without slowing us down
  • Promote a security-first mindset by providing guidance, training, and documentation to team members on secure coding practices and emerging threats
  • Assist with compliance audits and assessments as necessary (e.g., SOC 2, ISO 27001, etc.)
  • Conduct security research and contribute to the development of new security tools and techniques.
  • Take ownership of security initiatives from design to implementation and measurable outcomes
  • Define and track metrics to assess product security health and incident response effectiveness
  • Contribute to security policies, coding standards, and risk management frameworks
  • Mentor engineers and foster secure-by-default practices across the organization


Must Haves
  • 6-8 years of experience in product security and DevSecOps-focused roles
  • Proficiency in at least one programming language (e.g., Go, Python, etc.) and the ability to review and write secure code
  • Experience with API security (e.g., OAuth, JWT, WAF, rate limiting)
  • Knowledge of LLM based attack vectors and mitigation strategies
  • Experience with cloud security (e.g., AWS) including DevSecOps and embedding security in the CI/CD pipeline
  • A strong understanding of how to secure containerized environments (e.g., Kubernetes, Docker)
  • Familiarity with security tools such as static code analyzers, vulnerability scanners, and penetration testing frameworks
  • Knowledge of common security vulnerabilities (e.g., OWASP Top 10) and mitigation strategies
  • Analytical, curious, and solutions-oriented—especially under pressure
  • Strong communicator who thrives in cross-functional teams


Nice To haves
  • Bachelor's degree in Information Technology or a related field
  • Security related certifications such as CISSP, GIAC, OSCP, CRTO, K8s is a plus
  • Experience working on security products, preventing cross-contamination
  • Experience in securing and monitoring APIs
  • Business acumen to be able to balance tradeoffs between stakeholders and technology feasibility and budget constraints


Benefits & Perks


 • Competitive salary

 • 100% individual and dependent medical + dental + vision coverage

 • 401(k) with a 4% company match

 • 20 days PTO

 • Kandji Wellness Week the first week in July

 • Equity for full-time employees

 • Up to 16 weeks of paid leave for new parents

 • Paid Family and Medical Leave

 • Modern Health - Mental Health Benefits - Individual and Dependents

• Fertility Benefits

 • Working Advantage Employee Discounts

 • Free onsite fitness center

 • Free parking

 • Lunch 5 days/week

 • Exciting opportunities for career growth

 • An outstanding, inclusive culture


We are excited to be serving a significant need for a fast-growing market, and are proud of the high-performing team we have brought together so far. If you’re someone who wants to engage in new, exciting projects that will challenge your skills in the best way possible, we would love to connect with you.


At Kandji we believe in fostering an inclusive environment in which employees feel encouraged to share their unique perspectives, leverage their strengths, and act authentically. We know that diverse teams are strong teams, and welcome those from all backgrounds and varying experiences.


Kandji is proud to be an equal opportunity employer committed to diversity and inclusion in the workplace. Qualified applicants will be considered for employment without regard to race, color, religion, national origin, age, sex, sexual orientation, gender identity, physical or mental disability, protected veteran or military status or any other status protected by applicable law.

Kandji Glassdoor Company Review
3.4 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Kandji DE&I Review
3.5 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
CEO of Kandji
Kandji CEO photo
Adam Pettit
Approve of CEO

Average salary estimate

$115000 / YEARLY (est.)
min
max
$100000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Staff Security Engineer, Prod Sec, Kandji

Kandji is on the lookout for a motivated Staff Security Engineer to join our dynamic team in Miami! As a leader in Apple device management and security, our mission is to empower organizations to streamline and secure their workflow. In this role, you'll dive deep into the realms of cybersecurity, application security, and DevSecOps to keep our innovative products safe and sound. You’ll collaborate closely with our talented Product, Engineering, and DevOps teams to embed security into every phase of the development lifecycle. Every day will present you with fresh challenges like performing threat modeling, managing vulnerabilities, and constantly enhancing our security initiatives. You will have the chance to shape our bug bounty program and lead incidents with a focus on continuous improvement. Moreover, you'll be the go-to mentor for our engineering teams, promoting best practices in secure coding. We value teamwork, curiosity, and a proactive approach. If you're ready to step into a pivotal role that champions security at Kandji, we can't wait to meet you!

