Security Engineer at Skydio
San Mateo, CA
$160,000–$210,000from the description
Jun 28, 2026
San Mateo, CA
Jul 21, 2026
What this job asks for AI summary
A security engineering role focused on building automation and internal tooling to keep cloud and corporate environments secure and audit-ready. Day-to-day work centers on coding integrations across cloud APIs, identity providers, and vulnerability scanners; automating compliance evidence collection; and replacing manual security processes with self-remediating controls. Over time, the scope expands to end-to-end design of internal security systems and architectural collaboration with broader engineering teams.
Mid level · 3+ years · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 920 people nationally plausibly meet what this posting asks for (information security analysts). range 550–1,400
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $129,180 (middle half $97,810–$163,500). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (9)
SOC code is a genuine toss-up: the role is framed as a Security Engineer but the primary day-to-day work is writing automation code and building internal tooling (Python/Go, API integrations, dashboards, pipelines), which leans toward 15-1252 Software Developers. 15-1212 Information Security Analysts is chosen because the security domain (GRC, compliance controls, vulnerability management, identity) is the explicit organizing purpose of the work; 15-1252 is the close runner-up.
Python and Go are presented as interchangeable examples ('languages such as Python or Go') under the required qualifications; Python is listed as the primary with Go as an alternative.
AWS is listed as the preferred cloud ('ideally AWS') within the required qualifications block — the 'ideally' signals a substitution qualifier, not optionality, so it remains a hard gate with Azure and GCP as alternatives.
SCIM provisioning is called out explicitly in the required qualifications as an example of identity system integration and is retained as a hard gate.
SIEM, IAM/IdP, EDR, vulnerability management tooling, GRC tooling, FedRAMP, SOC 2, ISO 27001, and Kubernetes all appear exclusively under the 'Nice to Have' section.
The ITAR/EAR export-control clause effectively requires US persons (citizens, LPRs, or those with appropriate status) but does not gate on a formal US government security clearance, so the clearance requirement is set to None.
No degree requirement is stated anywhere in the posting.
The title carries no seniority level word; the title states no level. The 3+ years requirement and scope (building automation, growing into broader security engineering) support a Mid classification.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.