LinkedIn

Staff Security Engineer - Production & Enterprise Security

LinkedIn Mountain View, California, United States · $156K–$255K/yr

Software Development · 10,001+ employees

6 h ago
security Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The role involves owning and driving the secure software development lifecycle (SSDLC) and building scalable security tooling to mitigate vulnerabilities. You will lead threat modeling, architectural design reviews, and partner with engineering teams to embed secure design patterns across cloud and product platforms.

What they look for

Security engineering Application security Cloud security Threat modeling SSDLC Java GoLang Python CI/CD Authentication protocols Cryptography Supply chain security Vulnerability assessment Penetration testing Cloud infrastructure Microservices

Requirements

Candidates must have a bachelor's degree in a technical field and at least 5 years of experience in security engineering. Proficiency in programming languages like Java, GoLang, or Python and experience with security assessment methodologies are required.

Benefits

Health and wellness programs Time away Performance bonus Stock options

Full description

Company Description

LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. Our products help people make powerful connections, discover exciting opportunities, build necessary skills, and gain valuable insights every day. We're also committed to providing transformational opportunities for our own employees by investing in their growth. We aspire to create a culture that's built on trust, care, inclusion, and fun – where everyone can succeed.

Join us to transform the way the world works.

Job Description

At LinkedIn, our approach to flexible work is centered on trust and optimized for culture, connection, clarity, and the evolving needs of our business. The work location of this role is hybrid, meaning it will be performed both from home and from a LinkedIn office on select days, as determined by the business needs of the team.

This role will be hybrid in LinkedIn’s Mountain View office location.

About the Team

LinkedIn's members entrust us with their information every day and we take their security seriously. Our core value of putting our members first powers all the decisions we make, including how we manage and protect the data of our members and customers. Information Security at LinkedIn is dedicated to protecting and securing business-critical member data and company assets. Our core mission is to empower LinkedIn to create a secure and thriving platform for every member of the global workforce. The Production & Enterprise Security team strives to proactively safeguard our products, applications, cloud environments, and core engineering infrastructure by identifying, assessing, and mitigating security and privacy risks. We are dedicated to protecting our members by conducting security reviews, threat modeling, establishing secure software development lifecycle (SSDLC) controls, and building scalable automation to minimize potential risks across the company.

About the Role

As a Staff Security Engineer on the Production & Enterprise Security team, you will strengthen the security posture of LinkedIn's core products, cloud infrastructure, and development workflows — leading threat modeling, designing and implementing secure-by-default frameworks, executing architecture reviews, and building scalable tooling to detect and mitigate application and platform vulnerabilities across the company.

Responsibilities:

  • Own and drive the secure software development lifecycle (SSDLC) and shift-left security controls across engineering platforms, including automated SAST/DAST scanning, software supply chain security, and CI/CD security guardrails.
  • Architect and build secure-by-default frameworks, paved roads, and developer guardrails for cloud infrastructure, microservices, authentication/authorization services, and core application components.
  • Build automation and security tooling that continuously identifies, reproduces, and mitigates application and cloud security vulnerabilities at scale; partner with Detection & Response on security logging, telemetry, and incident playbooks.
  • Lead threat modeling, architectural design reviews, and risk assessments for complex engineering systems and platforms. Partner with security and engineering teams to embed secure design patterns and risk mitigations into developer tooling and production services.
  • Define application and cloud security standards, reference architectures, and policies across product development, API design, data storage, and third-party integrations; drive secure adoption of cloud services and enterprise tools.
  • Drive cross-functional architecture and engineering decisions across platform engineering, security engineering, ML/AI teams, and product/DevEx to build developer platforms, AI systems, and infrastructure that are scalable, reliable, and secure by design.