Frequently Asked Questions (FAQs) for Staff Security Engineer, Prod Sec Role at Kandji
What responsibilities does the Staff Security Engineer have at Kandji?

The Staff Security Engineer at Kandji is responsible for a broad range of tasks including collaborating with various teams to integrate security into our development lifecycle, performing threat modeling and security reviews, managing vulnerabilities, and overseeing our bug bounty program. Additionally, they support incident response efforts and contribute to compliance audits while promoting a security-first mindset across the company.

Join Rise to see the full answer
What qualifications are required for the Staff Security Engineer position at Kandji?

To qualify for the Staff Security Engineer role at Kandji, candidates should have 6-8 years of experience focused on product security and DevSecOps. Proficiency in at least one programming language, knowledge of API security, and familiarity with cloud security are essential. A strong understanding of common security vulnerabilities and their mitigation strategies is also necessary. Certifications such as CISSP or OSCP are considered a plus.

Join Rise to see the full answer
What tools and technologies does the Staff Security Engineer use at Kandji?

As a Staff Security Engineer at Kandji, you'll work with various tools for security testing and monitoring, such as static code analyzers and vulnerability scanners. You're expected to have experience with cloud platforms like AWS, as well as securing containerized environments like Kubernetes and Docker. Familiarity with security frameworks and incident response protocols is also pivotal.

Join Rise to see the full answer
How does Kandji promote a security-first culture for the Staff Security Engineer?

Kandji encourages a security-first culture by empowering the Staff Security Engineer to provide guidance, training, and documentation on secure coding practices. They will also engage in mentorship to foster secure practices across all engineering teams, ensuring that security is woven seamlessly into the company’s DNA without slowing down innovation.

Join Rise to see the full answer
What benefits does Kandji offer to the Staff Security Engineer?

Kandji provides an attractive benefits package for the Staff Security Engineer that includes a competitive salary, comprehensive medical, dental, and vision coverage, a 401(k) with a company match, and generous PTO. Additional benefits include mental health support, fertility benefits, free on-site amenities, and opportunities for professional growth in a diverse and innovative team environment.

Join Rise to see the full answer
Common Interview Questions for Staff Security Engineer, Prod Sec
How do you approach securing APIs?

When answering this question, emphasize your understanding of API security measures such as OAuth and JWT. Discuss your experience with implementing rate limiting and WAF to protect APIs from threats, and be ready to provide examples of vulnerabilities you've identified and mitigated in the past.

Join Rise to see the full answer
Can you explain your experience with cloud security?

Discuss your familiarity with cloud platforms, particularly AWS, and describe specific security measures you've implemented. Highlight your experience with protocols related to CI/CD pipeline security and securing cloud configurations to protect against potential vulnerabilities.

Join Rise to see the full answer
What is your process for conducting threat modeling?

In your response, outline a structured approach to threat modeling that you follow, including identifying assets, potential threats, vulnerabilities, and risk assessment methods. Use specific examples from past experiences to demonstrate your thoroughness in identifying and mitigating risks.

Join Rise to see the full answer
How do you stay current with security vulnerabilities and attack vectors?

Talk about your commitment to ongoing education in the cybersecurity field. Mention resources like industry blogs, forums, conferences, and certifications that you engage with to stay informed about emerging threats and best practices.

Join Rise to see the full answer
Describe a time you managed a security incident.

Share a specific example of an incident you handled, outlining the detection, response, and resolution steps you took. Highlight how you interacted with teams, managed communication, and conducted post-mortem analysis to prevent future occurrences.

Join Rise to see the full answer
What is your experience with secure coding practices?

Discuss your history of implementing secure coding standards and mentoring teams on these practices. Provide examples of languages you’re proficient in and specific vulnerabilities you've worked to eliminate during the development lifecycle.

Join Rise to see the full answer
How would you balance security measures with productivity?

Explain that you believe in integrating security seamlessly into the development process. Emphasize collaboration with teams to ensure security measures do not hinder productivity, using examples of how you've achieved this in the past.

Join Rise to see the full answer
What strategies do you recommend to improve security awareness among employees?

Outline a holistic approach to security awareness, such as regular training sessions, creating engaging documentation, and fostering an open dialogue regarding security. Mention how incentivizing security awareness can positively impact the company culture.

Join Rise to see the full answer
Can you share your experience with vulnerability management tools?

