offices in New York, Washington D.C., London and Amsterdam. The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s... ..., and aligned with industry and regulatory expectations. GRC Engineering is ho…
Security Engineer jobs in San Francisco, CA
Security engineers protect systems and data by finding vulnerabilities, building defenses, and responding to incidents. The work spans application security, infrastructure hardening, and threat detection.
No email, no resume, no sign-up. Save any listing below and you start anonymously.
You're signed in. Saving a listing drops it straight into your pipeline.
Open security engineer roles
12 shown of 385 · sorted by freshness
13, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. Security Engineering is the engineering function inside the Plaid security org that focuses on developing…
worldwide from increasingly sophisticated cyber and AI-driven threats, securing their AI transformation. Our prevention-first approach... .... Job Description We're looking for an AI Security Engineer to join our Red Tea…
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted... ...Technology, Data, and Intelligence (TDI) organization is the engine that powers…
build, operate, and scale onchain infrastructure. The platform secures over €100B in assets and powers critical operations—including key... ...institutions. Our client is seeking a Principal Security Engineer to lead pro…
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted... .... If you are too, let's talk. The Staff Product Security Engineer Opportunity As…
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted... ...mission. If you are too, let's talk. The Staff AI Security Engineer Opportunity…
our founding in 2013, we have focused on enabling our clients to securely navigate the digital asset space. With a global presence and... ...problem-solving. We are seeking a Senior Application Security Engineer to lead…
requirements vary by role and will be assessed during the interview process. About the Role: We're looking for a Senior Staff Security Engineer to lead Gusto's edge and network security strategy, owning the design and op…
Principal Cloud Security Operations Engineer (Scripting, AWS, DevOps, CISM, CCSA, CISSP, CCIE Security, CEH) in San Francisco, CA AWS, CEH, CISA, CISSP, DevOps, Python, scripting, Security Operations, SIEM Location: Cali…
outcomes. We stay close to our customers — from leadership to engineers — and work together to solve real problems with urgency and care... ...picture, and tackle more complex challenges in less time. Security is at the…
About the role We are seeking a Senior Security Engineer to build and lead our Offensive Security program. In this role, you will attack Chime’s services, applications, and infrastructure to discover security issues and…
What security engineers earn in San Francisco
Hourly first — that's how the offer arrives
| Experience | Hourly | Annual, full-time |
|---|---|---|
| Entry level | $54–$74 | $112k–$154k |
| Mid level | $74–$104 | $154k–$217k |
| Senior | $101–$141 | $210k–$294k |
Adjusted for the San Francisco market from national ranges.
What employers ask for
The skills these listings keep naming
Interview questions worth rehearsing
With the thing the interviewer is actually listening for
Walk me through how you would threat model a new feature.
Use a structure — assets, entry points, attacker goals — and show that you rank risks rather than listing everything. STRIDE is a fine scaffold if you actually apply it.
You find a critical vulnerability in production. What are your next steps?
Verify, assess exposure, contain, and coordinate disclosure and fix — with communication throughout. Panic-free process is the whole answer.
Explain a recent vulnerability class or breach and what you took from it.
Staying current is part of the job. Pick something real, explain the root cause simply, and connect it to a defense you would build.
How do you get developers to fix security issues they see as low priority?
Show empathy for delivery pressure: translate risk into business impact, make fixes easy, and build guardrails so the secure path is the default.
How would you secure a cloud environment from scratch?
Cover identity first, then network segmentation, logging, encryption, and automated policy checks. Saying 'IAM is where most cloud breaches start' shows you know the terrain.
What is the difference between authentication and authorization, and where do systems commonly get it wrong?
Define both crisply, then give a real failure mode like broken object-level authorization. The follow-through example is what distinguishes the answer.
Tell me about a security control you built or improved.
Describe the risk it addressed and evidence it worked — findings reduced, detection time improved. Controls without measurement are just hopes.
Resume tips that move the needle
For security engineers specifically — generic advice costs you here
Lead with concrete defensive wins: vulnerabilities remediated, detection coverage added, incident response times improved.
List relevant certifications (Security+, OSCP, CISSP) prominently; this field still screens on them.
Name the domains you cover — appsec, cloud security, detection — since 'security' alone is too broad to place you.
Mention responsible disclosures, CTF results, or published research if you have them; they are strong credibility signals.
Show you can work with engineers, not just audit them — secure code reviews, training, or paved-road tooling you built.
Where this role goes
Typical progression
Applying for security engineer jobs in San Francisco?
Robbi carries this page into your first day: your role, your city, your shift preference. Then it hands you a few small things each morning and keeps the pipeline honest.
Save what looks right here, then let Robbi hand you a few small things each morning and keep the follow-ups honest.