- Company Name
- Box
- Job Title
- Staff Security Engineer
- Job Description
-
**Job Title**
Staff Security Engineer
**Role Summary**
Senior security engineer responsible for designing, developing, and embedding security controls into the core platforms and architectural frameworks of a large‑scale SaaS product. Drives secure‑by‑design practices, conducts risk assessments, mentors engineers, and influences organization‑wide security standards.
**Expectations**
- Minimum 12 years of experience in software or security engineering, with a focus on large‑scale platform or distributed system security.
- Proven ability to lead security architecture initiatives and collaborate across engineering, product, and compliance teams.
- Strong growth mindset; proactively researches emerging threats and leverages AI/automation to enhance impact.
- Excellent communication skills for both technical and leadership audiences.
**Key Responsibilities**
- Design and implement security architectures and controls for foundational platforms (identity, API integration, frontend frameworks, mobile).
- Conduct architectural risk assessments and create secure‑by‑design components and patterns.
- Partner with engineering, product management, security architecture, production security, and compliance to embed security in new platform development.
- Research and incorporate emerging threat intelligence and vulnerability mitigations.
- Mentor and guide security engineers in scalable vulnerability detection and remediation.
- Define and promote company‑wide security standards and share knowledge on platform security strategies.
**Required Skills**
- Deep expertise in platform security domains: identity management, cryptography, API security, supply‑chain security, cloud infrastructure security.
- Strong proficiency in threat modeling, architectural risk assessment, and secure framework design.
- Advanced programming skills (e.g., Java, Go, Python, or similar) and experience with modern cloud environments (AWS, Azure, GCP).
- Familiarity with container orchestration (Kubernetes), microservices, service mesh, and CI/CD pipelines.
- Ability to automate security controls and integrate security tooling into development workflows.
- Strong analytical, problem‑solving, and mentorship capabilities.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field (or equivalent professional experience).
- Relevant security certifications (e.g., CISSP, CISM, GSEC, AWS/Azure Security Specialty) are preferred but not mandatory.
Redwood city, United states
Hybrid
Senior
19-10-2025