Discuss specific vulnerability management tools you have used in your previous roles, including static and dynamic analysis tools. Share how you implemented these tools and the impact they had on identifying and mitigating vulnerabilities effectively.

Join Rise to see the full answer
What cloud security compliance frameworks are you familiar with?

Share any experience you have with compliance standards such as SOC 2 or ISO 27001. Discuss how you have assisted with audits and what steps you've taken to ensure that systems remain compliant with necessary regulations.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Dental Insurance
Disability Insurance
Flexible Spending Account (FSA)
Vision Insurance
Paid Holidays

Join Kandji as a Senior Backend Software Engineer and contribute to the innovative Apple device management platform that simplifies enterprise security.

Photo of the Rise User
Posted 14 days ago
Dental Insurance
Disability Insurance
Flexible Spending Account (FSA)
Vision Insurance
Paid Holidays

Join Kandji as a Security Engineer and play a key role in securing Apple device environments within a dynamic tech company.

Photo of the Rise User
Posted 6 days ago

Join Visa as a Sr. Site Reliability Engineer and make an impact in the payments technology industry.

Photo of the Rise User
Datacom Remote No location specified
Posted 2 days ago

Join Datacom as a Network Engineer to harness your expertise and collaborate within a skilled team while ensuring optimal network performance.

Photo of the Rise User
Posted 4 days ago

Join the Whiting School of Engineering as a Developer III, responsible for developing and maintaining critical engineering applications.

Photo of the Rise User
Posted 9 days ago

Join Aetos Systems as a Cyber Defense Incident Responder to enhance enterprise cybersecurity across diverse environments.

Join The Growth Partner as an AI Systems Engineer, where you'll support clients in navigating the dynamic AI landscape while enjoying the benefits of a remote work environment.

Photo of the Rise User
Posted 9 days ago

Join Cority as a Senior Systems Administrator and contribute to the management of industry-leading SaaS infrastructure within a dynamic remote work environment.

Photo of the Rise User
Posted 9 days ago

Become part of a dedicated team at Deutsche Telekom IT Solutions Slovakia, focusing on security management in a thriving IT environment.

Photo of the Rise User
Customer-Centric
Rapid Growth
Diversity of Opinions
Reward & Recognition
Friends Outside of Work
Inclusive & Diverse
Empathetic
Feedback Forward
Work/Life Harmony
Casual Dress Code
Startup Mindset
Collaboration over Competition
Fast-Paced
Growth & Learning
Open Door Policy
Rise from Within
Maternity Leave
Paternity Leave
Flex-Friendly
Family Coverage (Insurance)
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
401K Matching
Paid Holidays
Paid Sick Days
Paid Time-Off

An opportunity for an IT Systems Engineer to join a dynamic team in Seattle, focusing on system security and server management.

Drawing on decades of experience in Apple IT, we saw a dire need for a device management platform that could accommodate growing businesses and increasing regulatory demands. Existing solutions were either overly simplistic or mind-numbingly compl...

40 jobs
MATCH
Calculating your matching score...
BENEFITS & PERKS
Dental Insurance
Disability Insurance
Flexible Spending Account (FSA)
Vision Insurance
Paid Holidays
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
April 21, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, North Royalton just viewed Remote AI Voice Trainer (High-Quality Microphone Required) at Datadog
C
Someone from OH, Akron just viewed Phlebotomy Technician - Outpatient at CCF
Photo of the Rise User
Someone from OH, Solon just viewed Graphic Designer at Applause
Photo of the Rise User
Someone from OH, North Canton just viewed NodeJs developer at BlackStone eIT
Photo of the Rise User
Someone from OH, North Canton just viewed Software Development Engineer - Recent Grads Welcome at Sonos
Photo of the Rise User
16 people applied to SOC Analyst I at CBIZ
Photo of the Rise User
Someone from OH, Dayton just viewed Data Entry and Word Processing at MoxieIT
Photo of the Rise User
Someone from OH, Dayton just viewed Content Developer - Intern at Big Ideas Learning
Photo of the Rise User
Someone from OH, Pickerington just viewed Salesforce Lead at Bounteous
Photo of the Rise User
Someone from OH, Pickerington just viewed Industry Lead - High Tech (Salesforce) at Thunder
D
Someone from OH, Akron just viewed Junior Motion Designer at DEPT®
R
Someone from OH, Akron just viewed 2D Graphic and Motion Designer at Ruby Labs