Security Software Engineer
Tailscale is building the new Internet by delivering software that makes it easy to securely interconnect people and their devices, no matter where they are. From hobbyists to multinational corporations, teams of every size use Tailscale each day to protect their networks, share access to internal tools, and more. We're building a future for the Internet that's easy, sensible, and safe. Founded in 2019 and fully distributed, we're backed by Accel, CRV, Insight, Heavybit, and Uncork Capital.
About the role
We’re seeking a talented software engineer, specializing in security and privacy, to help grow our product security team. We’re looking for people who can move Tailscale forward while making it safer to use. The abilities to think on your feet, collaborate with highly technical teams, and be comfortable working asynchronously are essential.
Responsibilities
- Improve the security properties of Tailscale by identifying opportunities for security and privacy features, bug fixes, and defense-in-depth, and implementing them across our codebase.
- Audit Tailscale features for technical security weaknesses, identifying mitigations or solutions, and driving them towards resolution.
- Support engineering decisions with threat modeling and security analysis and expertise.
- Spend at least 50% of your time in this role writing software vs purely operational or governance security responsibilities.
- Collaborate with engineering teams to promote secure coding practices and provide targeted security guidance and training.
Requirements
- Technical Proficiency developing in at least one programming language (Tailscale uses Go).
- Proficiency developing for at least one application platform (e.g. iOS, Android, web, Windows, macOS, Linux).
- Prior experience in a safety-related technical role, such as:
- application security or application platform security
- penetration testing
- threat modeling and prioritization
- user experience design or research
- digital forensics and incident response
- Deep understanding of web application vulnerabilities (e.g., OWASP Top 10), client-side security, and common API security flaws.
- Knowledge of cryptographic primitives and protocols.
- Knowledge of common networking protocols.
Team Fit
- Ability to give and process constructive feedback.
- Ability to work independently and collaboratively.
- Flexibility to adjust to the dynamic nature of a startup.
- Take a risk-based approach to building security controls, balancing your security expertise and broad technical skillsets with practical, usable solutions.
Pay
US Pay Range: $163,000—$226,000 USD
Benefits
- An inclusive, flexible environment where you can be your authentic self.
- A competitive total compensation package including base salary, equity incentive plan, and variable commission (for quota-based roles).
- Comprehensive group benefits with no waiting period (health, vision, dental, and more for you and your family).
- Remote-first company with virtual and in-person social events, and a corporate co-working program (e.g., WeWork).
- Employer-funded retirement contributions (dollar-for-dollar match up to 0.75% of eligible compensation).
- Annual company retreat, team off-sites, and opportunities to collaborate in person across Canada, the United States, the United Kingdom, and Singapore.
- $1500 USD annually for professional development, mentorship, coaching, and internal promotion opportunities.
- Flexible, paid time off program for any situation, supporting work-life integration.
- Build-your-own home office setup: company-owned laptop (Mac or PC), monthly home internet reimbursement, and $500 USD to customize your workstation.
- Paid parental leave program (20 weeks for birthing parents, 16 weeks for non-birthing parents).