freehire launches on Product Hunt on 26 August.

Follow →

Staff Security Engineer

Summary

Lead Flock Safety’s Product Security Incident Response Team (PSIRT), coordinate vulnerability disclosures, and manage CVE records for connected hardware and cloud systems.

The Problem

As Flock rapidly expands its fleet of connected hardware devices and cloud platforms, establishing a dedicated, centralized product security response program is critical to protecting our public safety network. Managing vulnerabilities across hardware, firmware, and cloud systems requires a single point of accountability to coordinate disclosures and drive fixes to closure. You will stand up our Product Security Incident Response Team (PSIRT), serve as the technical owner of our Coordinated Vulnerability Disclosure (CVD) program, and safeguard the products our customers depend on.

What You'll Own

  • Own the operational model and execution of Flock's Product Security Incident Response Team (PSIRT) across every externally reported and internally discovered product vulnerability.

  • Serve as the operational lead for our CVE Numbering Authority (CNA), managing vulnerability intake, triage SLAs, severity rubrics, and public CVE record publishing.

  • Drive cross-functional remediation efforts across Hardware, Firmware, Device SRE, Cloud SRE, Mobile, Legal, Communications, and Support to ensure timely patch delivery.

  • Author clear, accurate public security advisories, internal postmortems, and executive summaries tailored to technical, legal, and leadership audiences.

  • Establish metrics and operational reporting for PSIRT performance, tracking time-to-triage, time-to-fix, and time-to-disclose.

What This Role is Not

  • This isn't a people management position, you are an individual contributor who drives execution and policy adherence through cross-functional influence.

  • This is not a corporate security or internal SOC role, your sole focus centers on product security, field devices, and embedded software platforms.

  • This isn't a passive triage desk, you will actively guide technical remediation strategies and defend severity decisions with engineering leaders and external security researchers.

What You Bring

  • Demonstrated experience leading or running a PSIRT, product security, or coordinated vulnerability disclosure function, ideally within connected hardware or IoT environments.

  • Deep operational experience acting as a CVE Numbering Authority (CNA) or implementing the FIRST PSIRT Services Framework across discovery, triage, remediation, and disclosure.

  • Hands-on technical background in product security across embedded or firmware security, Linux or Android device security, AWS cloud security, or mobile application security.

  • Expertise applying CVSS, CWE, EPSS, and SSVC frameworks to evaluate risk and assign accurate vulnerability severities.

  • Strong written communication skills with the capability to translate complex technical vulnerabilities into clear advisories for customers, engineers, and executives.

Compensation

In this role, you'll receive a starting salary between $185,000 and $230,000 as well as Flock Stock Options. Base salary is determined by job-related experience, education/training, as well as market indicators. Your recruiter will discuss this in depth with you during our first chat.

Why Flock đź’š

Every community deserves to be safe. Flock builds the technology that makes that real: last year we supported over 1 million criminal investigations and helped locate more than 10,000 missing people. We're 1,700 people building the impossible with over $1B in funding, and the expectations are high on purpose. If you want a role where the stakes are real and the pace matches, this is it.

📍Some problems get solved faster in the same room, so we prioritize candidates in Atlanta and Boston. Hub-based roles mean real in-person time with your coworkers. Remote roles exist, and when a posting is open to remote work, it says so.

🌟 the impossible takes every kind of mind. Flock is an equal opportunity employer, and we know the best solutions come from diverse perspectives, experiences, and skills working together with mutual respect. Everyone is welcome to apply. If you need assistance or an accommodation due to a disability, email recruiting@flocksafety.com; your information stays confidential and is used only to arrange the right accommodation for your interviews.

đź’° On compensation: we pay fairly for the work. Base salary is determined by job-related experience, education, training, and market indicators. The range in this posting covers base salary only and doesn't include equity, sales bonus plans where applicable, or benefits. The range may be adjusted over time, and this posting may span more than one career level.

📣 One last thing: all legitimate communication from Flock comes from an email ending in @ or noreply@ashbyhq.com. We never make offers through messaging apps or third parties, and we never request payment or sensitive personal information during hiring. If you encounter suspicious outreach about a Flock role, report it to recruiting@flocksafety.com.

What this application asks

ashby

Name, Email, Location, Resume

  • Where are you based relative to our hubs? choose any
  • Phone Number
  • LinkedIn Profile optional
  • Preferred Pronouns optional
  • Describe a real piece of work where AI changed your process. What did you use it for, and where did you still have to do the thinking yourself? written answer
  • Will you now or in the future require Flock Safety to commence ("sponsor") an immigration case in order to employ you (for example, H-1B or other employment based immigration case)? This is sometimes called sponsorship for an employment-based visa status. yes / no
  • Are you authorized to work lawfully in the United States for Flock Safety? yes / no
  • Do you have a family member, spouse or significant other that is currently employed by Flock? choose one
  • Some Flock’s roles require the ability to obtain and maintain Criminal Justice Information Services (CJIS) certification as a condition of employment. This includes meeting all FBI CJIS Security Policy requirements, including a fingerprint-based background check. Are you able to meet these requirements if certification is required? yes / no

See also