Qualifications

Basic Qualifications

  • BA/BS Degree in Computer Science, Cybersecurity, Information Security, or related technical field, or equivalent technical experience.
  • Hands-on experience or working knowledge of web/application security, cloud security risks, or secure development lifecycle practices.
  • 5+ years experience in security engineering and in-depth knowledge of application security, authentication and security protocols, cryptography, or supply chain security.
  • 5+ Experience in various security assessment methodologies such as threat modeling, design reviews, penetration testing and vulnerability assessment.
  • Experience with programming languages such as Java, GoLang or Python.
  • Experience architecting or implementing tooling that detects and mitigates security vulnerabilities.

 

Preferred Qualifications:

 

  • BS and 8+ years of relevant work experience, MS and 7+ years of relevant work experience, or PhD and 4+ years of relevant work experience.
  • 5+ years experience with programming languages such as Java, GoLang or Python.
  • Experience securing cloud-native systems, containerized applications, microservice architectures, and modern CI/CD pipelines.
  • Working knowledge of modern technology stacks: cloud platforms (Azure, AWS), identity federation (OAuth/OIDC), distributed systems, and SSDLC automation tools.
  • Demonstrated ability to ramp up quickly on emerging threat vectors and technology stacks.
  • Ability to work across teams and communicate concisely and clearly to stakeholders.
  • Experience with security research, bug bounty or CTF competitions.
  • In-depth expertise in assessing, architecting, and safeguarding AI platforms and solutions.
  • Proven track record of challenging existing paradigms and championing continuous enhancement through strategic innovation and novel approaches.

 

Suggested Skills:

  • Product Security
  • Security Assessment Methodologies
  • Security Architecture
  • Technical Leadership

 

You will Benefit from our Culture

We strongly believe in the well-being of our employees and their families. That is why we offer generous health and wellness programs and time away for employees of all levels.

LinkedIn is committed to fair and equitable compensation practices. The pay range for this role is $156,000 to $255,000. Actual compensation packages are based on a wide array of factors unique to each candidate, including but not limited to skill set, years & depth of experience, certifications and specific office location. This may differ in other locations due to cost of labor considerations.

The total compensation package for this position may also include annual performance bonus, stock, benefits and/or other applicable incentive compensation plans. For additional information, visit: https://careers.linkedin.com/benefits. 

Additional Information

Equal Opportunity Statement 

We seek candidates with a wide range of perspectives and backgrounds and we are proud to be an equal opportunity employer. LinkedIn considers qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.

LinkedIn is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. Our goal is to foster an inclusive and accessible workplace where everyone has the opportunity to be successful.

If you need a Reasonable Accommodation to search for a job opening, apply for a position, or participate in the interview process, connect with us and describe the specific Accommodation requested for a disability-related limitation.

Fill out an Accommodation request here: https://app.smartsheet.com/b/form/b660a0327d044969abfd7a4e73d15c36

Reasonable accommodations are modifications or adjustments to the application or hiring process that would enable you to fully participate in that process. Examples of reasonable accommodations include but are not limited to:

  • Documents in alternate formats or read aloud to you
  • Having interviews in an accessible location
  • Being accompanied by a service dog
  • Having a sign language interpreter present for the interview

A request for an accommodation will be responded to within three business days. However, non-disability related requests, such as following up on an application, will not receive a response.

LinkedIn will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by LinkedIn, or (c) consistent with LinkedIn's legal duty to furnish information.

San Francisco Fair Chance Ordinance ​

Pursuant to the San Francisco Fair Chance Ordinance, LinkedIn will consider for employment qualified applicants with arrest and conviction records.

Pay Transparency Policy Statement ​

As a federal contractor, LinkedIn follows the Pay Transparency and non-discrimination provisions described at this link: https://lnkd.in/paytransparency.

Global Data Privacy Notice and Compliance Posters for Job Candidates 

Please use this link to access documents that provide information about how LinkedIn handles the personal data of employees and job applicants, as well as the E-Verify Participation Notice and the Department of Justice Immigrant and Employee Rights Section Right to Work posters: https://www.linkedin.com/legal/candidate-portal.

  • Workplace Type: Hybrid
  • Career Track & Grade: IC4/9
  • Department: Engineering

Similar roles